Audits
Status
Section titled “Status”fact No third-party audit of the Note Systems contracts has been completed, and none is in progress at the time of writing.
Nothing on this site, in the app or in any communication should be read as claiming otherwise. If you see a claim of an audit that is not listed on this page, treat it as false.
fact Internal security review. The build team has completed an internal security review of the core, oracle, token, governance, sale and automation contracts and keeps the full reports in the repository under audit/. Source access is by request (security@note.systems) until the mainnet release, when the repository is opened. It is a self-review, not an independent audit, and every report carries that status box. An independent external engagement is planned after the raise, before any mainnet deployment holding user funds. All deployments are on the Robinhood Chain testnet only.
Internal review reports
Section titled “Internal review reports”| Date | Report | Scope | Location |
|---|---|---|---|
| 4 Sep 2026, updated 5 Sep 2026 | Internal security review report | Core, oracle, token, governance; test inventory, differential and Monte-Carlo campaigns, static analysis, findings and accepted risks | audit/AUDIT_REPORT.md |
| 4 Sep 2026, updated 5 Sep 2026 | Module D (Sale) internal security review | AngelSale, PublicSale, VestingVault, deploy scripts, sale front-end; tokenomics v2 terms check | audit/sale/SALE_AUDIT_REPORT.md |
| 5 Sep 2026 | Automation internal security review | RollPolicy, NoteAutomation, NoteCore lazy crank and seriesCreator; threat model, invariants, static-analysis re-run | audit/automation/AUTOMATION_REVIEW.md |
| 5 Sep 2026 | Adversarial economics and composability review | Threat catalogue against known attack classes, executable flash-loan attacker suite, multi-protocol game theory, macro stress scenarios, composability of NOTE / sNOTE / dNOTE / veNOTE / legs and external dependencies, Halmos state-machine formal verification; 2 High and 6 Medium findings, all fixed in this release; residual-risk register | audit/adversarial/ (THREAT_CATALOGUE.md, FLASH_LOAN_REVIEW.md, game-theory/, macro/, composability/, FORMAL.md, FIXES.md, RESIDUAL_RISK.md) |
Supporting artefacts (manual review notes, static-analysis triage, differential vectors, invariant logs, coverage) sit next to the reports in the same directory.
Intended path
Section titled “Intended path”planned
- Complete the unit, fuzz and invariant suites to the methodology targets.
- Publish static analysis reports.
- Engage at least one independent audit firm for the core (escrow) and automation contracts before any mainnet deployment holding user funds (planned after the raise).
- Engage a second review for the token engine before NOTE issuance.
- Publish every report in full, including findings that were acknowledged rather than fixed, in
contracts/reports/and on this page. - Launch the bug bounty alongside the first deployment.
External audit reports
Section titled “External audit reports”| Date | Firm | Scope | Report |
|---|---|---|---|
| — | — | — | None yet |