One page for the question a depositor asks before a 48-hour-queue deposit: who can touch the SOL, what broke before and what was done, and whether the deployed code is the published code. Every block has a status and a command to check it without us.
Admin: single key (HByG…QZAf). It can withdraw vault, pool and buyback SOL; each withdrawal is a public event.
solana find-program-derived-address BohF4FAftBwEBoa23sUgM8Vr5HL2nAHLx5s7b1iBK56f string:platform
solana account <PLATFORM_ADDRESS> --url https://indexer-production-617d.up.railway.app/rpcAdmin withdrawals so far: 0 SOL in 0 withdrawals from the pool and the buyback; vault withdrawals are listed per coin in its vault log.
The full list of admin powers and what each one can never take.
curl -s https://indexer-production-617d.up.railway.app/api/admin/withdrawals | jq '.totals, .items[0:5]'Nothing to compare yet: the deployed hash is read from the RPC and shown above when the indexer has it; the published hash lands with the mainnet build.
Upgrade authority is the key that can replace the code. While it exists the rules on these pages hold only as long as that key does not ship different code; after the audit it is set to none, and the row above reads “none (immutable)” on its own.
solana program show BohF4FAftBwEBoa23sUgM8Vr5HL2nAHLx5s7b1iBK56f --url https://indexer-production-617d.up.railway.app/rpc
solana-verify get-program-hash BohF4FAftBwEBoa23sUgM8Vr5HL2nAHLx5s7b1iBK56f --url https://indexer-production-617d.up.railway.app/rpc
solana-verify build --library-name floor && solana-verify get-executable-hash target/deploy/floor.soThe hash the indexer compares against comes from trust.json in its data directory once a build is published and signed; before that, from the target/deploy/floor.so on the indexer host, which is the same binary the deploy used. Neither replaces running the build yourself.
Not audited. No firm is booked yet. The plan: scope is programs/floor at the deployed commit, plus the SDK mirror the site builds transactions with; the report is linked here, and the upgrade authority is revoked only after it signs off the exact deployed build. Until then the program's own tests (litesvm, the pump.fun fixtures) and the public source are what you have.
10% of the funds at risk, paid in SOL, capped at $50,000 for a critical finding (funds can leave a vault, the pool or the buyback against the rules) and $5,000 for a high one (a floor, its strength or a backing can be read or set wrongly; the agent can be made to sell outside the caps). Scope: the program, the indexer and the web app. Out of scope: pump.fun and PumpSwap themselves, denial of service on hosted services, findings that need a leaked key.
Until the Immunefi listing is live, report privately to the address in the privacy policy; the same terms apply, and a fix ships before any disclosure.
/status shows the program RPC, the indexer (lag in slots), the vault agent (heartbeat age) and the AI service, each with its uptime, plus the last vault trade and the incident log. A hosted page with e-mail subscriptions comes with mainnet; the header's truth bar links here when something is degraded.
Incidents. Every incident is a file in docs/incidents, rendered on /status: time, impact, cause, fix, within 72 hours of resolution. The empty state says what the policy is so that an empty log is a claim, not an absence.
Every balance the program holds and every platform key's float, from /api/treasury: the sum of vault ammo (and the backing of Burn / Pulse / Diamond vaults), the pool's NAV, idle and outstanding SOL, its queue, unvested income, buyback SOL pending and spent, what the AI treasury received and spent, the cumulative fee split in SOL, and the admin withdrawals total.
SOL at $120. Key balances are fee float, not funds: no platform key holds user money outside the program accounts above.
curl -s https://indexer-production-617d.up.railway.app/api/treasury | jq .Using the site means accepting the terms of service and the privacy policy: 18 or older, no KYC, every transaction signed in your own wallet. The one custodial option is Continue with Google, where we hold the wallet's key encrypted, sign only what a fixed policy allows and let you export the key any time. Residents of the UK and of sanctioned jurisdictions may not use LOADED; there is no geo-block code, the terms carry the list.