Este documento define las políticas de seguridad técnica y operativa del proyecto DOA Token.
Su objetivo es garantizar integridad, protección de activos y confianza de la comunidad y exchanges.
This document defines the technical and operational security policies of the DOA Token project.
Its purpose is to ensure integrity, asset protection, and trust from the community and exchanges.
.env nunca deben compartirse ni almacenarse en repositorios públicos. / Private keys and .env files must never be shared or stored in public repositories.changelog.md y audit-log.md. / Every change must be recorded in changelog.md and audit-log.md..env para credenciales y configuraciones sensibles. / Mandatory use of .env for sensitive credentials and configurations.gitignore para evitar exposición de archivos críticos. / Inclusion of gitignore to prevent exposure of critical files.monitor-liquidez.js) deben registrar logs claros y auditables. / Monitoring scripts (monitor-liquidez.js) must record clear and auditable logs.audit-report.md. / Periodic audits documented in audit-report.md.governance-roles.md. / Repository access limited by roles defined in governance-roles.md.releases.md). / Integrity validation in each release (releases.md).announcement.md. / Publication of security incidents in announcement.md.governance-log.md). / Transparency in governance votes related to security (governance-log.md).community-metrics.md. / Inclusion of security metrics in community-metrics.md.audit-checklist.md, audit-log.md y audit-report.md.This file complements audit-checklist.md, audit-log.md, and audit-report.md.
It must be reviewed and updated every six months or after any relevant incident.
Última actualización / Last update: Enero 2026