INTEGRATE · IN BUILD

Security

What can write to the ledger, what holds keys, what this property is allowed to do, and how to tell us when something is wrong. No external audit has been commissioned; that is stated here rather than left to be inferred.

SurfaceControlState
This propertyRead-only. Holds no write credentials and no keysLIVE
Public read APIUnauthenticated, aggregates first, no personal data in any responseIN BUILD
Ledger write pathOne guarded writer requiring an idempotency keyIN BUILD
Balance writersLint rule exists in flashy-contracts; not yet installed in the consumerNORTH STAR
External auditNone commissioned. Stated here rather than left to be inferredNORTH STAR

Responsible disclosure

Report anything that affects the correctness of the ledger or the privacy of the explorer to security@flashy.network. We acknowledge within 72 hours and tell you what we are doing. The same address, machine-readable, is at /.well-known/security.txt.

If a report reveals a discrepancy in the ledger, it appears on the incidents page once corrected — including the ones we would rather not publish.

What this property can do

Read. That is the whole list. It holds no write credentials, no signing keys and no personal data. The adapter it queries the ledger through is read-only by type, not by convention — there is no write method on it to call by mistake.