Robots in the real world.
Paranoia in the stack.
Machines that move around people don't get to have a casual security story. Every layer of Loxley — chain contracts, OTA pipeline, on-robot runtime — is independently audited, and the findings are public.
Published reports
Settlement contracts (Q1), OTA pipeline (Q2), LoxOS boot chain (Q2) and the royalty splitter (Q3) — every report is public in full, including what we got wrong.
Double-signed builds
Author signature plus on-chain anchor, verified on-device before flashing. There is no code path that flashes an unverified manifest — we removed it, then audited the removal.
Capability sandboxes
Third-party skills run capability-scoped: sensor reads in, actuation intents out, nothing else. Escapes are bounty-class events, and so far the record is clean.
Live bug bounty
Up to 250,000 $LOX for critical findings in the settlement path or the OTA chain. Scope, rules and past payouts are public. security@loxley.work.
Sim as a safety layer
Security review covers behavior too: adversarial scenarios — sensor spoofing, crowd surges, GPS denial — ship as first-class sim presets every quarter.
Incident policy
Kill-switch rollouts propagate to a full fleet inside one wave cycle. Post-mortems publish within 14 days, named and dated. No silent patches.
Found something?
Report it through the bounty program — critical findings in the settlement or OTA path pay up to 250k $LOX.