Non-Custodial Architecture

The ai.market Protocol

Buyers find and pay for data on ai.market. The data itself goes straight from the seller to the buyer. It never passes through us.

How It Works

Central discovery, direct delivery

Data in AWS or Cloudflare? Sell it from your browser. There is nothing to download or install. The AIM Data gateway is only for sellers who keep data on their own servers.

1

List

Files stay where they are

Sellers with data in AWS S3 or Cloudflare R2 connect their bucket in the browser with read-only access and pick the files to sell. Nothing to download or install. Sellers who keep data on their own servers run the open-source AIM Data gateway with Docker. Either way the files never move to ai.market.

2

Discover

Marketplace Matching

Buyers and AI agents search ai.market's catalog using semantic search, filters, and structured queries.

3

Transact

Platform Billing

When a buyer purchases, ai.market handles checkout and signs a file-specific delivery permission.

4

Deliver

Direct delivery

The buyer downloads purchased files straight from the seller's own AWS or Cloudflare storage, or from the seller's AIM Data gateway. ai.market does not store the files.

What the Platform Does

Discovery: Semantic search, category browsing, and AI agent-accessible APIs for finding assets

Authentication: Identity verification, API key management, and OAuth for all participants

Trust: Short-lived download links to the purchased files in cloud storage, and signed delivery permissions that the seller gateway verifies before serving a file

Billing: Payment processing, usage metering, and seller payouts at 5% marketplace fee

Observability: Delivery receipts and signed audit entries for every outbound gateway message

What the Platform Does NOT Do

Store data: Purchased files go from the seller's cloud storage or gateway directly to the buyer, without passing through ai.market.

Serve files: Files are served by the seller's own AWS or Cloudflare bucket, or by the seller gateway through the seller's HTTPS door

Lock in sellers: Sellers keep their files in their own cloud account or behind AIM Data, an open-source gateway they run themselves, and can disconnect at any time

The Stack

Platform responsibilities are explicitly separated

ComponentRoleWho Runs It
ai.marketDiscovery, auth, billing, trust tokensai.market (cloud)
Seller cloud storageHolds the files in the seller’s own AWS S3 or Cloudflare R2 account and serves purchased files to buyers through short-lived links.Sellers (their own cloud account)
AIM DataLists seller files in place, describes confirmed files, and serves purchased files directly to buyers.Sellers (self-hosted)
allAIWebsite listing assistanceai.market

Encryption & Security

Security primitives designed for non-custodial delivery

The platform coordinates trust, authentication, and billing without taking custody of datasets or any payload bytes, whether the files sit in cloud storage or behind a gateway.

CLOUD STORAGE ACCESS

AWS sellers create a role that only ai.market can use, with a unique external ID and read access limited to the bucket folder they choose. Cloudflare sellers give an R2 key with Object Read only permission for one bucket. ai.market keeps these encrypted, uses them to list file names and sizes and to create each buyer's download link, and never copies the files. Disconnecting stops new download links. Links already issued can remain usable for up to five minutes.

CLOUD DOWNLOAD LINKS

After a purchase, ai.market creates a link to each purchased file that works for at most five minutes. The buyer downloads directly from AWS or Cloudflare, and the file never passes through ai.market.

DEVICE IDENTITY

Sellers get a one-time pairing code and Docker Compose file in Sell Data > Gateways. The gateway runs without admin rights and with read-only file access.

SIGNED PERMISSIONS

ai.market signs file-specific download permissions. The seller gateway checks each signature, file version, expiry, and local offer rules before serving bytes.

WHAT LEAVES THE GATEWAY

Opaque file IDs and keyed commitments leave automatically, with an alias only if the seller sets one. After confirmation, structure and raw SHA-256 leave. No data values go to ai.market in these messages. The gateway sends delivery receipts and signed audit entries for every outbound message. The seller may separately publish a public sample.

NETWORK BOUNDARY

The seller restricts gateway egress to api.ai.market:443 with a restricted proxy or firewall and DNS. The gateway reports open egress through its canary, and ai.market blocks publishing and new permissions until the check passes.

For Developers

API-first by design

The protocol is API-first. Every interaction - listing, searching, purchasing, delivering - is available as a REST endpoint. AI agents can discover and transact with data programmatically without human intervention.