● Ship · How it protects traders
Security
non-custodial by construction.
What PARACHUTE does and never does with keys, approvals and data, and what you must protect as the operator.
01Non-custodial
- No keys anywhere. No private key, signer, relayer or transaction coordinator exists in the dApp or the operator server. The app only asks the trader's wallet to sign.
- Built in the browser. Every transaction is built in the trader's browser, shown in a review sheet and signed by the trader's wallet.
- The server never touches a trade. It stores settings and the audit log and reads the chain only to show your fee revenue (
server/app.ts). - Parachutes alert; they never execute. There is no auto-execution module in this codebase (Parachute rules).
02Approvals and trade protection
| Protection | Detail |
|---|---|
| Exact approvals | By default a token approval covers exactly the amount of the trade. Unlimited approval is an opt-in checkbox. |
| Permit2 expiry | Exact Permit2 allowances expire after 1 hour; opted-in unlimited ones still expire after 30 days (src/features/swap/service.ts). |
| Slippage | Every trade has slippage protection and it cannot be set to 0. |
| Price-impact cap | The review refuses to sign above the operator's cap (default 15%). |
| Quote freshness and deadline | Quotes expire after 30 seconds; swaps carry a 10-minute deadline. |
| Router check | The Universal Router's code and its PoolManager wiring are checked; a mismatch refuses the trade before any signature is requested. |
| Unknown hooks | Uniswap v4 pools with hooks that are not on the verified list are excluded from routing, and the quote says so. |
| Stock routes | Nine live pause and blocklist reads before every stock trade; any failure blocks it (details). |
| Fee to a zero address | The swap builder refuses to pay a fee to address(0). |
03Data and privacy
- No user accounts for traders, no user table, no wallet list, and no request log with wallets on the server.
- Parachute rules, the stock self-declaration, the referral code and preferences live in the trader's own browser (localStorage and IndexedDB).
- The referral lookup answers one code with one payout address and records nothing.
- Creator-supplied token names, descriptions and logos are shown as plain text and images, unfiltered. Logos on hosts that forbid embedding fall back to a monogram.
04What you must protect
ADMIN_SECRET_KEY: in the server environment only, never in git or in.env.local. Back it up.server/data/: created with owner-only permissions; keep it that way and back it up.- Owner accounts: strong passwords (12+ characters), two-factor on; require two-factor for owners and managers in Security & alerts.
VITE_*values are public. Never put a secret there; restrict RPC keys to your domain.- Your fee wallet: use a wallet you control. Only its public address goes into PARACHUTE.
- Run the server behind HTTPS; keep
HOST=127.0.0.1when the proxy is on the same machine.
05Console safeguards
- Secrets are write-only: they can be replaced or tested, never read back.
- Wallet addresses are masked; revealing, exporting and audit CSV are owner-only.
- Money fields default to off and have hard caps that the server enforces at start-up and on every save.
- Every change is in the audit log with who and when; every configuration is a version you can roll back.
- The console has its own strict Content Security Policy on
/adminonly.
06Checks shipped with the code
npm run gate # types, tests, licences, contrast, build
npm run verify:contracts # every configured contract has code and the expected wiring (reads mainnet)
The read-only QA scripts in scripts/qa/ and scripts/admin/ never send a transaction. The source is scanned with gitleaks before release (.gitleaks.toml).
07Reporting a vulnerability
Report it privately through the item's Support tab on CodeCanyon, with steps to reproduce (Support).