Skip to content

Audits

fact No third-party audit of the Note Systems contracts has been completed, and none is in progress at the time of writing.

Nothing on this site, in the app or in any communication should be read as claiming otherwise. If you see a claim of an audit that is not listed on this page, treat it as false.

fact Internal security review. The build team has completed an internal security review of the core, oracle, token, governance, sale and automation contracts and keeps the full reports in the repository under audit/. Source access is by request (security@note.systems) until the mainnet release, when the repository is opened. It is a self-review, not an independent audit, and every report carries that status box. An independent external engagement is planned after the raise, before any mainnet deployment holding user funds. All deployments are on the Robinhood Chain testnet only.

DateReportScopeLocation
4 Sep 2026, updated 5 Sep 2026Internal security review reportCore, oracle, token, governance; test inventory, differential and Monte-Carlo campaigns, static analysis, findings and accepted risksaudit/AUDIT_REPORT.md
4 Sep 2026, updated 5 Sep 2026Module D (Sale) internal security reviewAngelSale, PublicSale, VestingVault, deploy scripts, sale front-end; tokenomics v2 terms checkaudit/sale/SALE_AUDIT_REPORT.md
5 Sep 2026Automation internal security reviewRollPolicy, NoteAutomation, NoteCore lazy crank and seriesCreator; threat model, invariants, static-analysis re-runaudit/automation/AUTOMATION_REVIEW.md
5 Sep 2026Adversarial economics and composability reviewThreat catalogue against known attack classes, executable flash-loan attacker suite, multi-protocol game theory, macro stress scenarios, composability of NOTE / sNOTE / dNOTE / veNOTE / legs and external dependencies, Halmos state-machine formal verification; 2 High and 6 Medium findings, all fixed in this release; residual-risk registeraudit/adversarial/ (THREAT_CATALOGUE.md, FLASH_LOAN_REVIEW.md, game-theory/, macro/, composability/, FORMAL.md, FIXES.md, RESIDUAL_RISK.md)

Supporting artefacts (manual review notes, static-analysis triage, differential vectors, invariant logs, coverage) sit next to the reports in the same directory.

planned

  1. Complete the unit, fuzz and invariant suites to the methodology targets.
  2. Publish static analysis reports.
  3. Engage at least one independent audit firm for the core (escrow) and automation contracts before any mainnet deployment holding user funds (planned after the raise).
  4. Engage a second review for the token engine before NOTE issuance.
  5. Publish every report in full, including findings that were acknowledged rather than fixed, in contracts/reports/ and on this page.
  6. Launch the bug bounty alongside the first deployment.
DateFirmScopeReport
None yet