Deployment facts
Reading configured deployment status…
Executable status is an RPC observation. It is not an audit or proof that source matches a deployed binary.
Source and reproducibility
The complete web app, small Rust custody program, browser SDK, test vectors, and deployment instructions are included in the source bundle. Builds use committed npm and Cargo lockfiles. A successful local build is not independently verified deployment evidence.
The release gate
Cryptographic review
Review the upstream primitive, full parameter set, canonical message, and Bunker’s browser port.
Program audit
Independently examine SOL and SPL custody, account validation, proof staging, and atomic authorization changes.
Recovery and signing review
Address stale backups, multi-device state, interrupted submissions, browser isolation, and malicious frontend updates.
Deployment verification
Match reviewed source to the binary, publish hashes and program ID, and decide the upgrade-authority policy.
Operational readiness
Set up an RPC provider, incident contact, security disclosure process, monitoring, and a clearly scoped bounty.
How a future deployment is verified
A reviewer should reproduce the reviewed build and compare its executable hash to the on-chain program using the Solana verified-build workflow. Inspect the program-data account and upgrade authority separately. An Explorer link alone establishes neither source equivalence nor audit coverage.
Current release policy
The public deployment is read-only on mainnet. No environment switch enables mainnet custody. The isolated testing configuration permits only a pinned local or devnet network and rejects mainnet writes. Accepting real assets requires a reviewed code release and actual audit evidence.