Contact
Share the project, target date, and the components you expect to include. The team performs an initial review and responds with questions, availability, and next steps.
Share the project, target date, and the components you expect to include. The team performs an initial review and responds with questions, availability, and next steps.
Kann Audits and the protocol team align on repositories, files, a fixed commit, architecture, assumptions, exclusions, and engagement requirements.
A direct communication channel and private reporting workflow are established. Researchers receive the final code, documentation, tests, and technical contacts.
Researchers independently inspect the code, compare behavior with protocol intent, explore attack paths, and collaborate on high-risk areas. Material findings can be shared as they are validated.
The preliminary report records the scope and methodology, then explains each confirmed finding with severity, technical impact, evidence, and remediation guidance.
After the protocol team submits remediations, researchers re-test the affected paths and assess whether the original issue is resolved without an obvious regression in the reviewed area.
The final report reflects the agreed scope, reviewed commits, findings, and verified remediation status. Publication and any follow-up support follow the engagement terms.
Research method
Public Kann Audits reports repeatedly document these areas of analysis.
FAQ
Share the repository or code-access plan, approximate scope, target release date, architecture documentation, supported chains and languages, and any known high-risk components. Do not submit secrets through the public form.
A fixed, stable commit is important for the formal review boundary. Active development can continue elsewhere, but changes to the reviewed scope need to be communicated and may affect the schedule.
The existing process uses a direct team channel and a private reporting workflow so validated findings and technical questions can be discussed during the engagement.
The protocol team can discuss alternatives or acknowledge the risk. The final report should accurately reflect the response and verification status rather than implying a resolution that did not occur.
Disclosure terms are agreed during scoping. The audit library contains only reports that Kann Audits has already published.
No. The report describes a bounded review of a specific scope and code revision. Deployment choices, later changes, and out-of-scope systems can introduce additional risk.
Start a conversation
Share your intended scope and release plan before code freeze so there is time for review, remediation, and verification.