Security

Security.

How keys, payouts and the website are protected, and what that does not cover.

Keys The developer wallet key exists only inside an isolated signer service on a private network. It is provisioned as a deployment secret, never committed, never printed, and never available to the website, the worker, the support assistant or any public API.

What the signer will sign Only two things, each built by the signer itself: SOL transfers for a payout batch already committed in the database, and Pump creator-fee collections for the configured wallet. Every request must carry a valid HMAC signature, a fresh timestamp and a single-use nonce. The signer independently checks recipients against committed, unpaid entitlements and refuses anything that would spend the free pool, reserved liabilities or the operating minimum. It also supports per-transaction, per-round and per-day spending caps from its own journal; the operator currently runs without practical caps, so payouts are bounded by the collected creator fees in the pool. A kill switch disables signing entirely.

Duplicate protection Each payout transaction is stored with its signature before broadcast. Uncertain submissions are reconciled on chain before anything is retried, and a transaction is rebuilt only after its blockhash has provably expired. Database constraints prevent duplicate fee receipts and duplicate entitlements, and an advisory lock ensures only one worker runs rounds.

Documentation · Status