> ## Documentation Index
> Fetch the complete documentation index at: https://docs.route.fun/llms.txt
> Use this file to discover all available pages before exploring further.

# Security

> Official Route domains, wallet checks and security limitations.

## Official domains

* [Swap website](https://www.route.fun)
* [Public API](https://api.route.fun)
* [Documentation](https://docs.route.fun)
* [Official account](https://x.com/routedotfun)

`route.fun` redirects to `www.route.fun`. The experimental design site is a preview, not the production swap site. Check the full hostname before connecting a wallet. Route never needs your seed phrase or private key.

## Wallet and transaction review

Route connects external wallets. Review the network, token addresses, approved spender, input amount, recipient, minimum output, expiry and gas in your wallet before signing. A logo or successful wallet connection does not verify a token. Disconnecting or changing the wallet invalidates an in-progress Route wallet session.

The API builds transactions; your wallet authorizes them. Exact input, safe approval amounts, minimum-output checks and simulation reduce particular risks but do not guarantee a successful or profitable swap. See [quotes and execution](/concepts/quotes-and-execution).

## Contract verification and audit status

Route's contracts are **not independently audited**. A verified source match is not an audit or a guarantee of safety.

The activated swap-fee collector on Robinhood Chain (4663) is `0xBFADcf357545cb185420eAD0fDE1008A289c0154`. Its fixed receiver is `0xcCeb9655af6877D5c8c2919902c356beD71Fa1Fc`, which credits manager `0xDa5790345FD25878e5186EBd98823814188AcfBE`. These contracts have exact Sourcify source matches. The treasury Safe is `0x3b9C7bC09FF64F554480f30Ad40286cFc09d2F80`.

These addresses explain the fee flow; they are not instructions to send funds or approve every listed address. Review the spender in the specific current transaction. [Current API configuration](/api-reference/v2-config) and [fees](/concepts/fees) explain the active configuration.

## Service protections

Public quote and swap requests have separate concurrency and caller quotas. The public RPC gateway restricts methods, batch size, body size, response size and concurrency. Rate limits are per runtime and do not provide unlimited protection against distributed traffic. Respect HTTP 429 and Retry-After rather than retrying immediately.

Browser security controls and reputation labels do not replace wallet review or contract audits. A vendor can incorrectly flag a legitimate site, and a clean reputation result does not prove a site is safe.
