
Defence-in-depth security for the Vault, the TOASTs, and every builder who refuses to hand their jam to the old banks.
This page is maintained by Pass The Jam to answer common security and privacy questions about the protocol. It describes the controls we have built, the platform capabilities we rely on, and the responsibilities that remain shared between us, our users, and the underlying infrastructure providers.
Pass The Jam does not store your private keys, mint unauthorised tokens, or commingle reserve capital with day-to-day operating wallets. Every design choice starts from one assumption: the people who create value must keep control of it.
We secure the protocol contracts, the application layer, the custody structures, the reserve logic, and the infrastructure that serves the site. We publish the rules, enforce them in code, and monitor for abuse.
You keep your wallet seed phrase and private keys safe, verify transaction details before signing, use a hardware wallet where possible, and only interact with official Pass The Jam URLs and contracts.
We are working toward independent smart-contract audits and a formal information security programme. Audit reports and compliance documentation will be published or made available to qualified counterparties once complete.
Until then, the protocol runs on transparent, deterministic code: reserve rules, default waterfalls, and issuance mechanics are visible on-chain and documented in the whitepaper. If you are a regulator, investor, or enterprise user and need our latest security pack, please contact us directly.
We welcome responsible disclosure. If you discover a security issue in our application, contracts, or infrastructure, please email us with enough detail to reproduce and remediate it safely.
security@passthejam.com