The Based Protocol is implemented as immutable code in its deployment address with access controls to allow for changing of the Market implementation. The Protocol and its peripheries have been reviewed by third-parties.
For any responsible disclosures, please contact security (at) basedapp (dot) com.