Security
Coming at TGEWATT INU is pre-TGE. The practices below describe internal operating posture today, not a completed third-party security audit. No contract audit exists yet — see Transparency for verified addresses and audit status.
Multi-factor authentication
Admin access to WATT internal systems requires MFA. This governs internal operator access — it does not imply any user-facing account system.
Role-based access control
Admin and treasury-adjacent actions are gated by role. No single operator can unilaterally move Vault or Project Fee Receiver funds.
Audit logging
Administrative actions in internal tooling are logged for accountability. This is an operational log, not a third-party security audit of the contracts.
Secrets handling
Seeds, private keys, and recovery phrases are never requested, stored, logged, or placed in code, prompts, or documentation. Environment variables and secret managers only, with least privilege.
Human approval gates
TGE, signing, treasury/Vault movement, tokenomics or fee/pair changes, and other irreversible financial actions require explicit owner approval — they are never automated.
Incident response
No incidents have occurred. If one does, it will be disclosed here honestly, including what happened, impact, and remediation — never minimized or omitted.