> ## Documentation Index
> Fetch the complete documentation index at: https://docs.mecone.trade/llms.txt
> Use this file to discover all available pages before exploring further.

# Security overview

> Security practices, integration guidance, and how to contact Mecone.

Mecone provides benchmark, index, analytics, API, and signed-data services. This page describes selected practices supporting those services and the checks customers should apply when integrating them.

## Development and change review

Our engineering workflow uses private GitHub repositories, pull requests, automated checks, and deployment records. Changes to the main application repository require an approving review before merge.

## Data access and protection

The [Index API](/api-reference) is served over HTTPS. Public endpoints and authenticated interfaces have different access requirements. Scoped API keys support authorized integrations; credentials should be kept private and used according to the endpoint documentation.

Mecone's S3 data and log buckets have server-side encryption, versioning, public-access blocking, and cross-region replication configured. These measures support storage protection and recovery. They do not establish a guaranteed database or full-service recovery time.

## Signed data and operational status

The [signed-round documentation](/oracle/signed-rounds) describes how to retrieve and verify signed outputs. Consumers must check the applicable signature, timestamps, and validity constraints before using a value. A valid signature or successful connection alone does not establish that a value is fresh enough for a particular use.

The [public status page](https://status.mecone.trade) reports current service checks. See [release notes](/changelog) for documented updates. Current health checks are observations and do not provide historical uptime statistics.

## Security questions and concerns

Contact [info@mecone.trade](mailto:info@mecone.trade) with security questions or a brief description of a suspected issue. Include the affected service and relevant time, and leave credentials, private keys, and sensitive customer data out of the initial message.

Customers remain responsible for protecting their own credentials, controlling access within their integrations, and applying the documented validation rules to the data they consume.
