Skip to main content

Audit preparation field guide

What auditors need before they can quote your smart contract audit

A quote becomes easier when the repository, pinned commit, scope, commands, actors, deployments, and open questions are explicit. This guide gives a small public EVM team a concrete handoff shape.

By Vitalii RadionovChecked 14 July 2026Public EVM preparation

Artifact 1

Repository and pinned commit

Give the reviewer one immutable code target. A branch name is not a review target.

Artifact 2

In scope and out of scope

List exact source paths, generated code, tests, scripts, and excluded integrations.

Artifact 3

Build and test commands

Provide reproducible commands, tool versions, environment assumptions, and the expected test result.

Artifact 4

Architecture and actors

Explain trust boundaries, privileged roles, upgrade paths, emergency controls, and external dependencies.

Artifact 5

Deployment evidence

Map chain, addresses, program or contract identity, proxy relationships, and the commit being reviewed.

Artifact 6

Prior review and known issues

Link previous reports and record known limitations or accepted risks without hiding them.

Artifact 7

Incident and disclosure path

Name the technical owner and a private security contact for questions during and after review.

Free self-serve path

Use the template without hiring Vartovii.

  1. 1. Freeze one public repository commit.
  2. 2. Fill every scope, command, actor, and evidence field.
  3. 3. Send the same completed file to each auditor so quotes refer to the same review target.

Leave a field empty when the artifact does not exist. A visible gap is more useful than an unsupported claim.

You may use ChatGPT as a drafting assistant, but verify every repository path, command, role, deployment reference, known issue, and reviewer question against direct source evidence before sharing it.

Before requesting a quote

Run one final consistency pass.

  • The commit matches every scope link.
  • Build and test commands work in a clean environment.
  • Privileged roles and upgrade authority have evidence.
  • Deployment addresses match the intended review target.
  • Known issues and prior reviews are disclosed.

Boundary

This checklist is not a smart contract audit, vulnerability review, security assurance, or guarantee of audit acceptance, price, grant approval, or launch safety. The same boundary applies to the Vartovii sprint.

Need the handoff assembled?

Vartovii prepares one commit-bound scope pack for 750 USDC.

Public EVM repository only, up to approximately 3,000 nSLOC, delivered within 72 business hours after complete intake, accepted scope, and confirmed payment.

Request async fit check