> For the complete documentation index, see [llms.txt](https://ura-labs-1.gitbook.io/ura-documentation/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ura-labs-1.gitbook.io/ura-documentation/security-and-trust.md).

# Security & Trust

Custody facts, trust boundaries, limitations and responsible disclosure.

Ura documents trust boundaries directly. Privacy and non-custody claims are limited to what the protocol actually enforces.

## Core boundaries

* NIGHT remains with the provider in the bounded Model A path.
* Generated DUST at the external receiver is controlled by the receiver/operator key.
* Cardano transaction detection is not treated as strict bridge finality; Mithril certification is required.
* Midnight submission and indexer confirmation are recorded separately from Cardano certification.
* On-chain credit replay protection is enforced in the proven bridge path.

## Current limitations

* Ura is operating on Preprod.
* The system is not presented as audited or production-ready.
* Generalized wallet authorization is unresolved.
* Complete public verification tooling and production-grade multi-operator failover are unfinished.
* Broader asset routes remain future work.

## Responsible disclosure

Do not publish active vulnerabilities, secrets, operator endpoints or exploit instructions. Security reports should be shared privately with Ura Labs so they can be classified and resolved before public disclosure.

Production credentials, private operational runbooks, receiver keys, partner configuration and unreleased routing logic are intentionally excluded from these public docs.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://ura-labs-1.gitbook.io/ura-documentation/security-and-trust.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
