SEND policies

Security at SEND

Creator payments require stronger controls than possession of a username or social account.

Review status: This working policy requires qualified legal review before meaningful production use.

Current controls

SEND uses confirmed direct transfers, replay protection, server-side signing boundaries, idempotent financial operations, append-only ledger entries, delayed withdrawal allowlists, and reconciliation states.

Custody

Creator balances, SEND revenue, buyback allocations, and operating funds are accounted for separately. Production signing material must never enter browser code, prompts, or public repositories.

Audit status

SEND is not represented as independently audited. Meaningful production custody expansion requires devnet testing, independent review, multisig operations, incident response, and legal review.

Responsible disclosure

Security reports should include the affected surface, impact, and reproducible steps. A dedicated bounty and security contact will be published before broader production use.