See what is still covered and what is not
Post-audit deployment assurance
Your audit proves what was reviewed. Prove what is live now.
Connect live contracts to audited code, expose the gaps, and create one versioned Trust Passport.
Plus the confirmed size adjustment
The live launch offer is applied below
Aave V4 public evidence snapshot
chain 1 / block 25,596,250 / 8 contracts
Independent public evidence record
No customer relationship, endorsement, or safety conclusion
Free audit gap review
Let's find what your audits do not cover now.
We connect every relevant audit to the releases that followed it, then compare the last covered state with the deployment running today. You receive the gap map before deciding whether to buy an audit.
Aave V4: eight contracts observed at one exact Ethereum block.
Independent public record, not an Aave engagement or endorsement
At block 25,596,250, Proof of Audits recorded runtime bytecode hashes for eight material contracts and confirmed two EIP-1967 implementation slots.
- Observed: eight contract addresses and eight runtime bytecode hashes at the same block
- Confirmed: Core Hub and Main Spoke implementation slots
- Still open: exact audit-to-commit mapping, authority paths, function coverage, and exit behavior
Choose whether the confirmed gaps should be audited.
No purchase required
Each gap receives a recommended depth based on how far its risk can travel.
- T4: Changed function
- T3: Contract and access
- T2: Cross-contract path
- T1: System and economics
Paid audit price, only if you continue
- 01$250 engagement base
- 02Very Small: +$500, $750 total
- 03Small: +$2,000, $2,250 total
- 04Medium: +$5,750, $6,000 total
- 05Large: +$14,750, $15,000 total
- 06Extra Large: +$34,750, $35,000 total
Same features at every size. The scale, audit depth, reviewer count, and delivery effort change.
Reviewer count: confirmed after the gap review, before payment. It is not guessed from contract count alone.
Never score-linked: the deployed ITS result cannot raise or lower the audit fee.
See full pricing and size limitsThe evidence gap starts after deployment.
A valid audit can still leave investors and users rebuilding today's system from PDFs, explorers, multisigs, repositories, and team claims.
Is the live code still the reviewed code?
Bytecode, proxy implementation, source evidence, and covered hashes are checked together.
Who can change the rules tomorrow?
Upgrade, pause, oracle, treasury, timelock, multisig, and emergency controls are mapped.
Can users still get their assets out?
Withdraw, unstake, redeem, unlock, bridge, and emergency exit paths are reviewed.
Who answers when the evidence is challenged?
Role binding, interviews, and accountability evidence connect claims to responsible people.
Public evidence snapshot
Real observations stay separate from open proof.
This Aave V4 record shows what was observed at one exact block and keeps unproven audit, authority, function, and exit relationships visibly open.
The official audit reports have not yet been mapped to exact commits, reviewed files, build settings, and the live runtime hashes.
Aave V4 · Ethereum mainnet
Observed at block 25,596,250. Not an official Aave review, customer relationship, partnership, endorsement, score, or safety conclusion.
A private path from deployed code to public proof.
The free review fixes one reference state, traces audit coverage through every relevant release, and shows the current gaps before any paid audit decision.
- 01
Fix the reference state
Agree the chains, production addresses, repositories, audit reports, and exact reference block.
- 02
Match proof to production
We inspect live bytecode, proxy implementations, audited commits, authority, and exit paths.
- 03
Resolve the gaps
Your team sees missing proof, critical flags, role questions, and a private score draft.
- 04
Approve what goes public
Your team reviews the completed record and authorizes publication. Findings remain independently determined.
The product, in plain English
We connect each audit to the code running now.
For every audit, we record exactly what was reviewed. Then we follow each later release in order until the current deployment. Anything changed without later audit coverage becomes a visible current gap.
Audit baselines
Record the scope, commit, files, findings, and fixes for every relevant audit.
Release timeline
Follow each deployment and upgrade from the audited version to the version live now.
Current gap map
Separate still-covered code from changed, new, partially covered, or unverified code.
Trust Passport
Package the current evidence, controls, exits, flags, and limits into one versioned record.
Every accepted baseline establishes
Which live contracts still match code covered by an audit
Which contracts or code changes appeared after the latest relevant audit
Which live features have missing, partial, or unclear audit coverage
The live proxy and implementation state at one recorded block
Who can upgrade, pause, move funds, change oracles, or govern the system
How users can exit during normal operation and an emergency
Who is accountable, what evidence is missing, and which flags are critical
A private deployed ITS preview and a versioned Trust Passport draft
48 implemented capabilities
Explore the full deployed evidence system.
Each card now explains what the capability does and why it matters. Every capability is part of the platform, not a separately priced add-on. Swipe, use the arrows, or choose an evidence group.Case and evidence control
Separate record for every version
Evidence from one release cannot silently carry over to a later release.Keep one review tied to one protocol version, with sources that can be checked later.
Capability 1 of 48: Separate record for every version. Group: Case and evidence control.
Evidence first. Score second.
One deployed-protocol evidence model.
External Deployed ITS v2 evaluates the evidence available for a protocol already operating in production. It does not claim the protocol completed the Proof of Audits native lifecycle.
Read the scoring policyExternal Deployed ITS v2
Critical flags, missing proof, and scope limits remain visible above the number. A score is withheld when material evidence cannot support it.
Inspect the deployed policyPricing at a glance
The gap review is free. Auditing the gap is optional.
If you continue, the audit starts with a $250 engagement base and adds the confirmed size adjustment. Every size gets the same workflow and evidence outputs.
VS $750 total / S $2,250 total
Standard totals are VS $750 total, S $2,250 total, M $6,000 total, L $15,000 total, and XL $35,000 total. The active launch discount is applied automatically on the pricing page.
See full pricingComplexity includes interaction depth, proxy and authority paths, external dependencies, economic risk, build reproducibility, and the reviewer depth needed for the confirmed gaps.
Make due diligence easier before attention moves elsewhere.
A published Trust Passport gives investors and wallet users one versioned place to inspect code match, authority, exits, flags, and evidence status.
Proof of Audits verifies scoped claims and evidence state. It does not certify that a protocol is safe.
Before first publication, the protocol decides whether the record becomes public. After publication, later stale, superseded, corrected, or withdrawn states remain versioned in the historical record where legally permissible.
Start without an audit commitment
First understand the gap. Then decide.
Submit the live addresses, repositories, and audit reports you already have. We build the private current-gap map at no charge. You decide whether any T4, T3, T2, or T1 audit should follow.
Useful inputs
- Production contract addresses and chains
- Repositories, commits, and build settings
- Audit reports, fix reviews, and named scope
- A technical contact who can clarify deployments and authority
Fee: Free. A paid audit begins only after you accept the gap scope, depth, reviewer plan, timeline, and total.
The free result separates audited, changed, uncovered, and unverified production evidence. It is a gap assessment, not a security audit or safety certificate.
Clear boundary: identifying a gap does not mean the gap has been audited. Coverage changes only after accepted review evidence supports it.

