The cryptography that keeps payments trustworthy.
Plain-English explainers on payment security, key management, and the trust layer of agentic commerce — for the people who build, secure, and lead in payments.
Featured writing
Coming Soon
A new whitepaper on payment security and AI agents
I'm finishing up a deep dive on how cryptographic trust frameworks govern AI agents in card transactions. Subscribe to the newsletter below to be the first to read it.
Recent posts
-
The HSM key hierarchy, explained
LMK, ZMK, TMK, BDK, DUKPT and the rest of the HSM key hierarchy — how one master key born inside the hardware quietly protects every other key in a payment.
-
Key block formats, explained
TR-31, TR-34, Atalla and Thales key blocks compared side by side — what they are, how they differ, and where they live in a payment transaction.
-
ECC, explained
Smaller keys, same strength. How elliptic curves sign and agree on secrets, where they run in payments, and a quick guide to the curves you'll meet.
Newsletter
Monthly insights on payment security, cryptography, and what changes as AI agents start to pay.
About
Why "The Root Of Trust"
In cryptography, a root of trust is the anchor everything else chains back to — the one thing you have to trust for the rest to hold. Payments run on exactly that idea: keys, signatures, and scoped credentials that let strangers transact safely.
This is where I break that machinery down in plain English — EMV and HSMs, key management and tokenization, PCI and PIN security, and now the cryptographic trust layer that will decide whether AI agents can be trusted to pay.
Read my story