Zum Hauptinhalt springen

Public Offer Ladder And Audit Scope Readiness

Vartovii's first commercial path is an Accepted Documentation PR: reviewer-ready documentation for one public repository and pinned commit, at 250 USDC after pull-request acceptance for the first three engagements, then 350 USDC upfront, within 48 business hours after written scope acceptance. Cohort Evidence Triage is 500 USDC for five public projects or 1,250 USDC for ten, within five business days; it is manual, public-source, and non-ranking. Audit Scope Readiness remains a 750 USDC, 72-business-hour qualified upsell after fit. None is an audit, vulnerability review, certification, security assurance, or launch verdict.

Dashboard and commercial artifact are separate

SurfaceMeaning
Dashboard readiness previewThe existing /app/crypto/:slug/readiness route renders a Trust Score-based preview from the current crypto project payload. It does not expose security_readiness.v1 or the commercial artifact.
Audit Scope Readiness SprintA manually delivered, commit-bound pack using audit_scope_readiness.v1. It prepares scope and evidence for an intended auditor or contest reviewer.

The legacy security_readiness.v1 classifier remains an internal, backward- compatible advisory contract. Its machine-authored status is not a commercial judgement and is not shown as the result of the Audit Scope Readiness Sprint.

Audit Scope Readiness upsell terms

  • Price: 750 USDC as a qualified upsell after fit.
  • SLA: 72 business hours after the accepted written scope states the start condition.
  • Revision: one async revision within seven days.
  • Refund: a full refund of 750 USDC if Vartovii fails to deliver the named artifacts within the SLA because of Vartovii.
  • Language: async English delivery; no sales call is required.

There is no guarantee of audit acceptance, audit price, grant approval, vulnerability discovery, launch safety, or any security outcome.

Eligibility

The sprint is designed for an EVM team with one public repository, roughly one to five engineers, code close to freeze, and an external review expected in two to six weeks. The initial boundary is one repository up to approximately 3,000 nSLOC.

Vartovii does not accept private repositories, bridges, exchanges, custody systems, active incidents, live high-TVL systems, requests to find vulnerabilities, or requests for launch or security assurance.

Intake

The fit check requires:

  • project and contact details;
  • public repository URL and pinned commit;
  • chain, intended review target, and deadline;
  • proposed in-scope and out-of-scope paths;
  • build and test commands;
  • intended recipient and payment owner.

Do not submit private keys, credentials, production secrets, customer data, or private repository content.

Delivery

The delivered pack includes:

  1. pinned repository URL, commit, chain, and nSLOC;
  2. in-scope and out-of-scope manifest;
  3. build and test commands plus architecture and actor map;
  4. evidence register for privileges, upgrades, dependencies, deployments, prior reviews, monitoring, incidents, and disclosure readiness;
  5. five to ten gaps with priority, owner, required artifact, and audit-scoping impact;
  6. auditor-ready RFQ summary and question list;
  7. branded PDF and machine-readable YAML/JSON.

Manual artifact states

audit_scope_readiness.v1 uses three manual workflow states:

StateMeaning
QUOTE_READYThe defined scope handoff contains the required commit, commands, sources, and recipient context.
BLOCKEDA specific blocker prevents a responsible quote handoff.
EVIDENCE_INCOMPLETEThe scope can be discussed, but required supporting artifacts are incomplete.

Evidence entries use EVIDENCED, PARTIAL, MISSING, or OUT_OF_SCOPE. EVIDENCED always requires a direct URL or artifact reference and a checked timestamp. These states describe documentation readiness, not code safety.

Free self-serve resources

You do not need to buy the Vartovii sprint to prepare a consistent scope handoff:

  1. read the public audit quote preparation guide;
  2. download the open audit-scope.yml template;
  3. pin one public repository commit and fill the exact in-scope paths, excluded paths, build/test commands, actors, deployments, prior reviews, known issues, and disclosure contact;
  4. leave missing evidence visibly incomplete rather than replacing it with an unsupported claim;
  5. send the same completed file to each potential auditor so their quotes refer to the same review target.

The paid sprint is optional manual assembly, evidence normalization, gap tracking, and RFQ preparation for teams that do not want to complete the handoff themselves.

DIY, Vartovii, and auditor roles

LayerResponsibility
Founder + ChatGPTUse the open template and AI drafting help independently, then verify every path, command, role, deployment reference, known issue, and reviewer question against direct repository evidence.
VartoviiNormalize one pinned-commit evidence set, keep gaps visible, perform a human consistency pass, and prepare the reviewer handoff.
External auditorEvaluate vulnerabilities and security. The auditor or contest reviewer remains the security authority.

Generic AI output does not by itself establish that the repository paths, pinned commit, commands, actors, deployment evidence, known issues, and review questions are mutually consistent or source-backed. Vartovii does not certify the resulting evidence or replace the external review.

Request async fit check

Privacy and publication

Only material the requester is authorised to share should be submitted. Customer material is private by default. Any case study, logo, quote, repository discussion, or named result requires separate written consent. See the public Privacy Notice for retention and rights details.