Scope locked
Score starts with a locked baseline - no moving source, no silent mutations before review.
Before any core auditor starts, Proof of Audits locks your snapshot, checks readiness gates, maps risks, builds the invariant registry, clusters the code, and writes the core-audit brief. Scope is frozen. Gaps are listed. Auditors do not walk in cold.
The full pre-audit pack: locked scope, readiness result, risk map, invariants, cluster plan, and a brief that drives routing.
Invariants registered
Core review only opens when prep is real - not when someone says they are ready.
Before any core auditor starts, Proof of Audits locks your snapshot, checks readiness gates, maps risks, builds the invariant registry, clusters the code, and writes the core-audit brief. Scope is frozen. Gaps are listed. Auditors do not walk in cold.
The full pre-audit pack: locked scope, readiness result, risk map, invariants, cluster plan, and a brief that drives routing.
Auditors routed
Every review point is tied to a tiered auditor and a cluster - not a self-reported claim.
Pre-audit clusters become T4→T1 work packages. A lending path and a bridge path are different risks, so each package goes to auditors matched by skill, tier, and eligibility - not random assignment.
Named coverage: who reviewed which package, at which tier, with what status.
Findings validated
You can ask: who checked this exact function or cluster?
Pre-audit clusters become T4→T1 work packages. A lending path and a bridge path are different risks, so each package goes to auditors matched by skill, tier, and eligibility - not random assignment.
Named coverage: who reviewed which package, at which tier, with what status.
Fixes verified
Fix points only count when re-test evidence exists - not because someone said “fixed.”
When the team says a bug is fixed, a post-audit panel re-checks the fix commit: replay, regressions, collisions, and a verdict. “Fixed” is evidence - not a promise in a chat.
A clear verdict: fixed, still risky, residual risk, or a new problem from the patch.
Bytecode matched
Deployed-code match keeps the score honest after launch - change the code, the proof updates.
Audit PDFs go stale. We compare live on-chain bytecode (and proxies) to the audited commit and fix baseline so markets see match, drift, or unknown - not last year’s PDF.
A live status: matched, changed, unknown, or pending review.
Authorities mapped
Show who can change the system and who is accountable for each critical role.
Native protocols now carry authority, people, exit, release, and incident proof through the same pre-audit, core-audit, and post-audit record.
Upgrade, multisig, timelock, and bypass mapping. Wallet-based critical-role binding. Role-specific interviews and evidence review
Upgrades monitored
Keep the published record useful when code, controls, or operating history changes.
The full trail lives on the Trust Passport and investor view. The extension shows the short version right before you sign - no PDF to read mid-signature.
One clear signal: proof found, proof missing, or code changed - plus open gaps.