Security
Token generation has not occurred and the design has not been audited, including the vesting program planned for the founder allocation. The design aims to limit what can go wrong, but no claim of safety is made:
- Standard token program. The token itself uses only the standard Solana SPL Token program, with no custom token code.
- Vesting program: unaudited. A purpose-built vesting program is designed and tested locally. It is not audited, not deployed and blocked by a release gate. Custom code can contain bugs that testing misses.
- Fixed supply. The mint authority is to be revoked permanently, so no one can create more.
- No freeze authority. No one will be able to freeze holders' tokens.
- Hardware-wallet signing. Any real deployment will be signed by humans on hardware wallets, outside automation.
- No automated deployment. The repository's CI has no deployment path, and tests enforce that.
- No secrets in the repository. Secret scanning runs on every change.
Security reports: [Security contact: To be published before token generation.]