Verifiable trust
Lite security and evidence
Threat model, manifest, authorities, and reporting channel.
- The upgrade authority was permanently revoked; the manifest publishes the evidence.
Public deployment evidence
FinalizedThe upgrade authority is revoked; consult the manifest for the release state.
A5jfds9W9rEtVUoEWRgNYVVTiYyM8jYKVyt5vdSF72CY6uFJN2fJTj8hcBnsr3HEauM3hUahnKxCWn8gRcAgaRPH44386916322na4enfzv1DegyYc5wdApQrsmSLv7nQ9jod1FQxgoJZ3TkdyyxjzaV6nzt5q3F8Z56PLNbkypGXHFVMNVeSxULc5eb5ac97fa3fc2273b819fc629eaa37f037adda6bc71d2a23bd64b92b2afd7ba10504Revoked998075213723425303bc645d9285995f22247a49441c76ec790b35b28a17ebbbWhat protects ownership
The Lite Program ID, ProgramData account, name-derived PDA, reproducible hash, and upgrade-authority state form the public evidence. The manifest records that the upgrade authority is revoked and the finalized program is immutable.
Actual authorization
Registration, transfer, and owner changes require the wallet signatures defined by the ABI. The interface never needs a seed phrase or private key.
Wallet visibility
A Lite name is a raw custom PDA record. Most wallets will not automatically display it as a rich collectible with an image and description; that generally requires an integrated asset standard or an explicit wallet integration. TOCNP does not create a second transferable asset whose owner could diverge from the canonical Lite record.
Report a vulnerability
See security.txt. It is the canonical source for the currently configured reporting channel and policy.