> Bull Launch docs. Every page is available as Markdown by adding `.md` to its URL; the index is https://bulllaunch.fun/llms.txt. This page on the web: https://bulllaunch.fun/docs/security

# Security

How to report a vulnerability, and what the contracts can and cannot do.

## Reporting a vulnerability

If you find a bug that could put user funds at risk, report it privately through the support panel below, with enough detail to reproduce it. Please do not disclose it publicly, open a public issue, or test it against other people's funds before it is fixed.

Open the support panel from the footer of any page on https://bulllaunch.fun.

## Audits

No audit report is published for this deployment yet. When one is, it will be linked here, next to the addresses it covers.

## What the contracts can and cannot do

- Deployed contracts are immutable. No one can upgrade them, pause them, or reverse a trade.
- Launch liquidity is locked in `LauncherLocker`, which has no withdrawal function, for the tail band from launch and for the graduated position.
- The registry's owner can whitelist or drop base assets and set curves for new launches. That changes what can be launched next, not a pool that already exists.
- Fee claims are restricted to a pool's creator or a hook operator, and a claim only ever pays the creator and the Treasury.

> Bull Launch will never ask for a private key or seed phrase, and never asks you to send funds to fix, verify or unlock anything. Anyone who does is not us.
