Section 14
Security, Privacy and MEV Protection
14.1 Security Principles
- Non-custodial control
- Scoped, revocable permissions
- Deterministic enforcement
- Fail-closed execution
- Data freshness checks
- Trigger deduplication
- Heartbeats and degraded-state handling
- Emergency pause controls
- No AI permission expansion
14.2 AI Boundary
AI-assisted systems may monitor selected conditions and coordinate approved workflows.
They cannot choose a user's investments, change a strategy, expand permissions or override enforced limits.
14.3 MEV-Aware Execution
INDEXLA intends to use MEV-aware execution mechanisms where supported to reduce exposure to front-running and sandwich attacks. No mechanism can eliminate all MEV or execution risk.
14.4 Privacy
INDEXLA is designed for wallet-first access without requiring a traditional platform account for the non-custodial core experience.
This does not mean anonymity. Blockchain addresses, transactions and holdings may remain publicly observable.
The objective is to minimize unnecessary platform-level identity exposure while protecting execution where supported.
14.5 Reviews
Independent smart-contract reviews, audits and a public bug bounty are planned before broad production deployment.
