{
  "date": "2026-09-05",
  "method": "Official home page plus at most two documented candidate paths. Text matches require manual contextual classification. HTTP failures and JS-only pages are unknown, not negative findings. No forms submitted.",
  "pilotSelection": "Purposive five-provider pilot. Linked artifacts: most recent dated Trail of Bits PDF visible in archive; the two PDFs linked by Quantstamp audits page; Hacken documented public API; OpenZeppelin research index; Pharos service and editorial pages. Not a random sample or exhaustive report census.",
  "coverage": {
    "networks": 11,
    "languages": 8,
    "services": 15
  },
  "reports": [
    {
      "slug": "pharos-production-evidence-review-2026",
      "measurements": [
        {
          "metric": "Distinct homepage/service/policy artifacts",
          "value": 3
        },
        {
          "metric": "Customer audit reports established in those pages",
          "value": 0,
          "qualification": "Bounded page set only; private reports not inspected"
        }
      ],
      "sources": [
        {
          "url": "https://pharosproduction.com/services/security-audits-and-gas-optimization/",
          "label": "Official audit service and pricing",
          "checkedAt": "2026-09-05",
          "status": "opened",
          "sha256": "15691c95df3ccd98702fb2e8f7cdf48b27e1d4bb5325c1e21d7447784bce5839"
        },
        {
          "url": "https://pharosproduction.com/",
          "label": "Official homepage",
          "checkedAt": "2026-09-05",
          "status": "opened",
          "sha256": "72191b403781ef206638c9af23dfb7c85aee474102797567c79df7809978dbc3"
        },
        {
          "url": "https://pharosproduction.com/editorial-policy/",
          "label": "Provider editorial policy",
          "checkedAt": "2026-09-05",
          "status": "opened",
          "sha256": "4c9a63cacd75ad185d663e9d8662cdba49cdab01c7617af23483eed4a1c644c7"
        }
      ]
    },
    {
      "slug": "openzeppelin-evidence-review-2026",
      "measurements": [
        {
          "metric": "Initial revisions identified in first two scope blocks",
          "value": 2
        },
        {
          "metric": "Report-stated issues",
          "value": 22
        },
        {
          "metric": "Report-stated resolved issues",
          "value": 16
        },
        {
          "metric": "Report-stated partially resolved issues",
          "value": 1
        }
      ],
      "sources": [
        {
          "url": "https://www.openzeppelin.com/news/zksync-os-audit",
          "label": "OpenZeppelin ZKsync OS audit",
          "checkedAt": "2026-09-05",
          "status": "opened",
          "sha256": "02eedac03d6f177cc389c6a828d4a15e347a6ca3b131b34072ed1632de6d2887"
        },
        {
          "url": "https://www.openzeppelin.com/research",
          "label": "Official research index",
          "checkedAt": "2026-09-05",
          "status": "opened",
          "sha256": "8987a14adf5e106ceed163b87deaab2b2aa6d1235f1d97fcf2f3936d7fbb7e6b"
        },
        {
          "url": "https://www.openzeppelin.com/security-audits",
          "label": "Published audit process",
          "checkedAt": "2026-09-05",
          "status": "opened",
          "sha256": "14277e05b221f30ffa19aa08891b32b921dcaf844ae040b726b50cb83357f5d0"
        },
        {
          "url": "https://www.openzeppelin.com/news/miden-smart-contracts-audit",
          "label": "miden smart contracts audit",
          "checkedAt": "2026-09-05",
          "status": "opened",
          "sha256": "632decfd12453e01c98a02679fdbd85bcd740bb601820185687870f691c5488f"
        },
        {
          "url": "https://www.openzeppelin.com/news/stablegold-audit",
          "label": "stablegold audit",
          "checkedAt": "2026-09-05",
          "status": "opened",
          "sha256": "829c7cd3ef566f872dcb4071676e2c57d1fe4be8b10bc7d099fea56473c07d6a"
        },
        {
          "url": "https://www.openzeppelin.com/news/txflow-security-audit",
          "label": "txflow security audit",
          "checkedAt": "2026-09-05",
          "status": "opened",
          "sha256": "5c28ea5d09b9787d6c862fbc0d639808b0fb5fff02586c381a585c57303049cf"
        },
        {
          "url": "https://www.openzeppelin.com/news/across-protocol-v5-bridging-system-audit",
          "label": "across protocol v5 bridging system audit",
          "checkedAt": "2026-09-05",
          "status": "opened",
          "sha256": "0877575dfd549ffe84e4649c6255b7cf161fb3dfd6c907a6ad01d614dbbbf527"
        },
        {
          "url": "https://www.openzeppelin.com/news/contracts-v5-audit",
          "label": "contracts v5 audit",
          "checkedAt": "2026-09-05",
          "status": "opened",
          "sha256": "61ab0f61244b136825281e6892c22de8fe35286a2c889214fa65e73c5f1ee100"
        }
      ]
    },
    {
      "slug": "trail-of-bits-evidence-review-2026",
      "measurements": [
        {
          "metric": "Version hashes listed in project targets",
          "value": 3
        },
        {
          "metric": "Detailed findings and fix-review entries",
          "value": 2
        },
        {
          "metric": "Resolution narratives based on intended behavior",
          "value": 1
        },
        {
          "metric": "Resolution narratives referencing a code change",
          "value": 1
        }
      ],
      "sources": [
        {
          "url": "https://raw.githubusercontent.com/trailofbits/publications/master/reviews/2026-05-kiln-lagoonvaultdiffreview-securityreview.pdf",
          "label": "Kiln Lagoon Vault v0.6.0 security assessment",
          "checkedAt": "2026-09-05",
          "status": "opened",
          "sha256": "ce300c02223b89be2686a74e2b4eca67ab993dc12f744575f1927c12ba34e38b"
        },
        {
          "url": "https://www.trailofbits.com/reports",
          "label": "Official report index",
          "checkedAt": "2026-09-05",
          "status": "opened",
          "sha256": "ac5ed62a6753c30bfcf2f90fb80c3de964ecb2e015e259e3f6f960ee4a11ef60"
        },
        {
          "url": "https://raw.githubusercontent.com/trailofbits/publications/master/reviews/2026-04-ripple-labs-xrp-ledger-confidential-transfer-securityreview.pdf",
          "label": "2026 04 ripple labs xrp ledger confidential transfer securityreview.pdf",
          "checkedAt": "2026-09-05",
          "status": "opened",
          "sha256": "ea38f093f477225884f91707ec44a1f74bcc72ef80e795f44cb6d58b4856c70f"
        },
        {
          "url": "https://raw.githubusercontent.com/trailofbits/publications/master/reviews/2026-04-gensyn-erc-20-token-securityreview.pdf",
          "label": "2026 04 gensyn erc 20 token securityreview.pdf",
          "checkedAt": "2026-09-05",
          "status": "opened",
          "sha256": "b8affdca20bd8afccb1140587dec2c5c03f95a8a901a9fd8b5d238b5de3666a7"
        },
        {
          "url": "https://raw.githubusercontent.com/trailofbits/publications/master/reviews/2026-04-franklintempleton-benjiswapdifferentialreview-securityreview.pdf",
          "label": "2026 04 franklintempleton benjiswapdifferentialreview securityreview.pdf",
          "checkedAt": "2026-09-05",
          "status": "opened",
          "sha256": "00b4d390152963b829bfb40f1ed03a1d9333396a70bd7c0da8d8f6b3036f54f0"
        },
        {
          "url": "https://raw.githubusercontent.com/trailofbits/publications/master/reviews/2026-03-shape-tokenlock-securityreview.pdf",
          "label": "2026 03 shape tokenlock securityreview.pdf",
          "checkedAt": "2026-09-05",
          "status": "opened",
          "sha256": "89c7103c80b3ac351ccca7f432a02a4551943d13bccc8d4d1779d0aead55223b"
        }
      ]
    },
    {
      "slug": "hacken-evidence-review-2026",
      "measurements": [
        {
          "metric": "Returned API records",
          "value": 1373
        },
        {
          "metric": "SCA records dated no later than check date",
          "value": 1123
        },
        {
          "metric": "Nonempty repository fields",
          "value": 1100
        },
        {
          "metric": "Nonempty commit fields",
          "value": 1043
        },
        {
          "metric": "Records with both fields nonempty",
          "value": 1042
        },
        {
          "metric": "Nonempty asset lists",
          "value": 637
        },
        {
          "metric": "Nonempty issue lists",
          "value": 670
        },
        {
          "metric": "Nonempty report links",
          "value": 1373
        },
        {
          "metric": "Placeholder commit values",
          "value": 21
        },
        {
          "metric": "Single 7-to-40-digit hex commit strings",
          "value": 963
        }
      ],
      "sources": [
        {
          "url": "https://hacken.io/api/audits",
          "label": "Public audits API snapshot",
          "checkedAt": "2026-09-05",
          "status": "opened",
          "sha256": "dca20863d906d096e625de4b29d0c3cddc6f10a17c0290ed0b2b313ccdd07e35"
        },
        {
          "url": "https://hacken.io/services/blockchain-security/smart-contract-security-audit/",
          "label": "Official service description",
          "checkedAt": "2026-09-05",
          "status": "opened",
          "sha256": "a253fd20f9ad23cc5ba4f8b5d4c22c7ef4043fefd5f24af8b0ee17a105105dd8"
        },
        {
          "url": "https://hacken.io/a/kLoHqL",
          "label": "[SCA] vAPI Network / SC Audit / Jul2026",
          "checkedAt": "2026-09-05",
          "status": "opened",
          "sha256": "cbe796565ee8c04494d775082c518eeff653f46683953c4b3be8a363e9a1c028"
        },
        {
          "url": "https://hacken.io/a/cvkBf1",
          "label": "[SCA] Europeum / TPR / Jul2026",
          "checkedAt": "2026-09-05",
          "status": "opened",
          "sha256": "f4c2cb2904a4432ddafcca0d29f720fc83bc0b64089dfef9c2bc606c681bdd45"
        },
        {
          "url": "https://hacken.io/a/YBdWTo",
          "label": "[SCA] Europeum / Beacon Proxy / Jul2026",
          "checkedAt": "2026-09-05",
          "status": "opened",
          "sha256": "ec7d902ab333e408dd67303014ae8a9cda4e24cbab720f93820d830883fd29b5"
        },
        {
          "url": "https://hacken.io/a/zVIZIF",
          "label": "Tangible USDR",
          "checkedAt": "2026-09-05",
          "status": "opened",
          "sha256": "49a79f32c4b21dcaed50635ac63aec61044a28e1a9def678a2b7df20d4eb9415"
        },
        {
          "url": "https://hacken.io/a/-OswHu",
          "label": "YFSX Token",
          "checkedAt": "2026-09-05",
          "status": "opened",
          "sha256": "f8270e344e21cead593f2db5334022cf5ef994ed48d1bbeea7e76cb980957539"
        },
        {
          "url": "https://hacken.io/a/NbZCuC",
          "label": "VIN Token",
          "checkedAt": "2026-09-05",
          "status": "opened",
          "sha256": "18e57cfa5dcbc55987d050e3ee5e2747202c47114bb8a4713d162d2ecc12d518"
        }
      ]
    },
    {
      "slug": "quantstamp-evidence-review-2026",
      "measurements": [
        {
          "metric": "Directly linked PDFs inspected",
          "value": 2
        },
        {
          "metric": "Sample PDFs with version and outcome evidence",
          "value": 2
        },
        {
          "metric": "Sample PDFs inside preceding 24 months",
          "value": 0
        },
        {
          "metric": "Additional HTML reports rendered and inspected",
          "value": 4
        },
        {
          "metric": "All linked sample artifacts within 24-month window",
          "value": 0
        }
      ],
      "sources": [
        {
          "url": "https://quantstamp.com/audits",
          "label": "Current audit service and linked PDFs",
          "checkedAt": "2026-09-05",
          "status": "opened",
          "sha256": "67a9ca2d731616473afc24dc05b480e436f5a5092f6f9e0f4819b67752889074"
        },
        {
          "url": "https://certificate.quantstamp.com/full/maker-dao-liquidations-2-0.pdf",
          "label": "MakerDAO Liquidations 2.0 report",
          "checkedAt": "2026-09-05",
          "status": "opened",
          "sha256": "dc98b30953e93dfc67c9b525e3bf78593929267751a9220ce375bc8c2436b2d5"
        },
        {
          "url": "https://certificate.quantstamp.com/full/teku.pdf",
          "label": "Teku report",
          "checkedAt": "2026-09-05",
          "status": "opened",
          "sha256": "502cd3591359a17ec7d9825b34babbb193af4dd460341f7d216d86c1ff8f80f4"
        },
        {
          "url": "https://certificate.quantstamp.com/full/alchemy-modular-account/2c13aab2-5d5f-4f45-a9ef-b890bdb12b97/index.html",
          "label": "Alchemy Modular Account",
          "checkedAt": "2026-09-05",
          "status": "opened",
          "sha256": "cac0a0b9768ab916936f471a8b966fb443dc052150bf6c461f446078d51ad137",
          "renderedTextSha256": "ddbd0485b2e06a40d228746b13835e1bb19c963bc19a050e86d0b6a59d197e4d"
        },
        {
          "url": "https://certificate.quantstamp.com/full/sperax-us-ds/0612feed-ab51-4cb5-a2b2-32ed244dc385/index.html",
          "label": "Sperax - USDs",
          "checkedAt": "2026-09-05",
          "status": "opened",
          "sha256": "8ac6d26cc0204c365b45a06a89d370612f54682f4dfa04edb4414d91f2391c1f",
          "renderedTextSha256": "60cc0d76e43082dcdb728bf0b77b162b9aba26c92637602a083dafa5cbae3281"
        },
        {
          "url": "https://certificate.quantstamp.com/full/tensorplex-stake/7a7c3615-5f16-4129-86e6-ee4f37fdaf0a/index.html",
          "label": "Tensorplex Stake",
          "checkedAt": "2026-09-05",
          "status": "opened",
          "sha256": "29d8f0570589f4462a76e1c253e587d5817ac90f1a88a672355a6097506b6d72",
          "renderedTextSha256": "a25fc07f34f4a0f8d0ac1be2c3aa66b003f5da38b1eeae2361921016e5b32dc6"
        },
        {
          "url": "https://certificate.quantstamp.com/full/venus-protocol-vaults/9497f0a0-be2e-4214-9ade-f4f2e76b5cb2/index.html",
          "label": "Venus Protocol (Vaults)",
          "checkedAt": "2026-09-05",
          "status": "opened",
          "sha256": "7b5334f48e35b7e6998115f305355d99d27d3d03131529da707df8c532e19dd8",
          "renderedTextSha256": "33446391fd6276898e451969bbe637fbedc07b8cce07a7ccde7f8e8866698bef"
        }
      ]
    },
    {
      "slug": "audit-provider-evidence-study-2026",
      "measurements": [
        {
          "metric": "Directory population",
          "value": 23
        },
        {
          "metric": "Profiles with at least one readable page of 500 characters",
          "value": 17
        },
        {
          "metric": "Profiles with accepted networks",
          "value": 11
        },
        {
          "metric": "Profiles with accepted languages",
          "value": 8
        },
        {
          "metric": "Profiles with accepted services",
          "value": 15
        }
      ],
      "sources": [
        {
          "url": "https://hacken.io/api/audits",
          "label": "Hacken API measured in this study",
          "checkedAt": "2026-09-05",
          "status": "opened",
          "sha256": "dca20863d906d096e625de4b29d0c3cddc6f10a17c0290ed0b2b313ccdd07e35"
        },
        {
          "url": "https://raw.githubusercontent.com/trailofbits/publications/master/reviews/2026-05-kiln-lagoonvaultdiffreview-securityreview.pdf",
          "label": "Trail of Bits resolution example",
          "checkedAt": "2026-09-05",
          "status": "opened",
          "sha256": "ce300c02223b89be2686a74e2b4eca67ab993dc12f744575f1927c12ba34e38b"
        },
        {
          "url": "https://www.openzeppelin.com/news/zksync-os-audit",
          "label": "OpenZeppelin scope example",
          "checkedAt": "2026-09-05",
          "status": "opened",
          "sha256": "02eedac03d6f177cc389c6a828d4a15e347a6ca3b131b34072ed1632de6d2887"
        },
        {
          "url": "https://certificate.quantstamp.com/full/maker-dao-liquidations-2-0.pdf",
          "label": "Quantstamp historical sample",
          "checkedAt": "2026-09-05",
          "status": "opened",
          "sha256": "dc98b30953e93dfc67c9b525e3bf78593929267751a9220ce375bc8c2436b2d5"
        },
        {
          "url": "https://pharosproduction.com/services/security-audits-and-gas-optimization/",
          "label": "Pharos service evidence",
          "checkedAt": "2026-09-05",
          "status": "opened",
          "sha256": "15691c95df3ccd98702fb2e8f7cdf48b27e1d4bb5325c1e21d7447784bce5839"
        }
      ]
    }
  ],
  "directoryRequests": [
    {
      "slug": "verichains",
      "requests": [
        {
          "url": "https://verichains.io/",
          "finalUrl": "https://verichains.io/",
          "status": 200,
          "sha256": "abcc07fa84d0da2a55cd2aa1b60d55b5ab6aea48acaae7f456e8f5a4bc0d691d",
          "textLength": 8593
        },
        {
          "url": "https://verichains.io/audits",
          "finalUrl": null,
          "status": 404,
          "sha256": null,
          "textLength": null
        },
        {
          "url": "https://verichains.io/public-audit-reports",
          "finalUrl": null,
          "status": 404,
          "sha256": null,
          "textLength": null
        }
      ]
    },
    {
      "slug": "hashex",
      "requests": [
        {
          "url": "https://hashex.org/",
          "finalUrl": "https://hashex.org/",
          "status": 200,
          "sha256": "56ff25764655b9070854289110bd5e919eaf8df3d5992c83e0d3388ac40aba3c",
          "textLength": 18280
        },
        {
          "url": "https://hashex.org/audits",
          "finalUrl": "https://hashex.org/audits/",
          "status": 200,
          "sha256": "149044572501033be755d135cf1d1ded8d063024a636cdd00dfaaa69cc4b0f4c",
          "textLength": 4233
        },
        {
          "url": "https://hashex.org/audit",
          "finalUrl": "https://hashex.org/smart-contract-audit/",
          "status": 200,
          "sha256": "ada196289933aa442d18f62fdcb3c5783532f57fdb55977901227952612f01b9",
          "textLength": 6642
        }
      ]
    },
    {
      "slug": "slowmist",
      "requests": [
        {
          "url": "https://www.slowmist.com/",
          "finalUrl": "https://www.slowmist.com/",
          "status": 200,
          "sha256": "ec66f21bb7283593da7e258f08625cdabb2435023d610121a6119ca4cd62840f",
          "textLength": 8466
        },
        {
          "url": "https://www.slowmist.com/security-audit-solution.html",
          "finalUrl": null,
          "status": 404,
          "sha256": null,
          "textLength": null
        },
        {
          "url": "https://www.slowmist.com/audits",
          "finalUrl": null,
          "status": 404,
          "sha256": null,
          "textLength": null
        }
      ]
    },
    {
      "slug": "expelee",
      "requests": [
        {
          "url": "https://expelee.com/",
          "finalUrl": null,
          "status": 0,
          "sha256": null,
          "textLength": null
        },
        {
          "url": "https://expelee.com/audits",
          "finalUrl": null,
          "status": 0,
          "sha256": null,
          "textLength": null
        },
        {
          "url": "https://expelee.com/audit",
          "finalUrl": null,
          "status": 0,
          "sha256": null,
          "textLength": null
        }
      ]
    },
    {
      "slug": "peckshield",
      "requests": [
        {
          "url": "https://peckshield.com/",
          "finalUrl": "https://peckshield.com/",
          "status": 200,
          "sha256": "7130bad796db1b0a0d32a5313434923d626af31497a7b364c5cef56a2f405a3a",
          "textLength": 57
        },
        {
          "url": "https://peckshield.com/audits",
          "finalUrl": "https://peckshield.com/audits",
          "status": 200,
          "sha256": "7130bad796db1b0a0d32a5313434923d626af31497a7b364c5cef56a2f405a3a",
          "textLength": 57
        },
        {
          "url": "https://peckshield.com/publications",
          "finalUrl": "https://peckshield.com/publications",
          "status": 200,
          "sha256": "7130bad796db1b0a0d32a5313434923d626af31497a7b364c5cef56a2f405a3a",
          "textLength": 57
        }
      ]
    },
    {
      "slug": "hydn",
      "requests": [
        {
          "url": "https://www.hydnsec.com/",
          "finalUrl": "https://hydnsec.com/",
          "status": 200,
          "sha256": "a16946a610cd54000077b19f2fc3e856b978c24927128ee2c87a2299ef9a72b4",
          "textLength": 5653
        },
        {
          "url": "https://www.hydnsec.com/audits",
          "finalUrl": null,
          "status": 404,
          "sha256": null,
          "textLength": null
        },
        {
          "url": "https://www.hydnsec.com/reports",
          "finalUrl": null,
          "status": 404,
          "sha256": null,
          "textLength": null
        }
      ]
    },
    {
      "slug": "cyberscope",
      "requests": [
        {
          "url": "https://www.cyberscope.io/",
          "finalUrl": "https://www.cyberscope.io/",
          "status": 200,
          "sha256": "e3e095619e4f53f29ae89cb0ef9826a3a1d1e49d4949eacbef6317c9cfbb9d61",
          "textLength": 7572
        },
        {
          "url": "https://www.cyberscope.io/audits",
          "finalUrl": "https://www.cyberscope.io/audits",
          "status": 200,
          "sha256": "ed9204f99af3ea57c3e1f5dea2a301540f713daefb78899d7cf792590f812ddb",
          "textLength": 4991
        },
        {
          "url": "https://www.cyberscope.io/audits/",
          "finalUrl": "https://www.cyberscope.io/audits",
          "status": 200,
          "sha256": "654b7150f7b04b88065b3afbc8abd5d9c29a30327942f2aba160dfb4bd39d4f7",
          "textLength": 4991
        }
      ]
    },
    {
      "slug": "blaize-security",
      "requests": [
        {
          "url": "https://blaize.tech/",
          "finalUrl": "https://blaize.tech/",
          "status": 200,
          "sha256": "fe18e66537527700adc561c5ec0977fec0c7fb061963079f8b964330786380d5",
          "textLength": 10348
        },
        {
          "url": "https://blaize.tech/audits",
          "finalUrl": null,
          "status": 404,
          "sha256": null,
          "textLength": null
        },
        {
          "url": "https://blaize.tech/cases",
          "finalUrl": null,
          "status": 404,
          "sha256": null,
          "textLength": null
        }
      ]
    },
    {
      "slug": "solidproof",
      "requests": [
        {
          "url": "https://solidproof.io/",
          "finalUrl": "https://solidproof.io/",
          "status": 200,
          "sha256": "00ca81d02f28d2ea4137cfe5112faefa57ee3d5537bca227b7cc914aca1e79a0",
          "textLength": 11272
        },
        {
          "url": "https://solidproof.io/audits",
          "finalUrl": "https://solidproof.io/projects",
          "status": 200,
          "sha256": "5869daddb97fd5635c3dcbf0228f85332ea898f10fbd9fee196a9706f1ba8de6",
          "textLength": 3054
        },
        {
          "url": "https://solidproof.io/projects",
          "finalUrl": "https://solidproof.io/projects",
          "status": 200,
          "sha256": "4b6989ad2d1dcabade781ea380bab88d67d4869f31484028afc3d6527c6ba454",
          "textLength": 2982
        }
      ]
    },
    {
      "slug": "callisto",
      "requests": [
        {
          "url": "https://audits.callisto.network/",
          "finalUrl": "https://audits.callisto.network/",
          "status": 200,
          "sha256": "38cf9bfa72ae6d80de56cd971d75c6882ff83786ec053481d133cdc45d2d4c37",
          "textLength": 30
        },
        {
          "url": "https://audits.callisto.network/audits",
          "finalUrl": "https://audits.callisto.network/audits",
          "status": 200,
          "sha256": "38cf9bfa72ae6d80de56cd971d75c6882ff83786ec053481d133cdc45d2d4c37",
          "textLength": 30
        }
      ]
    },
    {
      "slug": "rapid-labs",
      "requests": [
        {
          "url": "https://rapidlabs.finance/",
          "finalUrl": "https://rapidlabs.finance/",
          "status": 200,
          "sha256": "e11b639efb8c7f9290e0e3d2e7300ae85c973630b5030e0570295c11d01319a1",
          "textLength": 202
        },
        {
          "url": "https://rapidlabs.finance/audits",
          "finalUrl": null,
          "status": 404,
          "sha256": null,
          "textLength": null
        },
        {
          "url": "https://rapidlabs.finance/reports",
          "finalUrl": null,
          "status": 404,
          "sha256": null,
          "textLength": null
        }
      ]
    },
    {
      "slug": "cystack",
      "requests": [
        {
          "url": "https://cystack.net/",
          "finalUrl": "https://cystack.net/",
          "status": 200,
          "sha256": "3eb110b90bb4d651503ddda9c34e04c44340143d1c59269e19c3601452eac98c",
          "textLength": 7139
        },
        {
          "url": "https://cystack.net/audits",
          "finalUrl": "https://cystack.net/audits",
          "status": 200,
          "sha256": "4bc9184dbed6df7a995d55b16a84378d3fd30c27b8f6859fdc1d3dd74140caad",
          "textLength": 1064
        },
        {
          "url": "https://cystack.net/reports",
          "finalUrl": "https://cystack.net/reports",
          "status": 200,
          "sha256": "7214bded64b9e0c5eceb7d5962f5514f2dab3797deffe2a8a934c03003e5f0e3",
          "textLength": 6958
        }
      ]
    },
    {
      "slug": "source-hat",
      "requests": [
        {
          "url": "https://sourcehat.com/",
          "finalUrl": "https://sourcehat.com/",
          "status": 200,
          "sha256": "26a87b74ec873c7bec16699935a77b43eb89c48cbf9f30d2cc363ef44b566606",
          "textLength": 34
        },
        {
          "url": "https://sourcehat.com/audits/",
          "finalUrl": "https://sourcehat.com/audits/",
          "status": 200,
          "sha256": "c486c789207171a24059038027a935df3f38a8b995e7911fcbf74834a84f4129",
          "textLength": 34
        }
      ]
    },
    {
      "slug": "blocksec",
      "requests": [
        {
          "url": "https://blocksec.com/",
          "finalUrl": "https://blocksec.com/",
          "status": 200,
          "sha256": "a91fd0c6b2dca44299ccf78f01118404288e3ab60df152f908823b6670575eed",
          "textLength": 18932
        },
        {
          "url": "https://blocksec.com/audits",
          "finalUrl": null,
          "status": 404,
          "sha256": null,
          "textLength": null
        },
        {
          "url": "https://blocksec.com/audit-reports",
          "finalUrl": null,
          "status": 404,
          "sha256": null,
          "textLength": null
        }
      ]
    },
    {
      "slug": "quantstamp",
      "requests": [
        {
          "url": "https://quantstamp.com/",
          "finalUrl": "https://quantstamp.com/",
          "status": 200,
          "sha256": "6ce06ee0710d7cd56faaa1b0ce721ed8346ac61aee0ec70acc5bd70036394be7",
          "textLength": 9275
        },
        {
          "url": "https://quantstamp.com/audits",
          "finalUrl": "https://quantstamp.com/audits",
          "status": 200,
          "sha256": "67a9ca2d731616473afc24dc05b480e436f5a5092f6f9e0f4819b67752889074",
          "textLength": 8434
        },
        {
          "url": "https://quantstamp.com/reports",
          "finalUrl": null,
          "status": 404,
          "sha256": null,
          "textLength": null
        }
      ]
    },
    {
      "slug": "openzeppelin",
      "requests": [
        {
          "url": "https://www.openzeppelin.com/",
          "finalUrl": "https://www.openzeppelin.com/",
          "status": 200,
          "sha256": "f94c65b5e0dab683612cf9e2001f1a9f4553de8ff12ea1a1ffec11109436db6c",
          "textLength": 10121
        },
        {
          "url": "https://www.openzeppelin.com/security-audits",
          "finalUrl": "https://www.openzeppelin.com/security-audits",
          "status": 200,
          "sha256": "14277e05b221f30ffa19aa08891b32b921dcaf844ae040b726b50cb83357f5d0",
          "textLength": 18786
        },
        {
          "url": "https://www.openzeppelin.com/security-audits/",
          "finalUrl": "https://www.openzeppelin.com/security-audits",
          "status": 200,
          "sha256": "14277e05b221f30ffa19aa08891b32b921dcaf844ae040b726b50cb83357f5d0",
          "textLength": 18786
        }
      ]
    },
    {
      "slug": "shellboxes",
      "requests": [
        {
          "url": "https://shellboxes.com/",
          "finalUrl": "https://shellboxes.com/",
          "status": 200,
          "sha256": "2e0f7266673a00d0a267effa04afcb61ebb530751af77157808ce5437482ca11",
          "textLength": 7342
        },
        {
          "url": "https://shellboxes.com/audits",
          "finalUrl": null,
          "status": 404,
          "sha256": null,
          "textLength": null
        },
        {
          "url": "https://shellboxes.com/reports",
          "finalUrl": null,
          "status": 404,
          "sha256": null,
          "textLength": null
        }
      ]
    },
    {
      "slug": "trail-of-bits",
      "requests": [
        {
          "url": "https://www.trailofbits.com/",
          "finalUrl": "https://trailofbits.com/",
          "status": 200,
          "sha256": "67208c479ffe510f5ade2a3394494e62fa6e2965c8310a79e4862cb2201ccd9e",
          "textLength": 7914
        },
        {
          "url": "https://www.trailofbits.com/reports",
          "finalUrl": "https://trailofbits.com/reports",
          "status": 200,
          "sha256": "ac5ed62a6753c30bfcf2f90fb80c3de964ecb2e015e259e3f6f960ee4a11ef60",
          "textLength": 89550
        },
        {
          "url": "https://www.trailofbits.com/publications",
          "finalUrl": null,
          "status": 404,
          "sha256": null,
          "textLength": null
        }
      ]
    },
    {
      "slug": "0xguard",
      "requests": [
        {
          "url": "https://0xguard.com/",
          "finalUrl": "https://0xguard.com/",
          "status": 200,
          "sha256": "1a3d5a28012e95a9c04fb1e866fada91c0f80ea66b099b6c6e00167127fd06fd",
          "textLength": 11118
        },
        {
          "url": "https://0xguard.com/audits",
          "finalUrl": null,
          "status": 404,
          "sha256": null,
          "textLength": null
        },
        {
          "url": "https://0xguard.com/reports",
          "finalUrl": null,
          "status": 404,
          "sha256": null,
          "textLength": null
        }
      ]
    },
    {
      "slug": "quillaudits",
      "requests": [
        {
          "url": "https://www.quillaudits.com/",
          "finalUrl": "https://www.quillaudits.com/",
          "status": 200,
          "sha256": "a638cfb3a5e5f2751f6af9053b405cdf188a4adb6ee1a896791b87df9130d852",
          "textLength": 3884
        },
        {
          "url": "https://www.quillaudits.com/audits",
          "finalUrl": null,
          "status": 404,
          "sha256": null,
          "textLength": null
        },
        {
          "url": "https://www.quillaudits.com/smart-contract-audit",
          "finalUrl": "https://www.quillaudits.com/smart-contract-audit",
          "status": 200,
          "sha256": "a253da1b96a37b5272c3f72a689c48fca352f0a810d00a9332762ba75334e6c3",
          "textLength": 4927
        }
      ]
    },
    {
      "slug": "paladin-ai",
      "requests": [
        {
          "url": "https://paladinai.com/",
          "finalUrl": null,
          "status": 0,
          "sha256": null,
          "textLength": null
        },
        {
          "url": "https://paladinai.com/audits",
          "finalUrl": null,
          "status": 0,
          "sha256": null,
          "textLength": null
        },
        {
          "url": "https://paladinai.com/reports",
          "finalUrl": null,
          "status": 0,
          "sha256": null,
          "textLength": null
        }
      ]
    },
    {
      "slug": "hacken",
      "requests": [
        {
          "url": "https://hacken.io/",
          "finalUrl": "https://hacken.io/",
          "status": 200,
          "sha256": "5b3f8bc1c51b23443d9d4682d18ac07f41359685110a556bef371b3aa8804c51",
          "textLength": 7552
        },
        {
          "url": "https://hacken.io/audits",
          "finalUrl": "https://hacken.io/audits/",
          "status": 200,
          "sha256": "7ad36e980a2d502c60ed8bc7e945cc15f39e0bd47cbb83e3217d18c87f639bef",
          "textLength": 3718
        },
        {
          "url": "https://hacken.io/audits/",
          "finalUrl": "https://hacken.io/audits/",
          "status": 200,
          "sha256": "ef9364b5b527ea4a646009e7e41511d2abb69e0ded23d0b79783a68fb4c71aa1",
          "textLength": 3718
        }
      ]
    },
    {
      "slug": "pharos-production",
      "requests": [
        {
          "url": "https://pharosproduction.com/",
          "finalUrl": "https://pharosproduction.com/",
          "status": 200,
          "sha256": "72191b403781ef206638c9af23dfb7c85aee474102797567c79df7809978dbc3",
          "textLength": 77862
        },
        {
          "url": "https://pharosproduction.com/smart-contract-audit",
          "finalUrl": "https://pharosproduction.com/services/security-audits-and-gas-optimization/",
          "status": 200,
          "sha256": "238e61d1e4858f79beb745af123262b35b824ee99012d5a3e2c22ae34ede63e4",
          "textLength": 56436
        }
      ]
    }
  ],
  "expandedSelection": [
    {
      "provider": "openzeppelin",
      "url": "https://www.openzeppelin.com/news/miden-smart-contracts-audit",
      "reason": "First distinct project candidates in research-index DOM order; publication dates verified after retrieval."
    },
    {
      "provider": "openzeppelin",
      "url": "https://www.openzeppelin.com/news/stablegold-audit",
      "reason": "First distinct project candidates in research-index DOM order; publication dates verified after retrieval."
    },
    {
      "provider": "openzeppelin",
      "url": "https://www.openzeppelin.com/news/txflow-security-audit",
      "reason": "First distinct project candidates in research-index DOM order; publication dates verified after retrieval."
    },
    {
      "provider": "openzeppelin",
      "url": "https://www.openzeppelin.com/news/across-protocol-v5-bridging-system-audit",
      "reason": "First distinct project candidates in research-index DOM order; publication dates verified after retrieval."
    },
    {
      "provider": "openzeppelin",
      "url": "https://www.openzeppelin.com/news/contracts-v5-audit",
      "reason": "First distinct project candidates in research-index DOM order; publication dates verified after retrieval."
    },
    {
      "provider": "trail-of-bits",
      "url": "https://raw.githubusercontent.com/trailofbits/publications/master/reviews/2026-05-kiln-lagoonvaultdiffreview-securityreview.pdf",
      "reason": "Recent visible blockchain-related report, unique project; filename date ties resolved by explicit sample selection."
    },
    {
      "provider": "trail-of-bits",
      "url": "https://raw.githubusercontent.com/trailofbits/publications/master/reviews/2026-04-ripple-labs-xrp-ledger-confidential-transfer-securityreview.pdf",
      "reason": "Recent visible blockchain-related report, unique project; filename date ties resolved by explicit sample selection."
    },
    {
      "provider": "trail-of-bits",
      "url": "https://raw.githubusercontent.com/trailofbits/publications/master/reviews/2026-04-gensyn-erc-20-token-securityreview.pdf",
      "reason": "Recent visible blockchain-related report, unique project; filename date ties resolved by explicit sample selection."
    },
    {
      "provider": "trail-of-bits",
      "url": "https://raw.githubusercontent.com/trailofbits/publications/master/reviews/2026-04-franklintempleton-benjiswapdifferentialreview-securityreview.pdf",
      "reason": "Recent visible blockchain-related report, unique project; filename date ties resolved by explicit sample selection."
    },
    {
      "provider": "trail-of-bits",
      "url": "https://raw.githubusercontent.com/trailofbits/publications/master/reviews/2026-03-shape-tokenlock-securityreview.pdf",
      "reason": "Recent visible blockchain-related report, unique project; filename date ties resolved by explicit sample selection."
    },
    {
      "provider": "hacken",
      "url": "https://hacken.io/a/kLoHqL",
      "date": "2026-08-20T00:00:00.000Z",
      "project": "vAPI Network",
      "reason": "Latest SCA records in 24 months, date/name descending, deduplicated by client_name."
    },
    {
      "provider": "hacken",
      "url": "https://hacken.io/a/cvkBf1",
      "date": "2026-08-13T00:00:00.000Z",
      "project": "Europeum",
      "reason": "Latest SCA records in 24 months, date/name descending, deduplicated by client_name."
    },
    {
      "provider": "hacken",
      "url": "https://hacken.io/a/zVIZIF",
      "date": "2026-08-04T00:00:00.000Z",
      "project": "Tangible \u2013 USDR",
      "reason": "Latest SCA records in 24 months, date/name descending, deduplicated by client_name."
    },
    {
      "provider": "hacken",
      "url": "https://hacken.io/a/-OswHu",
      "date": "2026-07-29T00:00:00.000Z",
      "project": "YFSX Token",
      "reason": "Latest SCA records in 24 months, date/name descending, deduplicated by client_name."
    },
    {
      "provider": "hacken",
      "url": "https://hacken.io/a/NbZCuC",
      "date": "2026-07-29T00:00:00.000Z",
      "project": "VIN Token",
      "reason": "Latest SCA records in 24 months, date/name descending, deduplicated by client_name."
    },
    {
      "provider": "quantstamp",
      "url": "https://certificate.quantstamp.com/full/alchemy-modular-account/2c13aab2-5d5f-4f45-a9ef-b890bdb12b97/index.html",
      "reason": "HTML report linked from current service page; date checked after retrieval. Historical PDFs retained as excluded-age examples."
    },
    {
      "provider": "quantstamp",
      "url": "https://certificate.quantstamp.com/full/sperax-us-ds/0612feed-ab51-4cb5-a2b2-32ed244dc385/index.html",
      "reason": "HTML report linked from current service page; date checked after retrieval. Historical PDFs retained as excluded-age examples."
    },
    {
      "provider": "quantstamp",
      "url": "https://certificate.quantstamp.com/full/tensorplex-stake/7a7c3615-5f16-4129-86e6-ee4f37fdaf0a/index.html",
      "reason": "HTML report linked from current service page; date checked after retrieval. Historical PDFs retained as excluded-age examples."
    },
    {
      "provider": "quantstamp",
      "url": "https://certificate.quantstamp.com/full/venus-protocol-vaults/9497f0a0-be2e-4214-9ade-f4f2e76b5cb2/index.html",
      "reason": "HTML report linked from current service page; date checked after retrieval. Historical PDFs retained as excluded-age examples."
    }
  ],
  "exclusions": [
    "OpenZeppelin research index: repeated Across project variants excluded from expanded sample; original ZKsync OS artifact retained for a detailed case study.",
    "Trail of Bits: PyPI and Open Home Foundation reports excluded as outside this blockchain-focused sample; multiple Gensyn report variants collapsed to one project.",
    "Hacken: repeated client_name entries excluded from expanded project sample; the original first-three-record measurement remains a separate diagnostic sample.",
    "Quantstamp: MakerDAO 2021 and Teku 2020 PDFs are outside the 24-month qualification window; retained only as historical examples.",
    "Pharos: no customer report established in the bounded official page set."
  ],
  "qualificationWindow": {
    "start": "2024-09-05",
    "end": "2026-09-05",
    "minimumDistinctProjects": 3,
    "maximumTargetSample": 5,
    "limitations": "The initial source-access pilot was expanded to up to five distinct project candidates where accessible. Candidate ordering is documented, not asserted to be an exhaustive chronology. Quantstamp includes all six linked landing-page artifacts because all predate the window; they are excluded from current qualification."
  }
}
