> For the complete documentation index, see [llms.txt](https://docs.jefetoken.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.jefetoken.com/jefe-token/faq/technical-and-security.md).

# Technical & Security

**Has JEFE been audited by a third party?**\
Not yet. All smart contracts undergo a rigorous internal review process combining AI-assisted code analysis (using large language models) and manual penetration testing by the development team. Third-party audits may be pursued as the ecosystem scales.

**Is the code open-source?**\
Yes. All core contracts are open-source and verifiable on the Sonic blockchain explorer. Anyone can review the code and track on-chain activity.

**How is the treasury secured?**\
Ecosystem funds are held in a multi-signature wallet requiring multiple team members to approve any transaction. This eliminates single points of failure.

**What happens if the AI agent makes a bad trade?**\
The AI agent operates with risk parameters and is not all-powerful. During periods of underperformance, it may temporarily draw capital from the liquidity pool to fund improvements. This can create short-term sell pressure, but the system is designed to return capital plus profits once performance recovers. All AI treasury movements are transparent and verifiable on-chain.

**How can I report a bug or security issue?**\
Contact the development team via the official Discord or email. A formal bug bounty program may be introduced in future phases.
