Decision guide · mid-funnel
Audit PDF vs Trust Passport
You already know audits matter. The decision is whether a static report is enough — or you need living proof the market can inspect after deploy.
Last updated: 2026-07-22
Point-in-time deliverable
Deep findings on a locked commit. Signal ages when code upgrades.
Living proof page
Reviewed scope, fixes, live match, open gaps — shareable after ship.
Choose your product path
Searchers comparing “audit report” vs “ongoing proof” need a product decision, not another definition. Use the table, then pick the action that matches your stage.
Side-by-side comparison
| Need | Audit PDF / contest report | Trust Passport (Proof of Audits) |
|---|---|---|
| What it is | Point-in-time security review deliverable | Living proof page: evidence + gaps + status |
| Tied to live code? | Only if someone re-checks after upgrades | Deployment match flags drift vs audited commit |
| Authority / admin keys | Often out of report scope or outdated | Mapped roles and missing key-holder proof |
| Market inspectability | Usually private or static PDF link | Public passport (when owner publishes) |
| Best for | Finding bugs before or during release | Keeping trust signals current after deploy |
| Does not do | Guarantee safety forever | Replace skilled code review or guarantee safety |
When the PDF is enough
- You need deep findings on a locked commit before mainnet.
- You are mid-contest or private firm engagement.
- You do not yet have a production deployment to match.
Pair that work with protocol onboarding so evidence does not die in a slide deck.
When you need a Trust Passport
- Users or LPs ask “is this still the audited code?”
- You upgraded proxies or modules after the report.
- You want investor diligence without ad-hoc data rooms.
- You want wallet-time signals linked to real evidence.
FAQ
Is a Trust Passport the same as an audit report?
No. An audit report is usually a point-in-time PDF for a scoped commit. A Trust Passport is a live proof page that can show whether that evidence still matches deployed code, what authority controls exist, and what gaps remain open.
Do I still need a smart contract audit if I use Proof of Audits?
Yes for deep code review. Proof of Audits does not replace auditors or contest firms. It makes audit and deployment evidence inspectable after the report — match, authority, and residual gaps.
Which should I choose first if my protocol is already live?
Start with External Deployed review: submit live addresses and existing audit PDFs for private scoring and a passport preview, then publish when you approve.