Contest for Discovery, Proof for Protection
Contest-scale eyes with T4→T1 ownership and a validation path that becomes living proof.
Core audit is contest-style discovery with a permanent proof trail: repository evidence becomes deterministic T4, T3, T2, and T1 clusters. Paid tiers hunt at their depth; validators check lower-tier submissions; T0 locks the report that feeds the Trust Passport.
- Who performs it
- Approved auditors who pass tier, skill-tag, conflict-of-interest, and availability gates. Independent validators review lower-tier submissions, and a T0 final-review role handles final review and disputes.
- When it starts
- After pre-audit release gates pass and the protocol approves and funds the repository-backed cluster plan.
- Pricing basis
- Codebase-sensitive tier poolThe deterministic scripts use billable score, billable hours, cluster count, and pool bands. A full-stack pool is split into four equal tier shares, and only protocol-selected paid hunting tiers are charged. A separate 3% protocol fee and automatic final-review fee sit outside core.
How the work moves
Each step creates or validates evidence needed by the next step. Missing proof stops the handoff.
- 01Parse whole functions
Compile AST evidence, function metadata, dependencies, source lines, and call-graph closures without using line fragments as audit scope.
- 02Build fair clusters
T4 owns whole entry-function closures, T3 owns whole contracts, T2 owns related cross-contract units, and T1 owns the system.
- 03Match qualified auditors
Eligibility uses approved status, tier, relevant tags, conflicts, availability, and the exact assigned scope.
- 04Validate and lock
T4 submits to T3, T3 to T2, T2 to T1, then the final-review role closes report, dispute, and settlement decisions.
What the protocol receives
Compact output records first. Methodology detail remains one click away.
Included, reference-only, excluded, and owned helpers remain visible with exact reasons and source links.
Entry functions, local invariants, asset movement, access controls, and owned helper closures.
State assumptions, permissions, external calls, and cross-function behavior without fragment splits.
Related contract pairs, dependencies, or integrations with evidence-backed relation gates.
System economics, governance, emergent risk, and the one full-system cluster.
Validated findings, exact reviewed commit, ownership evidence, and settlement inputs.
What blocks completion
- Repository parsing fails or returns no paid functions
- Scope files or exclusions remain unapproved
- Auditor eligibility or conflict checks fail
- Submission-validation links are incomplete
- Final reviewer or admin approval remains open
Inspect the rules behind this page.
Public copy summarizes current implementation and skill contracts. It does not replace repository evidence or approval.
Put core audit into the funding plan.
Build the lifecycle cart, then submit repository identity so the approved quote can replace every public estimate.
Estimate core audit scope