Decision guide · mid-funnel
Audit PDF vs Trust Passport
$16.65B already left after people trusted a report. A firm PDF dies when the code moves. An open contest report does too, and pays copies while it is still live. A firm PDF cannot close this. An open contest cannot. We run a contest with 4x coverage, then keep a live page that shows what was checked and if the code still matches.
Last updated: 2026-07-22
Point-in-time deliverable
Deep findings on a locked commit. Signal ages when code upgrades.
Living proof page
Our solution: reviewed scope, fixes, live match, open gaps. Shareable after ship.
Choose your product path
Searchers comparing “audit report” vs “ongoing proof” need a product decision, not another definition. Use the table, then pick the action that matches your stage.
Side-by-side comparison
| Need | Audit PDF / contest report | Trust Passport (Proof of Audits) |
|---|---|---|
| What it is | Point-in-time security review deliverable | Living proof page: evidence + gaps + status |
| Tied to live code? | Only if someone re-checks after upgrades | Deployment match flags drift vs audited commit |
| Authority / admin keys | Often out of report scope or outdated | Mapped roles and missing key-holder proof |
| Market inspectability | Usually private or static PDF link | Public passport (when owner publishes) |
| Best for | Finding bugs before or during release | Keeping trust signals current after deploy |
| Does not do | Guarantee safety forever | Replace skilled code review or guarantee safety |
When the PDF is enough
- You need deep findings on a locked commit before mainnet.
- You are mid-contest or private firm engagement.
- You do not yet have a production deployment to match.
Pair that work with protocol onboarding so evidence does not die in a slide deck.
When you need a Trust Passport
- Users or LPs ask “is this still the audited code?”
- You upgraded proxies or modules after the report.
- You want investor diligence without ad-hoc data rooms.
- You want wallet-time signals linked to real evidence.
FAQ
Is a Trust Passport the same as an audit report?
No. An audit or contest report is usually a point-in-time PDF for a scoped commit. A Trust Passport is a live proof page that can show whether that evidence still matches deployed code, who holds keys, and what gaps remain open.
Why is a contest PDF not enough for users?
Users still cannot see if this function was reviewed, if the fix was proven, if live bytecode matches, or what is still open. Duplicate pay and cherry-picking also mean the PDF may never have covered the function they are about to call.
Do I still need a smart contract audit if I use Proof of Audits?
You still need human review. Proof of Audits is the contest those reviewers run inside, plus the passport after. Specialists do the deep work. We keep match, authority, and residual gaps inspectable after the report.
Which should I choose first if my protocol is already live?
Start with a gap map against live addresses and existing reports. Pay only to close confirmed holes, then publish a passport when you approve.