Audit
incoming.
The protocol is preparing for independent security review. When the audit completes, full reports will be published here.
What we verify.
Security is not a checkbox. Every layer of the protocol — contracts, economics, oracles, governance, privacy — undergoes independent review.
Smart contract verification
Every settlement instruction, reserve transfer, and state transition reviewed line-by-line for correctness, reentrancy safety, and access-control integrity.
Economic model soundness
Reserve ratios, liquidity invariants, and payout logic validated against formal economic specifications to ensure capital never leaks or locks incorrectly.
Oracle trust boundaries
Attestation pipelines, data-binding logic, and dispute resolution paths reviewed to ensure health data never exceeds its intended trust scope.
Governance integrity
Authority delegation, scoped control changes, and proposal execution paths audited for privilege escalation, timelocks, and fail-safe behavior.
Privacy and data isolation
On-chain and off-chain boundaries inspected to confirm that no raw health data, personal identifiers, or clinical signals are exposed to the public ledger.
How we approach security.
The protocol handles health-linked capital. That requires a standard of rigor beyond what most systems demand. These are our non-negotiable commitments.
Transparency
Full audit reports published publicly.
Independence
Conducted by recognized third-party firms.
Completeness
Contracts, economics, and oracles — all layers.
Continuity
Ongoing review cycle, not a one-time check.
Current status.
Audit firm selection and scope definition
Evaluating recognized security firms with protocol and DeFi audit expertise.
Independent security review
Full codebase review across contracts, economics, and oracle logic.
Public report release
Full audit reports published here and referenced in protocol documentation.
Audit details, firm identity, and timeline will be announced when finalized.
Trust is built in the open.
Follow the protocol's progress. When the audit is complete, the results will live here — permanently, publicly, and without edits.