Decision guide · mid-funnel

Audit PDF vs Trust Passport

$16.65B already left after people trusted a report. A firm PDF dies when the code moves. An open contest report does too, and pays copies while it is still live. A firm PDF cannot close this. An open contest cannot. We run a contest with 4x coverage, then keep a live page that shows what was checked and if the code still matches.

Last updated: 2026-07-22

Audit PDF / contest report

Point-in-time deliverable

Deep findings on a locked commit. Signal ages when code upgrades.

Trust Passport

Living proof page

Our solution: reviewed scope, fixes, live match, open gaps. Shareable after ship.

Choose your product path

Side-by-side comparison

NeedAudit PDF / contest reportTrust Passport (Proof of Audits)
What it isPoint-in-time security review deliverableLiving proof page: evidence + gaps + status
Tied to live code?Only if someone re-checks after upgradesDeployment match flags drift vs audited commit
Authority / admin keysOften out of report scope or outdatedMapped roles and missing key-holder proof
Market inspectabilityUsually private or static PDF linkPublic passport (when owner publishes)
Best forFinding bugs before or during releaseKeeping trust signals current after deploy
Does not doGuarantee safety foreverReplace skilled code review or guarantee safety

When the PDF is enough

  • You need deep findings on a locked commit before mainnet.
  • You are mid-contest or private firm engagement.
  • You do not yet have a production deployment to match.

Pair that work with protocol onboarding so evidence does not die in a slide deck.

When you need a Trust Passport

  • Users or LPs ask “is this still the audited code?”
  • You upgraded proxies or modules after the report.
  • You want investor diligence without ad-hoc data rooms.
  • You want wallet-time signals linked to real evidence.

Product recommendation

Live protocols: start at /deployed. Pricing and scoring are product pages, not blog posts: pricing, scoring.

FAQ

Is a Trust Passport the same as an audit report?

No. An audit or contest report is usually a point-in-time PDF for a scoped commit. A Trust Passport is a live proof page that can show whether that evidence still matches deployed code, who holds keys, and what gaps remain open.

Why is a contest PDF not enough for users?

Users still cannot see if this function was reviewed, if the fix was proven, if live bytecode matches, or what is still open. Duplicate pay and cherry-picking also mean the PDF may never have covered the function they are about to call.

Do I still need a smart contract audit if I use Proof of Audits?

You still need human review. Proof of Audits is the contest those reviewers run inside, plus the passport after. Specialists do the deep work. We keep match, authority, and residual gaps inspectable after the report.

Which should I choose first if my protocol is already live?

Start with a gap map against live addresses and existing reports. Pay only to close confirmed holes, then publish a passport when you approve.