How keys, payouts and the website are protected, and what that does not cover.
Keys
The developer wallet key exists only inside an isolated signer service on a private network. It is provisioned as a deployment secret, never committed, never printed, and never available to the website, the worker, the support assistant or any public API.
What the signer will sign
Only two things, each built by the signer itself: SOL transfers for a payout batch already committed in the database, and Pump creator-fee collections for the configured wallet. Every request must carry a valid HMAC signature, a fresh timestamp and a single-use nonce. The signer independently checks recipients against committed, unpaid entitlements and refuses anything that would spend the free pool, reserved liabilities or the operating minimum. It also supports per-transaction, per-round and per-day spending caps from its own journal; the operator currently runs without practical caps, so payouts are bounded by the collected creator fees in the pool. A kill switch disables signing entirely.
Duplicate protection
Each payout transaction is stored with its signature before broadcast. Uncertain submissions are reconciled on chain before anything is retried, and a transaction is rebuilt only after its blockhash has provably expired. Database constraints prevent duplicate fee receipts and duplicate entitlements, and an advisory lock ensures only one worker runs rounds.
Website
Strict input validation, parameterized queries, a read-only database role for public pages, a per-request Content Security Policy, HSTS, frame denial, request size limits, rate limits and same-origin checks on state-changing requests. The admin area requires a password (scrypt hash), uses an HttpOnly, SameSite=Strict session cookie and CSRF tokens, and its actions are audit-logged.
Limits of these protections
CASHBACK is not audited and does not claim to be trustless or unhackable. The operator holds the developer wallet key. Once official channels are published in the footer, report suspected vulnerabilities there. Do not test against mainnet funds.