> ## Documentation Index
> Fetch the complete documentation index at: https://docs.eco.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Security and audits

> Security boundaries, audit references, API key handling, and issue reporting.

## Routes

* **Per-intent rewards.** Vaults hold rewards separately, but share contract implementations and depend on the selected prover and token contracts. See [Vaults and resource locks](/concepts/vaults).
* **Proof-based settlement.** The source Portal reads the intent's configured prover before withdrawing the reward. Review that prover's verification and configuration; implementing the interface is not a security guarantee. See [Provers](/routes/architecture/provers/overview).
* **Separate execution.** Destination calls run through the Executor. A reverted call rolls back that destination transaction, while source funding and refunds follow their own lifecycle. See [Executor](/routes/architecture/executor).
* **Quote signatures.** Verify a v1 quote against the published `quoteSigner` and check its amounts, recipients, and execution instructions before funding. A valid signature authenticates the signed quote fields; it does not establish every downstream call's business outcome. See [Quote verification](/api-reference/quote-verification).

Match the contract source and ABI to the actual deployment. A non-upgradable contract or a published audit does not eliminate contract, token, or integration risk.

## Sauce

On EVM, a Pot's `cook` operation is owner-only. For an intent route, the destination Portal's Executor owns the Pot. A public batcher that controls a Pot can expose that ownership to its callers; use the ownership constraints described in the [settle guide](/cookbook/sauce/settle).

Upgradeability depends on the component and release. Kitchens are upgradeable, and Solana engine 1.2.0 retains an upgrade authority. See [Sauce architecture and deployments](/programmable-transactions/sauce/architecture-and-deployments) for the current deployment details, and the [compiler API](/sdk-reference/sauce-compiler/api) for known compiler limitations.

## Audit reports

Consult the [Cantina portfolio](https://cantina.xyz/portfolio/f4ef1cd6-860e-4f58-82de-09751baea324) for published reviews and any listed bounty program. Match each report's scope and reviewed commit to the component and release you use.

## API keys

Keep API keys on your server and send them in the `x-api-key` header. Do not embed them in client applications, URLs, or logs. See [Get set up](/get-started/setup#api-keys-and-attribution).

## Reporting an issue

Report security issues privately to [contact@eco.com](mailto:contact@eco.com). For a repository with its own security policy, follow that policy; Permit3 accepts [private vulnerability reports](https://github.com/eco/permit3/security).
