# PactVerity Independent Security Audit — Request for Proposal

## Objective

PactVerity invites an independent security firm with demonstrable Solana and TypeScript security experience to audit the public evidence-verification stack and the unpublished value-bearing Solana candidates before deployment.

## Scope

1. Receipt creation, canonicalization and SHA-256 domain separation.
2. Strict parsing, tamper detection and optional Ed25519/Solana message verification.
3. Public API request limits, failure handling, data minimisation and D1 activity storage.
4. Build and dependency review, reproducibility and deployment configuration.
5. Solana escrow and sale candidate account constraints, authority design, state transitions, arithmetic, denial-of-service paths and economic abuse cases.

## Required deliverables

- Reproducible methodology and reviewed source revision.
- Severity-ranked findings with proof of concept where appropriate.
- Remediation review and final status for every finding.
- Public final report suitable for linking from pactverity.com.
- Explicit disclosure of auditor independence and conflicts of interest.

## Current boundary

No value-bearing PactVerity Solana program should be described as audited or production-ready until this work is completed and the report is public.
