Artifact 1
Repository and pinned commit
Give the reviewer one immutable code target. A branch name is not a review target.
Audit preparation field guide
A quote becomes easier when the repository, pinned commit, scope, commands, actors, deployments, and open questions are explicit. This guide gives a small public EVM team a concrete handoff shape.
Artifact 1
Give the reviewer one immutable code target. A branch name is not a review target.
Artifact 2
List exact source paths, generated code, tests, scripts, and excluded integrations.
Artifact 3
Provide reproducible commands, tool versions, environment assumptions, and the expected test result.
Artifact 4
Explain trust boundaries, privileged roles, upgrade paths, emergency controls, and external dependencies.
Artifact 5
Map chain, addresses, program or contract identity, proxy relationships, and the commit being reviewed.
Artifact 6
Link previous reports and record known limitations or accepted risks without hiding them.
Artifact 7
Name the technical owner and a private security contact for questions during and after review.
Free self-serve path
Leave a field empty when the artifact does not exist. A visible gap is more useful than an unsupported claim.
You may use ChatGPT as a drafting assistant, but verify every repository path, command, role, deployment reference, known issue, and reviewer question against direct source evidence before sharing it.
Before requesting a quote
Boundary
This checklist is not a smart contract audit, vulnerability review, security assurance, or guarantee of audit acceptance, price, grant approval, or launch safety. The same boundary applies to the Vartovii sprint.
Need the handoff assembled?
Public EVM repository only, up to approximately 3,000 nSLOC, delivered within 72 business hours after complete intake, accepted scope, and confirmed payment.
Request async fit check