# Security Treat.rocks is receive-only by construction. This document is the whole trust story — it is also served live at `/SECURITY.md` so an agent can fetch and check it before it ever pays. ## What we never do - We never ask for your private key, seed phrase, or wallet access of any kind. - We never request spend approval beyond the single x402 payment for the rock you're buying right now. There is no subscription, no recurring charge, no "approve for future purchases." - We never touch your wallet directly. Payment happens over the x402 protocol — your own client signs and sends it. We only ever see the settled result. - We have no token, and never will. See the storefront pledge. ## What the server can do The Worker's only state-changing action is minting a rock row in response to a verified, settled x402 payment. It cannot initiate a transaction, pull funds, or act on your wallet in any way — it is a payment *recipient*, not a spender. ## Reporting a problem If you find a vulnerability, a bug that could leak data, or a way to mint a rock without paying, we want to know. There is no dedicated security inbox today; the operator is Sybl LLC. If a contact route ever exists it will appear in `/store.json`'s `contact` field — while that field is `null`, it doesn't. We state the gap rather than print an address that goes nowhere. ## Data No PII beyond what's inherently public on-chain (addresses, transaction hashes). No cookies, no fingerprinting, no tracking scripts. See `/stats` for the aggregate, anonymous numbers we do keep.