Docs / Technology

Security principles

The principles that protect users and funds.

  • Secrets are handled only on the server and never reach the browser.
  • The backend is authoritative; the browser cannot write core data directly.
  • Access controls restrict every table and every owner action.
  • All input and all AI output is validated.
  • AI is separated from transactions and permissions.
  • Duplicate prevention on launches, votes, rewards and fee records.
  • Safe, generic error messages.
  • Least-privilege design throughout.
INFO

Security implementation details are intentionally not published.