PARACHUTE docs
v1.0.0
Live demo Get help
● Ship · How it protects traders

Security
non-custodial by construction.

What PARACHUTE does and never does with keys, approvals and data, and what you must protect as the operator.

No keysNo relayerExact approvalsPermit2 1 h

01Non-custodial

  • No keys anywhere. No private key, signer, relayer or transaction coordinator exists in the dApp or the operator server. The app only asks the trader's wallet to sign.
  • Built in the browser. Every transaction is built in the trader's browser, shown in a review sheet and signed by the trader's wallet.
  • The server never touches a trade. It stores settings and the audit log and reads the chain only to show your fee revenue (server/app.ts).
  • Parachutes alert; they never execute. There is no auto-execution module in this codebase (Parachute rules).

02Approvals and trade protection

ProtectionDetail
Exact approvalsBy default a token approval covers exactly the amount of the trade. Unlimited approval is an opt-in checkbox.
Permit2 expiryExact Permit2 allowances expire after 1 hour; opted-in unlimited ones still expire after 30 days (src/features/swap/service.ts).
SlippageEvery trade has slippage protection and it cannot be set to 0.
Price-impact capThe review refuses to sign above the operator's cap (default 15%).
Quote freshness and deadlineQuotes expire after 30 seconds; swaps carry a 10-minute deadline.
Router checkThe Universal Router's code and its PoolManager wiring are checked; a mismatch refuses the trade before any signature is requested.
Unknown hooksUniswap v4 pools with hooks that are not on the verified list are excluded from routing, and the quote says so.
Stock routesNine live pause and blocklist reads before every stock trade; any failure blocks it (details).
Fee to a zero addressThe swap builder refuses to pay a fee to address(0).

03Data and privacy

  • No user accounts for traders, no user table, no wallet list, and no request log with wallets on the server.
  • Parachute rules, the stock self-declaration, the referral code and preferences live in the trader's own browser (localStorage and IndexedDB).
  • The referral lookup answers one code with one payout address and records nothing.
  • Creator-supplied token names, descriptions and logos are shown as plain text and images, unfiltered. Logos on hosts that forbid embedding fall back to a monogram.

04What you must protect

  • ADMIN_SECRET_KEY: in the server environment only, never in git or in .env.local. Back it up.
  • server/data/: created with owner-only permissions; keep it that way and back it up.
  • Owner accounts: strong passwords (12+ characters), two-factor on; require two-factor for owners and managers in Security & alerts.
  • VITE_* values are public. Never put a secret there; restrict RPC keys to your domain.
  • Your fee wallet: use a wallet you control. Only its public address goes into PARACHUTE.
  • Run the server behind HTTPS; keep HOST=127.0.0.1 when the proxy is on the same machine.

05Console safeguards

  • Secrets are write-only: they can be replaced or tested, never read back.
  • Wallet addresses are masked; revealing, exporting and audit CSV are owner-only.
  • Money fields default to off and have hard caps that the server enforces at start-up and on every save.
  • Every change is in the audit log with who and when; every configuration is a version you can roll back.
  • The console has its own strict Content Security Policy on /admin only.

06Checks shipped with the code

npm run gate                # types, tests, licences, contrast, build
npm run verify:contracts    # every configured contract has code and the expected wiring (reads mainnet)

The read-only QA scripts in scripts/qa/ and scripts/admin/ never send a transaction. The source is scanned with gitleaks before release (.gitleaks.toml).

07Reporting a vulnerability

Report it privately through the item's Support tab on CodeCanyon, with steps to reproduce (Support).