DeFi Security Alliance

DSA original research · Version 1.0

Pharos Production: service claims and the missing report packet

The service page describes a priced audit process. Public customer-report evidence was not established in this bounded check.

DSA research, prepared with AI assistance. .

Public-source research; independent expert review pending

Measurements in this report

Distinct homepage/service/policy artifacts
3
Customer audit reports established in those pages
0 Bounded page set only; private reports not inspected

Evidence coverage against the seven criteria

These are research observations. All scores are withheld until independent reviewers assess the evidence.

Criterion evidence and remaining checks
CriterionStatusEvidence boundary
Technical finding qualityNot scoredNo customer finding artifact established.
Depth and threat modelNot scoredMethod described by provider; engagement workpapers unavailable.
Scope and version traceabilityNot scoredCustomer scope and version evidence missing from this packet.
Demonstrated specializationNot scoredService statements only; comparable project reports still required.
Fix verificationNot scoredProvider offers follow-up; no customer fix trail inspected.
Internal quality control and responseNot scoredNo independent internal QA workpapers inspected.
Transparency and conflictsNot scoredPublic identity sources are available. Reviewer and commercial conflict declarations have not been collected.

The decision this evidence supports

Pharos can be considered for an initial scoping conversation on the basis of its published service description. That is a narrower conclusion than a technical recommendation. Its featured position on DSA does not fill the missing customer-report evidence and the technical committee has not assessed the firm.

Source selection and original observation

We opened the official homepage, the smart-contract-audit URL that redirects to the audit service, the canonical service page and the editorial policy. The redirected and canonical service URLs returned the same content hash, so they count as one content artifact. The homepage, service page and policy constitute three distinct page artifacts in the pilot packet.

Within those pages, we did not establish a customer audit report containing an identified code revision, finding details and a resolution trail. Links to third-party research and tools do not satisfy that requirement. This is a result for the pages inspected, not a claim that Pharos has never produced or privately shared such a report.

Pricing and scope need separate interpretation

The service page advertises a single-contract starting price of $8,000 and separately presents $8,000 as a median from a provider-reported delivery sample. A starting price and a sample median answer different questions. Neither gives a quote for a specified protocol and neither establishes how much reviewer time is included. DSA now presents the starting price with its source and requests a scoped quote.

The service describes manual code review, automated analysis, formal verification where warranted and remediation guidance. These are attributed service claims. Naming a tool does not establish that it was used effectively on a customer engagement or that an invariant suite covered a particular economic risk.

Evidence to request before selection

Request three recent customer reports with permission to inspect them, including one matching the proposed chain, language and protocol class. Ask for the initial and final commits, excluded contracts, reviewer roles, a material finding's execution trace and the fix-verification record. If reports are confidential, the committee can inspect them under confidentiality and publish a limited rationale.

For the commercial proposal, identify the number of reviewers, estimated effort, gas-optimization scope, fix-review allowance and terms for a changed codebase. Ask which published performance figures can be reconciled to underlying records. Until that packet is reviewed, all seven technical criteria remain unscored.

Limits and next verification step

This is a bounded review of public evidence. We did not rerun exploits, inspect private workpapers, interview the assigned audit team or verify current booking availability. The observations describe the cited artifacts and cannot establish the provider's overall defect-detection rate. A procurement decision still needs a scoped proposal, relevant recent work and independent technical review.

Sources and reproducibility

Sources were opened on September 5, 2026. The data download records content hashes and measurement definitions. Counts describe the selected artifacts; provider-reported findings were not independently reproduced.

  1. Official audit service and pricing · checked SHA-256: 15691c95df3ccd98702fb2e8f7cdf48b27e1d4bb5325c1e21d7447784bce5839
  2. Official homepage · checked SHA-256: 72191b403781ef206638c9af23dfb7c85aee474102797567c79df7809978dbc3
  3. Provider editorial policy · checked SHA-256: 4c9a63cacd75ad185d663e9d8662cdba49cdab01c7617af23483eed4a1c644c7