External audit status

An independent professional security audit has NOT occurred. This page states the honest status plainly.

No external professional security audit of PolicyVault has occurred. This is stated here exactly as it is stated in PolicyVault's own SECURITY.md, and this documentation follows the same rule: nothing here claims "audited," "independently reviewed," or "professionally audited," and no such claim should be inferred from the depth of PolicyVault's own internal testing.

What has happened instead

Why this matters to you

Internal testing, however thorough, cannot fully substitute for independent scrutiny by reviewers with no stake in the project's own assumptions. If you are making a decision that depends on whether PolicyVault has been independently audited, the honest answer today is no — weigh that accordingly, and treat any documentation, marketing material, or third party summary that claims otherwise as inaccurate.

What is planned

An external professional security review is planned, and this documentation will be updated — with what was reviewed, what was found, and what was remediated — if and when it actually occurs. Until then, the status above is the complete and current picture.

See also: Non-custodial architecture for what is independently provable today (real consensus enforcement, not a substitute for audit but a different and complementary kind of evidence), Responsible disclosure.