External audit status
An independent professional security audit has NOT occurred. This page states the honest status plainly.
No external professional security audit of PolicyVault has occurred. This is stated here exactly as it is stated in PolicyVault's own SECURITY.md, and this documentation follows the same rule: nothing here claims "audited," "independently reviewed," or "professionally audited," and no such claim should be inferred from the depth of PolicyVault's own internal testing.
What has happened instead
- Internal adversarial (hostile-AI) review. PolicyVault has run an internal hostile-AI review of its agent-facing boundaries (MCP, payment-protocol adapters, explanation rendering, the signer interface, the API), with findings and remediations published and covered by dedicated adversarial test suites. This is explicitly labeled as an internal exercise, not an external one, and is not a substitute for independent review.
- Real-network verification. The covenant has been exercised against real Kaspa virtual-machine execution, authorized testnet negative-validation transactions (constructed independently of the PolicyVault application, correctly signed, and still rejected by consensus when policy-invalid), and a complete real-mainnet lifecycle operated by the vault owner. This is genuine evidence, but it is not the same thing as an independent third party reviewing PolicyVault's design and code for vulnerabilities its own authors might not think to test for.
- Production release, honestly labeled. PolicyVault launched its web/agent production platform after its own internal production-readiness gates passed, without waiting for external review to complete first. This was a deliberate, disclosed decision — not a claim that external review is unnecessary or has already happened.
Why this matters to you
Internal testing, however thorough, cannot fully substitute for independent scrutiny by reviewers with no stake in the project's own assumptions. If you are making a decision that depends on whether PolicyVault has been independently audited, the honest answer today is no — weigh that accordingly, and treat any documentation, marketing material, or third party summary that claims otherwise as inaccurate.
What is planned
An external professional security review is planned, and this documentation will be updated — with what was reviewed, what was found, and what was remediated — if and when it actually occurs. Until then, the status above is the complete and current picture.
See also: Non-custodial architecture for what is independently provable today (real consensus enforcement, not a substitute for audit but a different and complementary kind of evidence), Responsible disclosure.