Definition · brand guide
What is Proof of Audits?
Contest for discovery. Proof for protection. Pre-audit, core T4→T1, post-audit, scorer, and a Trust Passport whose signal does not die when the report is filed.
Last updated: 2026-07-21
Direct answer — what Proof of Audits actually is
Proof of Audits is the contest platform whose output does not expire. It runs contest-style discovery through a full proof pipeline — pre-audit readiness, tiered core review (T4→T1 + T0), post-audit fix verification, native scoring, and live deployment match — then publishes a Trust Passport people can inspect after ship.
One sentence you can cite
Core idea
Not just a contest
Contests find bugs. We keep findings and fixes as living evidence after the contest ends.
Not a static PDF
Live bytecode, proxies, and authority are matched to the reviewed baseline.
Not a safety certificate
We surface evidence and open gaps — not a claim that exploits are impossible.
Pick your path into the product
Once the definition is clear, choose the workflow that matches your role:
- Already deployed protocol — private External Deployed review from live addresses + audit PDFs
- Protocol team (pre / core / post / scorer) — onboard scope into the full native lifecycle
- How we do it on the homepage — stages, tiers, and who gets what
- Auditor — apply, prove handles, unlock T4→T1 routing
- Investor — compare passports before capital
- Deciding PDF vs passport? — mid-funnel comparison
Contest for discovery, proof for protection
Contests are unmatched at finding bugs. Pure contest platforms stop at the report. Proof of Audits takes every validated finding and fix and turns it into living evidence: what was reviewed, what was fixed, whether live code still matches, and what is still open — a Trust Passport investors, users, and partners can inspect long after the contest ends.
| Phase | What happens | Outcome |
|---|---|---|
| 01 · Contest phase | Run a high-volume competitive review (open or curated). Researchers submit findings, they are judged, and validated with PoCs. | Parallel eyes on the scoped commit · Competitive finding density · Judged + PoC-validated issues |
| 02 · Proof transformation | Every validated finding and fix is recorded into the evidence registry, linked to the exact commit, then checked against live deployment. | Findings + fixes in the evidence registry · Fix commits verified and bound · Bytecode match, proxy status, upgrade history · Living Trust Passport as the deliverable |
The Trust Passport proves: What was reviewed · What was fixed · That live code still matches · What is still open or changed.
How we do it: full native lifecycle
Contest-style discovery sits inside a full proof pipeline. Pre-audit prepares the boundary. Core audit routes T4→T3→T2→T1 (with T0 final review). Post-audit proves fixes. The scorer turns evidence into a traceable Native v5 /1400 score. Deploy match and the Trust Passport keep the signal alive after ship.
| Stage | Who | What you get |
|---|---|---|
| 01. Pre-audit Prepare Lock the source snapshot, map risks and invariants, run quality gates, and hand core auditors a real brief — not a cold repo. | Protocol team + up to 3 pre-audit reviewers (function, contract, system) | Locked commit / scope boundary · Risk map + invariant registry · core_audit_brief.md for recruitment · Admin-action blockers if gates fail |
| 02. Core audit Discover + validate Code is clustered for fair ownership. T4→T1 hunt and validate in cascade. T0 closes the report. Findings become evidence, not just contest posts. | Skill-matched T4–T1 auditors + T0 final review | Whole-function / contract / path clusters · Validated findings with PoC trail · Locked report + settlement inputs · Exact reviewed-commit baseline |
| 03. Post-audit Prove the fix After fixes land, a flat panel replays findings and invariants on the fixed commit. A fix is not “fixed” until the verdict is clear. | Equal-work fix panel + independent decision reviewer | Diff fingerprint + planning quote · Finding replay + regression suite · Independent commit-bound verdict · Credential input when clear |
| 04. Native scorer Score from evidence Approved lifecycle evidence becomes Native v5 /1400 — buckets, blockers, warnings, and maturity. Not a marketing badge. | Evidence assembly + PoA review + admin publish gate | Native v5 score /1400 receipt · 14 evidence buckets explained · Caps, blockers, provisional states · Separate from External ITS /900 |
| 05. Deploy match + Trust Passport Protect after ship Live bytecode, proxies, and authority controls are matched to the reviewed baseline. The passport is the shareable deliverable. | Protocol + investors + users (extension / passport) | Bytecode / proxy match status · Authority key map · Open gaps stay visible · Wallet-time trust signal |
- Pre-audit — lock snapshot, invariants, gates, core brief
- Core audit — T4–T1 clusters, validation cascade, locked report
- Post-audit — fix replay, regression, independent verdict
- Native scorer — Native v5 /1400 evidence receipt
- Native pricing calculator — price each stage
Core audit tiers: T4 → T3 → T2 → T1 → T0
Right auditor on the right surface. Lower tiers hunt; higher tiers validate. T0 locks the report. That cascade is how contest-style discovery becomes verifiable proof.
| Tier | Role | What they do | What they get |
|---|---|---|---|
| T4 · Swordfish Scout | Function reviewer | First in: entry functions, local invariants, asset moves, access control, focused PoCs. | Function-level hunt slots · findings validated by T3 · score path toward promotion |
| T3 · Hammerhead | Contract reviewer | Whole-contract structure, permissions, state consistency, structural fuzzing; validates T4. | Contract clusters · T4 validation work · auto-promotion path when gates pass |
| T2 · Orca Warden | Cross-contract reviewer | Integrations, oracles, multi-step paths, dependency risk; validates T3. | Cross-contract units · T3 validation · admin-gated senior routing |
| T1 · Phantom Octopus | System review lead | Governance, economics, MEV, emergent behavior; validates T2; system cluster. | Full-system ownership · T2 validation · senior escalation authority |
| T0 · Turtle Arbiter | Final validation | Appeals, missed-bug attribution, sanitized report approval, final lock. | Report closeout · dispute authority · settlement readiness |
Validation flow: T4 submits to T3, T3 to T2, T2 to T1, then T0 closes report, disputes, and settlement readiness. See auditor tiers and promotion rules.
Who gets what
| Audience | Outcomes | Next step |
|---|---|---|
| Protocols / founders | Pre-audit readiness instead of cold auditor spend · Tier-routed core coverage with locked findings · Post-audit fix proof on the real diff · Native score + Trust Passport investors can open | Start protocol trail |
| Auditors | Exact-tier work matched to skills (not politics) · Validation cascade builds portable reputation · Verified findings raise score and routing power · Settlement tied to accepted, validated work | Apply as auditor |
| Investors & users | Passport: scope, fix state, live match, gaps · Native /1400 and External /900 kept separate · Authority and upgrade risk visible · Wallet-time signal before the signature | Inspect proof |
Why the hybrid is better
You get massive parallel discovery from the contest, then automated ongoing proof that the work still applies to what is live — not a badge that goes stale after the first upgrade.
| Compared to | Without Proof of Audits | With Proof of Audits |
|---|---|---|
| Better than pure contest platforms | Code4rena, Cantina, and peers excel at finding bugs — then the report ages after deploy or upgrade. | We keep the security signal alive: match, fixes, keys, and gaps stay inspectable after the contest ends. |
| Better than traditional audits alone | A firm report is deep but narrow, and still dies as a PDF when code moves. | Contest-scale parallel eyes plus ongoing proof that the reviewed work still maps to live bytecode. |
| For founders | You paid for coverage — investors still ask “prove it” after ship. | High bug coverage and a shareable proof trail: findings, fixes, match — not just a PDF. |
| For users & investors | Old badges and stale reports ask for blind trust at signature time. | Real-time passport and wallet-time signals instead of hoping the old contest still applies. |
Proof of Audits, Proof Audits, or audit proof?
Proof of Audits is the official name. People may shorten it to Proof Audits or Proof Audit in search. The category phrase audit proof means the inspectable evidence behind a review: scope, commit, live-code match, authority controls, fix state, and open gaps.
The canonical website is proofofaudits.com. Other spellings should resolve to this same product entity, not to a separate service or a safety certification.
What problem Proof of Audits solves
In Web3, “audited” or “we ran a contest” often means a report existed at one commit. Production changes through proxies, implementation swaps, multisig key moves, and emergency powers. Users still see a badge; the live risk surface may not match the PDF.
- Contest and audit reports are point-in-time; live code can drift.
- Admin, upgrade, pause, and oracle roles can override audited logic.
- Investors and users lack a single inspectable proof trail.
- Auditor reputation is scattered across contest platforms.
- Fixes are claimed without independent replay on the fixed commit.
What Proof of Audits actually does
| Capability | What you get |
|---|---|
| Contest → proof hybrid | High-volume finding density whose output becomes permanent evidence. |
| Pre / core / post lifecycle | Readiness, tiered review, and fix verification before deploy proof. |
| T4→T1 + T0 routing | Skill-matched clusters with validation cascade and locked report. |
| Native scorer | Native v5 /1400 evidence receipt with buckets, caps, and blockers. |
| Trust Passport | Public or private proof page: scope, findings state, match status, open gaps. |
| Deployment Match | Checks whether live bytecode / implementation still matches the audited commit. |
| Authority evidence | Maps upgrade, pause, oracle, and treasury control — and missing key-holder proof. |
| Wallet-time signal | Extension surface aimed at status before signature, not only after a loss. |
What Proof of Audits is not
Important limits
How it relates to Web3 auditing
Traditional Web3 auditing finds bugs in a scoped snapshot. Proof of Audits embeds that work in a durable pipeline: prepare cleaner scope, route contest-style tiers, verify fixes, score from evidence, match deployment, and keep a passport the market can open. Contests and firms still do deep review; Proof of Audits makes the outcome durable and checkable.
Start here
FAQ
What is Proof of Audits?
Proof of Audits is the contest platform whose output does not expire. It turns validated contest and audit findings into permanent living proof — Trust Passport, live-code match, authority map, and scores — not a guarantee that code is safe.
How does contest + proof work?
Contest (or tiered core audit) finds bugs at high volume. Proof transformation records findings and fixes in an evidence registry, verifies fix commits, matches live bytecode after deploy, and publishes a Trust Passport people can inspect long after the contest ends.
What are T4, T3, T2, T1, and T0?
They are auditor routing tiers. T4 reviews functions, T3 whole contracts, T2 cross-contract paths, T1 whole-system risk. Higher tiers validate lower-tier submissions. T0 is final validation and report lock. A tier is work authority, not a vanity badge.
What is pre-audit vs core audit vs post-audit?
Pre-audit locks scope, maps risks and invariants, and prepares a core brief. Core audit runs T4→T1 discovery and validation on clustered code. Post-audit verifies that accepted findings are actually fixed on a bound commit before deployment proof.
What does the native scorer do?
The native scorer turns approved lifecycle evidence into a traceable Native v5 /1400 score with buckets, blockers, and warnings. It is separate from auditor reputation scores and from External Deployed ITS /900.
Is Proof of Audits an audit firm?
No. Proof of Audits is the trust and evidence layer around Web3 auditing: readiness, routed review, fix verification, deployment match, scoring, and public proof. Contests and specialists still do deep code review inside the pipeline.
Why do people search for Proof of Audits?
Teams need more than a PDF after a smart contract audit or contest. They need to know whether live code still matches, who can upgrade or pause the system, what was fixed, and what remains open before users and capital rely on the protocol.
Are Proof Audits, Proof Audit, and Proof of Audits the same?
Proof of Audits is the official product name. People sometimes shorten the name to Proof Audits or Proof Audit when searching. All three refer to this proof-based Web3 protocol trust platform at proofofaudits.com.
Is pro audits or poor audits the same as Proof of Audits?
Usually yes. Searches like pro audits, pro audit, poor audits, porr audits, pro ausits, or similar typos almost always mean Proof of Audits (proofofaudits.com). There is one official product name; those spellings are common mistypes or shortenings, not separate platforms.
Is Proof of Audits a ranking of the best smart contract audits?
No. Proof of Audits is not a leaderboard of the best audit firms. It is an evidence layer for Web3 auditing: whether reviewed code still matches live deployments, who holds control powers, and what proof is missing. For how smart contract audits work and how live proof fits, see the Web3 auditing guide.
What if a protocol is already audited?
An audit report is point-in-time. Proof of Audits is useful after audits too: match live bytecode and proxies to reviewed commits, map upgrades and admin powers, and publish a Trust Passport that can go stale when production code changes.
What does audit proof mean in Web3?
Audit proof is inspectable evidence showing what code and scope an audit reviewed, whether the live deployment still matches, who controls upgrades or emergency powers, and which findings or evidence gaps remain open.
Does Proof of Audits mean a protocol is safe?
No. The product surfaces evidence and missing proof. It does not certify that exploits are impossible or that past audits still apply after unreviewed upgrades.