GIRASOL

Local custody first

Security

Security boundaries, responsible disclosure and safe operating practices for Girasol.

Core model

Private keys and provider credentials should remain in the operator’s environment. Dry-run is the default in the public Solana repository. Use a dedicated wallet with limited funds.

Responsible disclosure

Do not publish an exploitable issue before maintainers can investigate. Contact @girasolsupportbot or the official @girasolbot account with a minimal non-destructive report. Never send private keys, seed phrases or live API secrets.

Official software

Use only links from this domain and github.com/girasolbot/girasolbot. Verify release notes and checksums when release artifacts become available.

Safe deployment

Keep control panels on loopback or a private network, rotate exposed credentials, restrict filesystem permissions and review configuration before enabling real execution.