Decision guide · mid-funnel

Audit PDF vs Trust Passport

You already know audits matter. The decision is whether a static report is enough — or you need living proof the market can inspect after deploy.

Last updated: 2026-07-22

Audit PDF / contest report

Point-in-time deliverable

Deep findings on a locked commit. Signal ages when code upgrades.

Trust Passport

Living proof page

Reviewed scope, fixes, live match, open gaps — shareable after ship.

Choose your product path

Side-by-side comparison

NeedAudit PDF / contest reportTrust Passport (Proof of Audits)
What it isPoint-in-time security review deliverableLiving proof page: evidence + gaps + status
Tied to live code?Only if someone re-checks after upgradesDeployment match flags drift vs audited commit
Authority / admin keysOften out of report scope or outdatedMapped roles and missing key-holder proof
Market inspectabilityUsually private or static PDF linkPublic passport (when owner publishes)
Best forFinding bugs before or during releaseKeeping trust signals current after deploy
Does not doGuarantee safety foreverReplace skilled code review or guarantee safety

When the PDF is enough

  • You need deep findings on a locked commit before mainnet.
  • You are mid-contest or private firm engagement.
  • You do not yet have a production deployment to match.

Pair that work with protocol onboarding so evidence does not die in a slide deck.

When you need a Trust Passport

  • Users or LPs ask “is this still the audited code?”
  • You upgraded proxies or modules after the report.
  • You want investor diligence without ad-hoc data rooms.
  • You want wallet-time signals linked to real evidence.

Product recommendation

Live protocols: start at /deployed. Pricing and scoring are product pages, not blog posts: pricing, scoring.

FAQ

Is a Trust Passport the same as an audit report?

No. An audit report is usually a point-in-time PDF for a scoped commit. A Trust Passport is a live proof page that can show whether that evidence still matches deployed code, what authority controls exist, and what gaps remain open.

Do I still need a smart contract audit if I use Proof of Audits?

Yes for deep code review. Proof of Audits does not replace auditors or contest firms. It makes audit and deployment evidence inspectable after the report — match, authority, and residual gaps.

Which should I choose first if my protocol is already live?

Start with External Deployed review: submit live addresses and existing audit PDFs for private scoring and a passport preview, then publish when you approve.