Trust
How fees, refunds and custody work, where the real Trenchaura lives, and what has changed.
Fee on success, by construction
The platform fee is a plain SOL transfer placed inside the same transaction as the action it pays for (a deployment, a launch). Solana executes a transaction completely or not at all, so if the mint, metadata or buy fails, the fee transfer fails with it and nothing leaves your wallet. The server only records a deployment after it has read the confirmed transaction from the chain and seen both the mint and the fee transfer in it.
Current fees: 0.1 SOL per launch (standard token, pump.fun launch or liquidity pool) on the Free plan; none on Pro ($199 per 30 days or $1,499 lifetime at list price, paid in SOL at the live Pyth SOL/USD price, which is locked for 15 minutes when you start paying and shown before you sign). Discounts are set on the server with a start, an end and a cap, and the price you pay is recorded with the payment. Volume, airdrops and exits carry no Trenchaura fee; they cost network fees and the venue's own fees, shown before you sign. The full list is on the pricing page, which renders from the same definition the server charges from.
Refunds
Because fees are only ever paid inside a successful transaction, there is no failed-action fee to refund. Pro is paid with a transfer to the treasury that the server verifies on-chain before activating the pass; if the transfer confirms but the activation step fails (for example your connection drops), the Upgrade page shows the signature and a "Record this payment" button that claims it again at no cost. Pro that has been activated is not refundable, since the access it grants cannot be returned. Network fees and rent go to the Solana network and are never held by Trenchaura.
Custody and security posture
- Trenchaura never holds your main wallet's key. Every transaction is signed by your wallet extension or, for sub-wallets, inside your browser tab.
- Sub-wallet keys are generated in your browser and encrypted there with a key derived from a signature only your wallet can produce. The server stores the ciphertext and the public addresses; it cannot decrypt them.
- Sign-in is a free message signature, never a transaction. Sessions are server-side and can be ended from Settings.
- The server never logs keys, seeds or request bodies. Logs carry a request id, route, status and timing. What the server can see is documented in the docs.
- Every chain read and send goes through the app's own RPC proxy with an allow-list, rate limits and failover; a Content-Security-Policy only lets scripts load from this site itself, so no third-party script host can run on the page. The wallet picker's stylesheet loads one font from Google Fonts; that is a stylesheet and a font file, not a script.
- The Volume Engine and Exit run entirely in your tab; nothing trades while the tab is closed.
Canonical links
The only official Trenchaura is https://trenchaura.com. Sign-in messages name this host; a sign-in request from any other host is not Trenchaura. No official social accounts are listed here yet; when they exist they will be added to this page and nowhere else first.
Changelog
2026-10-04
- Name and logo
- The name is settled as **Trenchaura**, with the new wordmark in every bar, icon and preview image. Sub-wallet vaults are keyed to the name: vaults made during testing before this date no longer open and were removed.
- Fixed
- pump.fun launches with sub-wallet buys: the sub-wallet buys were refused by the program. They now land with the launch.
- Take-profit ladder: it could fail to arm on a new coin and read the price in coarse steps. It now reads the price from a quote large enough to be exact.
- Airdrop: taking a holder snapshot failed in the browser; a minimum balance too large to be an amount showed every holder as eligible. Both fixed.
- Upgrade page: no longer jumps while your plan and the price load.
- New
- Token images can be positioned and resized before upload, on the token and pump.fun forms.
- Launch bundles go from your browser straight to Jito, with the server as a fallback.
- The shared RPC is divided fairly between users, so one busy user cannot slow the others.
2026-10-03
- Logo and icons
- The Trenchaura mark and lockup from the brand pack replace the text wordmark in the top bar, the phone menu, the landing page, the terminal sidebar and the operator portal. New favicon, app icon, Apple icon and social-preview image.
- Name
- The product is now **Trenchaura**. Every page, document, file name, the session cookie, the on-chain payment memo prefix (`trenchaura:pro_pass:…`) and the webhook signature header (`x-trenchaura-signature`) carry the new name. Existing sessions are signed out once; webhook receivers that checked the old header name need the new one. Vaults are unaffected: their key label is frozen on purpose.
2026-10-02
- Plans
- Two plans: Free (no upfront cost; a 0.1 SOL platform fee inside each launch transaction, shown before signing) and Pro (no platform fees, bundled launches, Volume Engine, Airdrop sending, Exit, 500 sub-wallets). Earlier Based and Whale passes count as Pro. Renewing early extends from the current end date.
- Pro is priced in US dollars, $199 per 30 days or $1,499 lifetime, and paid in SOL at the live Pyth SOL/USD price. The SOL amount is locked for 15 minutes when you start paying and shown before you sign. If the price feed is stale, upgrades pause instead of charging a wrong amount.
- Launch offer: $99 per 30 days or $999 lifetime for the first 500 users, until 31 December 2026. Pricing and Upgrade show the list price struck through, the end date and the spots left.
- Discount codes can be entered on Upgrade. The best price you qualify for applies; codes and offers do not stack.
- Prices show the SOL figure first (at the live rate) with the dollar anchor second, on Pricing and Upgrade.
- Free now holds 3 sub-wallets (was 5), keeps one notification channel (webhook or Telegram) and no longer exports the transaction CSV; those are Pro. Existing vaults above the limit keep their wallets.
- Operator portal and support
- A private `/admin` area for the owner (wallets listed in `ADMIN_WALLETS`): health (database, RPC, SOL/USD price age), users and plans, sales with USD at the time and CSV, discounts (same rules as the command-line tool), launches, support inbox, maintenance mode and an audit log of every operator action. Everyone else gets a plain 404.
- **Support**: users open tickets from the dashboard, read replies and close them; the owner answers in the portal and can get a Telegram ping.
- **Maintenance**: a banner on every page, or a full lockout with the owner's message and an optional window; operators bypass it. See `docs/OPERATOR.md`.
- Pro tools
- **Staged launches** on the pump.fun form: choose how many sub-wallets buy in the launch block and spread the rest over later blocks with randomised gaps; later buys are re-quoted on the live curve when sent, and a staged launch can use more wallets than one bundle holds.
- **Launch self-check** on the pump.fun form: a grade from A to F and every flag GMGN, Axiom, Bubblemaps, RugCheck and Trench will show for this exact launch (bundled share, creator share, insiders, largest wallet, identical sizes, wallets funded straight from yours), each with the terminals that show it and what to change. Funding links are read from the chain on request.
- **Launch templates**: save the reusable part of a launch (creator buy, slippage, sub-wallet amounts, links) under a name and apply it to a new launch in one click. Token name, ticker and image are never part of a template.
- **Take-profit ladder and sniper rule** on Exit: set steps ("sell 25% at 2× entry, 25% at 3×, 50% at 5×"), an optional sniper rule (sell a share if a stranger's buy of at least N SOL lands within the first seconds after launch) and a floor; arm it on a token and the tab watches the live price every few seconds, selling from each sub-wallet with normal signed transactions, each listed with its signature and recorded.
- **Positions**: per wallet and token, SOL spent, SOL received, realised result, the live balance and what selling it now would return, with totals and CSV. Launch buys are now recorded per wallet so the cost side is complete for launches made here.
- Loading
- Pages no longer slide into place: nothing moves after first paint, the address, drafts, plan and token list keep their space while they load, and the wallet warning waits for the wallet to reconnect. Measured on every page at 320, 390, 834, 1440 and 1920 px.
- Phone tap targets on chips, range buttons and row actions are at least 36 px tall.
- Public pages
- The top bar stays on screen while you scroll and turns solid once the page has moved. Anchors and keyboard focus land below it.
- Tutorial: the guide list no longer scrolls or shows a scrollbar; only the guide moves.
- Docs uses the same bar, background and card layout as the other public pages, with a fixed section list.
- Pro tools are visible to everyone: Free users see them blurred and locked with an Upgrade card, and the sidebar marks them. "Pro Pass" is now **Upgrade**, shown only to Free users.
- Launching
- A Launch hub explains the three paths (pump.fun launch, standard token, liquidity pool) with a comparison; each form switches to the others.
- Launch forms save drafts on your account as you type; the Overview lists them with Continue and Delete.
- Standard tokens choose the token program (Classic SPL or Token-2022) separately from authorities, and suggest opening a pool next.
- On devnet, a Get test SOL helper asks the faucet and falls back to the web faucet with your address.
- Overview and Analytics
- Overview: quick actions, drafts, an analytics preview for your latest token, and token rows with Analytics, Add pool, pump.fun and Explorer links.
- Analytics: opens a linked token, adds pump.fun bonding-curve progress, SOL in curve and market cap, 24-hour activity and holder share bars.
- Site and sign-in
- Landing: rotating lines in place of the big title, the colourful hover reveal restored, and the hero stacked cleanly on phones.
- New Features and Pricing pages; the Tutorial's guide list stays on screen; every public page has a phone menu.
- Sign-in: Connect wallet with Trenchaura's own wallet picker, three visible steps, and a plain explanation of the free signature and its nonce.
2026-10-01
- Launch, trade and exit
- pump.fun launches: create the token and buy from your wallet in one transaction, add sub-wallet buys (Pro Pass), a live bundled-share preview quoted from the curve, a review step with exact amounts before signing, and a verified per-transaction landing report afterwards. Mainnet sends the set as one Jito bundle; devnet sends sequentially.
- Raydium pools: open a CPMM pool for any token you hold, with fees read from Raydium's on-chain config, existing-pool detection, a review step, and a one-click LP burn.
- Volume Engine (Pro Pass): buy and sell cycles from your sub-wallets on the token's live market, every signature listed and read back from the chain, pause when the tab is hidden, graceful stop, trades recorded under your account.
- Exit (Pro Pass): sell every sub-wallet's holding at once or staged, quoted before signing, then sweep SOL and rent back.
- Airdrop: holder snapshots with CSV export; pass-gated multi-send with the exact cost shown first.
- Analytics: supply, holders, concentration, your wallets' share, recent activity, third-party market data labelled as such, and a CSV export of your own transactions.
- Foundations
- Token deployment with on-chain metadata and self-hosted images; the platform fee sits inside the deployment transaction, so a failed deployment charges nothing.
- Sign-In-With-Solana sessions; sub-wallet vault encrypted in your browser (the server stores ciphertext only); fund and sweep with batch confirmation.
- Pro Pass purchases verified on-chain; pricing page, dashboard and server fee check driven by one definition.
- Settings: custom RPC endpoint, priority fee, deploy defaults, session management.
- Every transaction: simulate, set fees, sign, send, confirm, with each stage shown and linked to an explorer.
- Quality
- Design tokens and shared components; WCAG AA contrast on every page; keyboard operable; reduced motion honoured; phone navigation covers every section.
- Structured request logs, `/api/health`, error pages with a reference, graceful shutdown, container health checks.
- Unit, integration and browser tests in CI, including failure cases (rejected signature, RPC outage, malformed input).
2026-09-28
- Project created.