Skip to main content
This page summarizes the security guarantees Tachyon stands behind. For the integrator-facing privacy breakdown, see privacy guarantees.

Properties Tachyon guarantees

What Tachyon (the organization) cannot see

  • Intent amounts
  • Intent sender or recipient addresses
  • Intent parameters (token pairs, TWAP slices, payroll amounts, x402 merchant addresses)
  • User viewing keys or viewing permission lists
This is by design. The organization is not in a position to leak data it doesn’t hold.

Threat model summary

For the full per-threat treatment, see privacy guarantees → threat model.

Audits

Audits are in progress. Reports will be published here and linked from this page when complete.

Bug bounty

A formal bug bounty is not active today. Responsible disclosures are still welcome via the channel below.

Status and disclosure

Real-time status is surfaced directly in the user dashboard at testnet.app.tachyon.pe, there is no separate status page today. To report a security vulnerability, email sudeep@tachyon.pe. Please do not open public GitHub issues for security bugs.

Testnet caveats

Tachyon is currently on testnet. The architecture and guarantees are operational on testnet, but you should not use real funds or production data until mainnet launches.

Auditor access

How to wire designated auditors into your integration.