Security
What the code guarantees, who holds which keys, and what still requires trust.
Upgrade authority caveat: Solana programs are upgradeable unless their upgrade authority is revoked. Whoever holds that authority could deploy different code, including code that moves vault funds. Check the program's upgrade authority on Solana Explorer (linked from the transparency page); a revoked authority, or one held by a public multisig with a timelock, removes or limits this risk.
The keeper holds an operator key that can start rounds, commit snapshots and request randomness; it cannot move funds. The website holds no private keys at all. Admin pages require a signed, single-use, domain-bound sign-in message plus an on-chain admin check on every request, and every privileged action is a transaction the program authorizes on its own. See Transparency for what remains trusted.
Found a vulnerability? Please disclose it privately to [CONTACT EMAIL]. Do not test against mainnet funds.