Local custody first
Security
Security boundaries, responsible disclosure and safe operating practices for Girasol.
Core model
Private keys and provider credentials should remain in the operator’s environment. Dry-run is the default in the public Solana repository. Use a dedicated wallet with limited funds.
Responsible disclosure
Do not publish an exploitable issue before maintainers can investigate. Contact @girasolsupportbot or the official @girasolbot account with a minimal non-destructive report. Never send private keys, seed phrases or live API secrets.
Official software
Use only links from this domain and github.com/girasolbot/girasolbot. Verify release notes and checksums when release artifacts become available.
Safe deployment
Keep control panels on loopback or a private network, rotate exposed credentials, restrict filesystem permissions and review configuration before enabling real execution.