> For the complete documentation index, see [llms.txt](https://docs.vishwalab.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.vishwalab.com/security/audits-and-compliance.md).

# Audits & Compliance

Security through transparency.

The Vishwa protocol undergoes rigorous third-party security audits to ensure the highest standards of safety. Our commitment to security goes beyond code review and includes formal verification, continuous monitoring, and comprehensive risk assessment.

## Completed Security Audits

<table><thead><tr><th>Auditor</th><th>Audit scope</th><th>Date</th><th>Status</th><th data-type="files">Report</th></tr></thead><tbody><tr><td>FuzzLand</td><td>Token contracts </td><td>08/20/2025</td><td>Completed ✅</td><td><a href="https://2581884455-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FiKtwuXgGckbrnwJbKNtR%2Fuploads%2FMxsdHGcGUVG3gEqjku0W%2Fbtcvn-audit-v3_8.20.pdf?alt=media&amp;token=05a7066d-0641-4059-a9bb-bd623c391ec0">btcvn-audit-v3_8.20.pdf</a></td></tr><tr><td>FuzzLand</td><td>BTC ZK-circuits</td><td>08/20/2025</td><td>Completed ✅</td><td><a href="https://2581884455-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FiKtwuXgGckbrnwJbKNtR%2Fuploads%2FH84n9QWPYe54D6TIg4lM%2Fcircuit-audit-v3_8.20.pdf?alt=media&amp;token=89aae877-ad15-4452-a286-9cd07afc0e1a">circuit-audit-v3_8.20.pdf</a></td></tr><tr><td>FuzzLand</td><td>Light client</td><td>08/20/2025</td><td>Completed ✅</td><td><a href="https://2581884455-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FiKtwuXgGckbrnwJbKNtR%2Fuploads%2FUCzSeyaN3VnyZIMjUMI4%2Fsui-light-client-audit-v3_8.20.pdf?alt=media&amp;token=6969c2f4-460e-4fe1-91af-c5240a50f353">sui-light-client-audit-v3_8.20.pdf</a></td></tr></tbody></table>

## FuzzLand Security Audit

**Completion date:** August 2025

**Audit duration:** 4 weeks

**Techniques employed:** static analysis, fuzz testing, formal verification, and manual code review

**Summary:** 25 unit tests written, all code manually reviewed, 3 issues found (all resolved)

### FuzzLand Security Audit - Agent Product

**Delivered:** 10 June 2026

**Scope:** Veta TEE Engine (`vishwanetwork/veta-server`), Vishwa MCP Server (`vishwanetwork/vishwa-cli`), and Vishwa Agent Service (`vishwanetwork/agent-api`), each audited at a pinned commit

**Effort:** 12 person-days - 4 engineers over 3 days

**Techniques employed:** static analysis, fuzz testing, formal verification, and manual code review

**Findings:** 14 issues - 5 Medium, 9 Low, no High or Critical. Findings centered on pre-sign intent binding, x402 payment handling, and gateway authentication.

**Remediation:** fix commits for the Vishwa MCP Server and Agent Service are recorded in the report. The Veta TEE Engine is off-chain code, so no on-chain fix-commit hash applies.

### ExVul Security Audit - Vishwa Proof Token

**Completion date:** June 2026

**Scope:** Vishwa Proof Token contracts - BTCvp (`0x79D154287DDC77e5C10127E68c2df1a942a330BB`) and Cfvc (`0xa3b81AA35A2462c588639483EBe68a856Cb32b0d`), from `vishwanetwork/lightclient-verifier` at a pinned commit

**Techniques employed:** OWASP-based risk assessment - static analysis, manual review, and business-logic scrutiny

**Findings:** 5 issues - 0 Critical, 0 High, 3 Medium, 2 Low. Four are fixed; one Medium (arbitrary `srcRef` bytes not canonically constrained on-chain) is acknowledged.

**Result:** audit passed.

### Disclaimer

No audit guarantees the absence of vulnerabilities. Audits are point-in-time reviews of pinned commits; they complement, rather than replace, ongoing security practices. A public bug bounty program has not yet opened.

{% file src="/files/3oWvgD8SCUvPuh1EysLc" %}

{% file src="/files/BRkc2VidObjHsYkN1Ub3" %}
