PRE-RELEASEHash-based custody. Independent review pending.Know the limits
VERIFY, THEN TRUST

Nothing hidden behind a badge.

Deployment observations, source, and the work required before real-fund custody.

Deployment facts

Reading configured deployment status…

Executable status is an RPC observation. It is not an audit or proof that source matches a deployed binary.

Source and reproducibility

The complete web app, small Rust custody program, browser SDK, test vectors, and deployment instructions are included in the source bundle. Builds use committed npm and Cargo lockfiles. A successful local build is not independently verified deployment evidence.

The release gate

01

Cryptographic review

Review the upstream primitive, full parameter set, canonical message, and Bunker’s browser port.

Pending
02

Program audit

Independently examine SOL and SPL custody, account validation, proof staging, and atomic authorization changes.

Pending
03

Recovery and signing review

Address stale backups, multi-device state, interrupted submissions, browser isolation, and malicious frontend updates.

Pending
04

Deployment verification

Match reviewed source to the binary, publish hashes and program ID, and decide the upgrade-authority policy.

Pending
05

Operational readiness

Set up an RPC provider, incident contact, security disclosure process, monitoring, and a clearly scoped bounty.

Pending

How a future deployment is verified

A reviewer should reproduce the reviewed build and compare its executable hash to the on-chain program using the Solana verified-build workflow. Inspect the program-data account and upgrade authority separately. An Explorer link alone establishes neither source equivalence nor audit coverage.

Current release policy

The public deployment is read-only on mainnet. No environment switch enables mainnet custody. The isolated testing configuration permits only a pinned local or devnet network and rejects mainnet writes. Accepting real assets requires a reviewed code release and actual audit evidence.