# Independent audit handoff **No independent audit has been commissioned or completed by this update.** Repository tests and assistant review are internal engineering evidence. An external auditor must identify its organization, scope, source commit, methodology, findings and retest results in a signed/public report before the independent-audit requirement can be marked complete. ## Review targets | Area | Source | Priority and acceptance evidence | | --- | --- | --- | | Legacy consensus | `coin/aurion.py`, generated `seed/core.py` | Critical: recomputation attack, grinding, weight/fork-choice, replay, supply and HTLC invariants | | Replacement design | `docs/PROTOCOL_UPGRADE.md`, `upgrade/storage.py` | Critical: choose and analyze full storage/time/randomness construction; a proof adapter is insufficient | | Standard signatures | `upgrade/protocol.py` and pinned dependency | High: FIPS 204 conformance vectors, independent interoperability, domain separation, malformed encodings, runtime support | | Legacy signing | Wallet file, sidecar signing journal, browser reservations | Critical: cross-device copies/whole-directory rollback, exhaustion, crashes and recoverability | | Rotation candidate | `upgrade/protocol.py` | High: dual-key proof, stale-key rejection, atomic epoch/nonce updates, reorg and migration design | | Public peers | `P2P`, `BoundedHTTPServer`, seed HTTP | High: CPU/storage DoS, discovery/redirect abuse, partitions, hostile dependencies, limits and retry behavior | | Persistence | SQLite desktop and seed journals, backup tool | High: corrupt/truncated state, durable-before-acknowledgment behavior, wrong genesis, restoration | | Operational network | Independent operator inventory and measurements | High: separate control/provider/region, sustained chain progress, restores, failover and partition/rejoin | ## Reproducible evidence Run `npm test`, `python3 coin/aurion.py selftest`, install the isolated upgrade requirements, run the upgrade/operations tests and build the website. Retain test output, environment versions and the exact Git commit; do not describe skipped optional cryptography/storage tests as passed. Windows and macOS must receive their own runtime qualification before cross-platform support claims. `tests/test_adversarial.py` deliberately reproduces the unresolved declared-space attack. Its passing result confirms a known weakness, not storage security. Real fork-choice tests verify receipt removal after branch replacement, but cannot establish economic finality or adversarial-network robustness. ## Audit deliverables and closeout 1. Auditors agree a threat model and complete protocol/migration specification. 2. Freeze an immutable candidate commit, lock dependencies and record checksums. 3. Provide no production wallet keys, passwords, tokens or customer records. 4. Track each finding with severity, reproduction, remedy commit and independent retest. Unresolved critical/high findings block a real-funds readiness claim. 5. Publish the final report and its exact covered commits. Re-audit consensus, cryptography or migration changes made after that scope. No auditor has been contacted, report invented or fee authorized here.