> For the complete documentation index, see [llms.txt](https://docs.vishwalab.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.vishwalab.com/security/audits-and-compliance.md).

# Audits & Compliance

The Vishwa protocol undergoes rigorous third-party security audits to ensure the highest standards of safety. Our commitment to security goes beyond code review and includes formal verification, continuous monitoring, and comprehensive risk assessment.

## Completed Security Audits

<table><thead><tr><th>Auditor</th><th>Audit scope</th><th>Date</th><th>Status</th><th data-type="files">Report</th></tr></thead><tbody><tr><td>FuzzLand</td><td>Token contracts </td><td>08/20/2025</td><td>Completed ✅</td><td><a href="/files/nBZ1RsTSsBFHy6Y6npnh">/files/nBZ1RsTSsBFHy6Y6npnh</a></td></tr><tr><td>FuzzLand</td><td>BTC ZK-circuits</td><td>08/20/2025</td><td>Completed ✅</td><td><a href="/files/2dSkmZassApxIsm8N7BH">/files/2dSkmZassApxIsm8N7BH</a></td></tr><tr><td>FuzzLand</td><td>Light client</td><td>08/20/2025</td><td>Completed ✅</td><td><a href="/files/9yy50TUwhg6rla1xSqGS">/files/9yy50TUwhg6rla1xSqGS</a></td></tr></tbody></table>

## FuzzLand Security Audit

**Completion date:** August 2025

**Audit duration:** 4 weeks

**Techniques employed:** static analysis, fuzz testing, formal verification, and manual code review

**Summary:** 25 unit tests written, all code manually reviewed, 3 issues found (all resolved)

### FuzzLand Security Audit - Agent Product

**Delivered:** 10 June 2026

**Scope:** Veta TEE Engine (`vishwanetwork/veta-server`), Vishwa MCP Server (`vishwanetwork/vishwa-cli`), and Vishwa Agent Service (`vishwanetwork/agent-api`), each audited at a pinned commit

**Effort:** 12 person-days - 4 engineers over 3 days

**Techniques employed:** static analysis, fuzz testing, formal verification, and manual code review

**Findings:** 14 issues - 5 Medium, 9 Low, no High or Critical. Findings centered on pre-sign intent binding, x402 payment handling, and gateway authentication.

**Remediation:** fix commits for the Vishwa MCP Server and Agent Service are recorded in the report. The Veta TEE Engine is off-chain code, so no on-chain fix-commit hash applies.

### ExVul Security Audit - Vishwa Proof Token

**Completion date:** June 2026

**Scope:** Vishwa Proof Token contracts - BTCvp (`0x79D154287DDC77e5C10127E68c2df1a942a330BB`) and Cfvc (`0xa3b81AA35A2462c588639483EBe68a856Cb32b0d`), from `vishwanetwork/lightclient-verifier` at a pinned commit

**Techniques employed:** OWASP-based risk assessment - static analysis, manual review, and business-logic scrutiny

**Findings:** 5 issues - 0 Critical, 0 High, 3 Medium, 2 Low. Four are fixed; one Medium (arbitrary `srcRef` bytes not canonically constrained on-chain) is acknowledged.

**Result:** audit passed.

### Disclaimer

No audit guarantees the absence of vulnerabilities. Audits are point-in-time reviews of pinned commits; they complement, rather than replace, ongoing security practices. A public bug bounty program has not yet opened.

{% file src="/files/3oWvgD8SCUvPuh1EysLc" %}

{% file src="/files/BRkc2VidObjHsYkN1Ub3" %}
