Security & permissions
A companion with clear boundaries.
Trenchbun has no intended buy, sell, signing or transfer feature. It does not ask for a wallet connection, seed phrase or cryptocurrency private key. Its purpose is to read available information and display companion reactions and research notifications.
What browser access means
To float inside a terminal, Trenchbun adds its interface to that page. Chrome does not provide a strictly read-only content-script permission: granted page access can technically permit reading and modifying page content. The extension is designed to avoid trading controls, but a permission label alone cannot guarantee security.
Permissions, explained
- Storage: save settings, alerts and local state.
- Alarms: schedule enabled background checks.
- Active tab: activate the companion on a supported tab after your action.
- Scripting: load bundled companion and data-reader files into supported terminal pages.
- Optional terminal access: show the bun and read displayed information on the specific sites you enable.
- Optional public-data and cloud access: obtain token information and artwork, process AI requests and perform supported public-post and wallet lookups.
Boundaries in the current build
- Executable extension code is bundled with the package; API replies are data and text.
- Provider API keys stay on the backend.
- AI chat has no tools for trading, signing or operating your terminal.
- The backend's blockchain transport permits a fixed set of public read methods; it does not offer transaction submission.
- Cloud access uses installation sessions and bounded requests rather than trusting an extension ID alone.
These are implementation boundaries, not a promise of absolute safety. Bugs, compromised updates, provider incidents and changing terminal layouts remain possible risks.
Your controls
Enable only the features you want. Use temporary terminal activation if you prefer not to grant persistent access. Revoke optional permissions or disconnect cloud access when no longer needed. Hiding the bun is a visibility control; it is not a substitute for disabling features or revoking access.
Audit status
An independent security audit has not yet been completed. Internal checks and an audit preparation package are not independent certification. We will publish a completed independent report here when one is available, including its reviewed version, scope, findings and remediation status.
Report a security concern
Contact support@trenchbun.fun. Include the extension version, affected feature and safe reproduction steps. Do not send passwords, access codes, API keys, wallet private keys or seed phrases. Avoid posting sensitive exploit details publicly before contacting us.
For information about data handling, read the privacy policy.