Security
Keep observation separate from execution
Boundaries for the non-custodial monitor and administrative record. No audit is claimed.
Read-only and non-custodial
The public frontend only reads snapshots. The protected admin console submits metadata and TXIDs for verification; it contains no private key, seed phrase, wallet connector, signing method or transfer method. A frontend index reading or treasury threshold is never authority to move funds.
Data and service boundaries
DEX Screener market observations and Solana RPC financial observations are separate services and stores. Provenance, freshness and configuration state are displayed explicitly. Missing addresses are shown as NOT CONFIGURED.
Admin credentials and RPC configuration remain server-side. Sessions use signed HttpOnly cookies and mutations verify their request origin. The current atomic JSON stores and locks support a single host; multi-host deployment requires shared persistence and distributed coordination.
Operational review
Production operation should review RPC trust, administrator credential rotation, reverse-proxy origin headers, persistence backups and incident handling. No smart contract or smart-contract audit is implemented or claimed because this website has no contract execution role.