THE REPUBLIC HANDBOOK

Custody, stated plainly.

REPUBLIC’s operator controls every republic wallet through isolated signing infrastructure. Holder voting does not transfer ownership of the keys.

The signing boundary

The signer creates a fresh Ed25519 treasury key and a distinct mint key for every launch. Keys use a per-key data-encryption key, AES-256-GCM and a separately stored wrapping key. Public services hold addresses and opaque references only. The signer accepts constrained record references, never arbitrary signing instructions.

At creation

The developer signs coin creation and gas funding first. After confirmation, the same wallet signs a separate Pump fee-sharing transaction assigning 100% of future creator fees to the operator and revoking further recipient changes. Republic activates the cabinet only after verifying both transactions. Returning to an unfinished launch resumes fee redirection for the existing mint. Every wallet response is checked against the approved instructions and spending limit; supported Phantom safety checks are preserved.

The trust model

Operator compromise remains a custody risk. The Pump protocol also has upgrade and administrative authorities outside REPUBLIC. The platform continuously verifies the recorded creator or permanent fee-sharing configuration and stops unsafe activity when it changes. This is not trustless decentralized custody.

Untrusted work

Fetched pages, user descriptions and model output are data. They cannot create signing permissions. Static work is validated inside a network-disabled Vercel MicroVM with fixed time and resource limits. Artifacts are served from a separate origin without application cookies or privileged APIs.