Skip to main content
Accepted Documentation PR · Audit Scope Readiness Sprint is a qualified upsell

Reviewer-ready
documentation for
one pinned commit.

The primary commercial path is a bounded documentation pull request for one public repository and pinned commit: 250 USDC after the pull request is accepted for the first three engagements, then 350 USDC upfront. Delivery is within 48 business hours after written scope acceptance.

250 USDC after acceptance48 business hoursOne async revision

Async English delivery. No sales call required; a call is optional.

Primary offer

Accepted Documentation PR

250 USDC after the pull request is accepted for the first three; 350 USDC upfront afterward.

48 business hours after written scope acceptance.

Bounded alternative

Cohort Evidence Triage

500 USDC for five public projects or 1,250 USDC for ten.

five business days; manual, public-source, non-ranking.

Bounded alternative

Audit Scope Readiness

750 USDC qualified upsell after fit.

72 business hours after its written scope is accepted.

Best fit

Public repository owners who need reviewer-ready documentation.

The repository and pinned commit must be public. Cohort operators provide one representative repository for a manual sample-fit check.

Exact commercial boundary

The selected offer is manually reviewed. A request does not imply acceptance, checkout, payment, a security conclusion, or a launch decision.

Delivery

The qualified Audit Scope upsell pack an auditor needs before quoting.

Pinned repository URL, commit, chain, and nSLOC snapshot

In-scope and out-of-scope manifest tied to that commit

Build and test commands plus an architecture and actor map

Evidence register for privileges, upgrades, dependencies, deployments, prior reviews, monitoring, incidents, and disclosure readiness

Five to ten gaps with priority, owner, required artifact, and audit-scoping impact

Auditor-ready RFQ summary and question list

Branded PDF and machine-readable YAML/JSON, with one async revision within seven days

Required intake

Commit first, interpretation second.

Send the public repository, pinned commit, chain, intended review, deadline, known scope, build and test commands, intended recipient, and payment owner. Every factual statement in delivery carries a source or artifact reference and checked timestamp.

Not accepted

Private repositories, bridges, exchanges, custody systems, or active incidents

Live high-TVL systems or projects seeking launch or security assurance

Vulnerability review, exploit testing, formal audit work, or a security verdict

Manual artifact state

Quote-ready, blocked, or evidence-incomplete.

These states describe whether the scope handoff is usable. They are selected manually and do not provide a security verdict. Evidence is marked EVIDENCED, PARTIAL, MISSING, or OUT_OF_SCOPE only against direct sources checked at a recorded time.

EVIDENCED

Repository and scope anchor

Synthetic fixture identity, revision, chain, and in-scope source paths are explicit; the revision is not a Git commit.

Checked 2026-08-01T08:00:00Z

PARTIAL

Privileged roles and upgrades

Roles are visible in source, but deployed addresses and upgrade-path evidence are absent.

Checked 2026-08-01T08:04:00Z

MISSING

Incident and disclosure readiness

No SECURITY.md or private disclosure path was found at the synthetic fixture revision.

Checked 2026-08-01T08:08:00Z

A missing source stays missing. Vartovii does not turn absent proof into a positive security judgement.

Synthetic commit-bound sample

See the exact handoff shape.

The sample ties scope, commands, evidence, and gaps to one pinned demo commit without making a security outcome claim.

Open full sample pack

Guarantee boundary

No guarantee of audit acceptance, audit price, grant approval, vulnerability discovery, launch safety, or a security outcome. This is not a smart contract audit, vulnerability review, certification, legal advice, investment advice, security assurance, or launch verdict.

Public-repository boundary

Do not submit private keys, credentials, private repository content, production secrets, or customer data. Case-study use requires separate written consent.

FAQ and service terms

Is this a smart contract audit?

No. The sprint prepares scope, commands, evidence, and questions for an external security authority. It does not search for vulnerabilities or judge code safety.

When does the documentation PR SLA start?

The 48 business hours delivery window starts after written scope acceptance for the public repository and pinned commit.

Is Audit Scope Readiness the first purchase?

No. It remains a 750 USDC qualified upsell after fit. Audit, grant, launch, and security outcomes are not guaranteed.

Can Vartovii review a private repository?

No. All three offers require public repositories. The EVM and approximately 3,000 nSLOC boundary applies specifically to the qualified Audit Scope Readiness upsell.

Can I prepare this with the free template and ChatGPT?

Yes. ChatGPT can help draft a checklist or YAML. You remain responsible for checking every path, command, role, deployment reference, known issue, and reviewer question against repository evidence. Vartovii is the optional human consistency and normalization layer; the external auditor remains the security authority.

A written scope controls the accepted repository, commit, deliverables, start condition, SLA, revision window, fee, and refund. No VAT number or VAT rate is represented unless Vartovii is registered to do so.

Offer fit check

Request an async fit check.

Share the public repository, audit target, and timeline. A written scope follows within 24 hours when the project fits the boundary.

Pilot intake form

Request an async fit check.

Share enough context for a manual fit check. This is not an account, payment, subscription, audit, or product-access request. Public repositories only.

Select the offer you want to discuss

pilot@vartovii.com

Use this contact address for privacy, correction, deletion, or fallback pilot-request messages.

Before submitting

One representative public repository, pinned commit, delivery context, deadline, recipient, and payment owner are required.

Do not include private keys, credentials, secrets, customer data, or private repository content.

Vartovii may reply by email about this fit check only after you consent.

The form creates a manual intake record only. It does not create an account, payment, subscription, customer portal, or gated product access.

Review the delivery process