Verifiable trust

Lite security and evidence

Threat model, manifest, authorities, and reporting channel.

  • The upgrade authority was permanently revoked; the manifest publishes the evidence.

Public deployment evidence

Finalized

The upgrade authority is revoked; consult the manifest for the release state.

Program IDA5jfds9W9rEtVUoEWRgNYVVTiYyM8jYKVyt5vdSF72CY
ProgramData6uFJN2fJTj8hcBnsr3HEauM3hUahnKxCWn8gRcAgaRPH
Deployment slot443869163
Deployment signature22na4enfzv1DegyYc5wdApQrsmSLv7nQ9jod1FQxgoJZ3TkdyyxjzaV6nzt5q3F8Z56PLNbkypGXHFVMNVeSxULc
ELF SHA-2565eb5ac97fa3fc2273b819fc629eaa37f037adda6bc71d2a23bd64b92b2afd7ba
ELF bytes10504
Upgrade authorityRevoked
Release manifest SHA-256998075213723425303bc645d9285995f22247a49441c76ec790b35b28a17ebbb

Download the TOCNP-LITE manifest

What protects ownership

The Lite Program ID, ProgramData account, name-derived PDA, reproducible hash, and upgrade-authority state form the public evidence. The manifest records that the upgrade authority is revoked and the finalized program is immutable.

Actual authorization

Registration, transfer, and owner changes require the wallet signatures defined by the ABI. The interface never needs a seed phrase or private key.

Wallet visibility

A Lite name is a raw custom PDA record. Most wallets will not automatically display it as a rich collectible with an image and description; that generally requires an integrated asset standard or an explicit wallet integration. TOCNP does not create a second transferable asset whose owner could diverge from the canonical Lite record.

Report a vulnerability

See security.txt. It is the canonical source for the currently configured reporting channel and policy.