# About AuditOne

AuditOne delivers modern audit infrastructure and cybersecurity services built for the teams that set the standard for trust.duction

Introducing TIC OS (formerly ISO OS)\
TIC OS is the AI-native operating system for certification bodies. It unifies the entire audit lifecycle, both ISO and non-ISO standards, into a single, AI-powered ecosystem. From client intake and smart scheduling to final certificate issuance, TIC OS eliminates the administrative friction holding your firm back.

Why Certification Bodies Choose TIC OS:

1. Instant Deployment: Built natively around IAF MD guidelines. Start auditing on day one - no complex onboarding required.
2. AI-Driven Automation: Let AI handle the heavy lifting. Automate pre-audit document triage, optimize complex audit planning, and generate reports with one click.
3. Scale Beyond the Talent Shortage: Supercharge your existing team's capacity. TIC OS handles the routine workflows with precision, allowing your certification body to scale volume without needing to instantly source hard-to-find qualified auditors.

Maintain absolute control, collaborate without friction, and uphold the highest standards of quality at every step of the certification journey.

Sharing our vision and have business or an innovative idea in mind? Reach out to us! <hello@auditone.io>


# Our Vision

Defining the Standards of a Secure Digital Future

AuditOne envisions a digital world where high-quality security and absolute transparency are fundamental principles, not afterthoughts.&#x20;

At the heart of this mission is our AI-native TIC OS. This specialized ERP system serves as the foundational infrastructure for the entire certification & inspection lifecycles, automating complex workflows and ensuring institutional-grade reliability. Rather than viewing an audit as a static event, our AI-native operating system allows for a modular, comprehensive approach to project integrity. By integrating advanced technology with deep human expertise, AuditOne is setting the benchmark for how trust is built and maintained in the decentralized economy.

<br>


# What makes us different?

#### The Evolution of Security: Bridging Traditional Rigor and Crowdsourced Intelligence

For digital ecosystems to scale securely, founders must move beyond "check-the-box" security. AuditOne has engineered a superior auditing strategy by synthesizing the institutional reliability of traditional global audit firms with the aggressive, decentralized intelligence of bug bounty platforms.

#### The AuditOne Hybrid Model

Unlike traditional models, AuditOne utilizes a competitive peer-review framework. We crowdsource elite, verified auditors who work independently on your project. This "proof-of-work" approach:

* Eliminates Collusion: Independent reviews ensure unbiased results.
* Maximizes Discovery: Multiple perspectives increase the probability of identifying edge-case vulnerabilities that a single auditor might miss.
* Streamlined Remediation: After our internal peer-review phase, findings are consolidated and shared with your team, allowing for fixes before the final report is published and a bug bounty is launched.

#### Our process separates us from other audit firms:&#x20;

<details>

<summary><strong>Transparent and Effective Auditing with AuditOne</strong></summary>

At AuditOne, our goal is not merely to rubberstamp a project with a complete audit but to make the auditing process as transparent and effective as possible. We aim to reduce the risk of bugs slipping through our net by providing the best auditing strategy. Unlike traditional audit firms, most fees paid to AuditOne are distributed to the auditors, ensuring they receive fair compensation for their work.

</details>

<details>

<summary><strong>Enhanced Auditor Pool and Compensation Structure</strong></summary>

Traditional firms typically have one or two auditors examining the code over time. At AuditOne, we utilize a pool of three auditors and an internal AuditOne reviewer for each project. This approach ensures a more thorough code examination and incorporates a bug bounty element during the session. Auditors are rewarded based on the severity of the issues they discover. Projects pay less for less severe issues but reward auditors for finding severe issues, incentivizing them to review the codebase meticulously.

</details>

<details>

<summary><strong>Quality Assurance and Peer Review</strong></summary>

To ensure the highest quality of work, we conduct an independent peer review of the audit findings. After the project team fixes the identified issues, AuditOne reviews the codebase again to ensure that the developers didn't introduce new bugs during the audit before issuing the final report.

</details>

<details>

<summary><strong>Auditor Transparency and Expertise</strong></summary>

We perform KYC on our auditors, providing projects with confidence in the individuals performing their audits. Our auditors are not anonymous; they are the centerpiece of our organization, and you can view them on our leaderboard. All auditors are vetted thoroughly through our verification examination to ensure they meet our high standards.

</details>

<details>

<summary><strong>Reduced Waiting Times</strong></summary>

With a large pool of over 400+ auditors, AuditOne significantly reduces the waiting time for audits compared to traditional firms, which often take months to start. This extensive pool allows us to begin audits promptly and deliver timely results. Here is a list of our [top ten auditors](https://www.auditone.io/auditors).&#x20;

</details>

\
**Request an audit** [**here**](https://www.auditone.io/)**.**

<table><thead><tr><th width="310"> </th><th align="center">AuditOne </th><th align="center">Audit Firms</th><th align="center">Bug Bounty Platforms</th></tr></thead><tbody><tr><td><strong>All-in-one Security Platform</strong></td><td align="center">✅</td><td align="center">❌</td><td align="center">❌</td></tr><tr><td><strong>Verified Identity of auditors</strong></td><td align="center">✅</td><td align="center">✅</td><td align="center">❌</td></tr><tr><td><strong>Audit Tools</strong></td><td align="center">✅</td><td align="center">❌</td><td align="center">❌</td></tr><tr><td><strong>Auditor performance review</strong></td><td align="center">✅</td><td align="center">✅</td><td align="center">❌</td></tr><tr><td><strong>Peer-review</strong></td><td align="center">✅</td><td align="center">❌</td><td align="center">✅</td></tr><tr><td><strong>Cost</strong></td><td align="center">€€</td><td align="center">€€€</td><td align="center">€-€€€</td></tr><tr><td><strong>Fair compensation for auditors</strong></td><td align="center">✅</td><td align="center">❌</td><td align="center">✅</td></tr><tr><td><strong>Guaranteed payment for auditors</strong></td><td align="center">✅</td><td align="center">✅</td><td align="center">❌</td></tr><tr><td><strong>Bug bounty</strong></td><td align="center">✅</td><td align="center">❌</td><td align="center">✅</td></tr><tr><td><strong>Credibility for projects</strong></td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td></tr><tr><td><strong>Standardized report</strong></td><td align="center">✅</td><td align="center">✅</td><td align="center">❌</td></tr><tr><td><strong>Waiting time</strong></td><td align="center">1 week</td><td align="center">2-3 months</td><td align="center">1 week</td></tr><tr><td><strong>Audit time</strong></td><td align="center">1 month</td><td align="center">1 month</td><td align="center">Ongoing</td></tr></tbody></table>


# TIC OS: Audit Management Software for Certification Bodies

Streamlining Conformity Assessment through Intelligent Automation Software and IAF MD Alignment

The [AuditOne TIC OS](https://www.auditone.io/iso-os) (formerly ISO OS) is a software solution engineered specifically for Certification Bodies (CBs). The platform is designed to automate the high-volume, non-judgmental phases of the ISO audit lifecycle (while non-ISO can be supported), ensuring your technical experts can dedicate their focus to high-level risk assessment and quality-driven decision-making.

Unlike generic audit software tools, AuditOne is built with deep-coded adherence to IAF Mandatory Documents (MD) and ISO/IEC 17021-1 requirements. We provide the structural framework necessary to maintain your Accreditation Status while scaling operations:

* IAF MD Guidelines Integration: Automated workflows for audit duration calculations (MD 5), multi-site sampling (MD 1), and competence management (MD 7).
* End-to-End Audit Lifecycle Automation: From initial Application Review and Contract Review to Stage 1/Stage 2 Planning, and final Certification Decision workflows.
* Integrated Management System (IMS) Support: Seamlessly manage complex, multi-standard audits with unified Audit Evidence collection.<br>

All Standard modules and functions of the software are included in every TIC OS subscription unless otherwise agreed in writing.

## Modules

### Module 1 — Applications

#### Client Onboarding & Sales

End-to-end intake flow from first client contact through signed contract. Covers the full sales and onboarding cycle.

| #  | Function / Feature                  | Description                                                                                                                                                                                                   | Tier       |
| -- | ----------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------- |
| 1  | Application Overview                | Centralised dashboard of all incoming and active applications with status tracking, filtering, and quick navigation.                                                                                          | ✓ Standard |
| 2  | Audit Day & Duration Calculation    | Automated calculation of required audit days based on employee count, number of locations, applicable standards, complexity factors, and adjustable overrides. Supports multi-site and multi-standard audits. | ✓ Standard |
| 3  | Availability Scheduling             | Auditee availability and duration planning. Clients can select which weeks they are available for an audit.                                                                                                   | ✓ Standard |
| 4  | Pricing & Offer Calculation         | Automated price calculation based on audit days, registration fees, auditor rates, and configurable discounts. Supports multi-stage inclusions and exclusions.                                                | ✓ Standard |
| 5  | Quote Generation                    | Automatic generation of a quote document from a certification body-provided template, shareable directly from the application.                                                                                | ✓ Standard |
| 6  | Contract Generation                 | Automatic generation of the client contract from a certification body-provided template, directly linked to application data.                                                                                 | ✓ Standard |
| 7  | In-App Contract Signing             | Clients can review, request revisions of, and digitally sign the contract and quote without leaving the portal.                                                                                               | ✓ Standard |
| 8  | Contract Revision & Version History | Full revision tracking with version history, audit trail of changes, and revision requests between the certification body and client.                                                                         | ✓ Standard |
| 9  | PDF Export                          | Export signed contracts and quotes as PDF directly from the application.                                                                                                                                      | ✓ Standard |
| 10 | Client Application Portal           | Dedicated client-facing intake form verified via OTP. Client can submit details about their company, specify availability and preferred or blocked weeks, and sign contract.                                  | ✓ Standard |
| 11 | Multi-Language Client Portal        | The client portal supports language switching to accommodate international clients.                                                                                                                           | ✓ Standard |
| 12 | Secure Link Management              | Application links use expiring tokens. A certification body can extend link validity. Clients can request a new link via email verification after expiry.                                                     | ✓ Standard |
| 13 | Draft Revert                        | Revert a submitted application back to draft so the client can amend data (e.g. add locations, standards, employees). Previously entered data is retained.                                                    | ✓ Standard |
| 14 | Deal Status Management              | Mark deals as lost or reactivate them. Permanently delete applications as required.                                                                                                                           | ✓ Standard |

<br>

### Module 2 — Audits: Planning

#### Auditor Assignment & Audit Plan Generation

All pre-audit logistics: sourcing auditors, building the team, and generating the detailed audit plan.

| # | Function / Feature                    | Description                                                                                                                                                                          | Tier       |
| - | ------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ---------- |
| 1 | Audit Overview                        | Dashboard of all upcoming, ongoing, and completed audits with key metadata and quick access.                                                                                         | ✓ Standard |
| 2 | Certification Plan                    | High-level view of the full certification cycle. Manages which standards, locations, and controls are in or out of scope across all audit stages.                                    | ✓ Standard |
| 3 | Audit Listing (Auditor Marketplace)   | Publish an audit to the internal or external auditor network so auditors can indicate availability and interest in participating.                                                    | ✓ Standard |
| 4 | Auditor Assignment                    | View availability, qualifications, and conflicts of interest. Assign auditors in defined roles: Lead Auditor, Auditor, Technical Expert, and others.                                 | ✓ Standard |
| 5 | Audit Plan Generation                 | Automatic generation of a detailed day-by-day audit plan based on template, clauses/controls, auditor assignments, locations, working hours, lunch breaks, and rounding preferences. | ✓ Standard |
| 6 | Multi-Stage & Multi-Standard Planning | Supports Stage 1 and Stage 2 audits, surveillance, recertification, and other audit types as defined in the certification plan.                                                      | ✓ Standard |
| 7 | Plan Editing & Bulk Edits             | Full manual editing of the generated audit plan. Bulk edit capabilities with validation checks for gaps, overlaps, and maximum daily audit hours.                                    | ✓ Standard |
| 8 | Calendar & Table View                 | View the audit plan in a table or interactive calendar format. Export to Excel.                                                                                                      | ✓ Standard |

<br>

### Module 3 — Audits: Execution

#### Evidence Collection & Fieldwork

Conducting the audit itself — document management, evidence collection, findings recording, and AI-assisted guidance.

| # | Function / Feature                  | Description                                                                                                                                                          | Tier       |
| - | ----------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------- |
| 1 | Document Upload & Management        | Upload client-submitted documents. Categorise by type, add name, publication date, and version number.                                                               | ✓ Standard |
| 2 | Third-Party Source Integration      | Connect external sources (e.g. Confluence, compliance platforms) to automatically fetch documents into ISO OS.                                                       | ✓ Standard |
| 3 | Audit Execution Interface           | Timeline-based execution interface aligned with the audit plan. Full clause and control structure visible with status indicators.                                    | ✓ Standard |
| 4 | Findings & Evidence Management      | Attach evidence, add audit notes, and set conformity status (conformity, nonconformity, opportunity for improvement, etc.) for each clause and control.              | ✓ Standard |
| 5 | Expected Evidence & Key Questions   | Pre-configured guidance per clause: expected evidence, key questions, and auditor notes to streamline fieldwork.                                                     | ✓ Standard |
| 6 | AI Readiness Check                  | AI-powered pre-audit document check. Analyses uploaded documents and flags missing policies or evidence before fieldwork begins.                                     | ⬡ AI       |
| 7 | AI Auditor Guidance (Stage-1 Agent) | AI assistant that processes all uploaded evidence, suggests findings, proposes audit questions for gaps, and recommends evidence attachments per clause and control. | ⬡ AI       |

<br>

### Module 4 — Audits: Reporting

#### Document Generation, Signing & Certificate Issuance

Generating, reviewing, signing, and distributing all audit documents and certificates.

| # | Function / Feature              | Description                                                                                                                                      | Tier       |
| - | ------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------ | ---------- |
| 1 | Document Generation             | Pre-fill report forms with organisational and audit data. Auditor reviews, adjusts, and generates the final document.                            | ✓ Standard |
| 2 | Approval Workflow               | Configurable approval cycles (e.g. lead auditor and reviewer sign-off) before final document generation. Full audit trail of approvals.          | ✓ Standard |
| 3 | Document Preview & Download     | Preview generated documents in-app and download as formatted files.                                                                              | ✓ Standard |
| 4 | Client Signing Portal           | Clients access a secure portal to view, sign, annotate, and process all audit documents without the certification body sending files externally. | ✓ Standard |
| 5 | Audit Report (Auto-Generated)   | A comprehensive audit report is automatically generated from execution findings, nonconformities, and evidence collected during the audit.       | ✓ Standard |
| 6 | Nonconformity Management        | Track open nonconformities, assign corrective action deadlines, and link closures to evidence within the platform.                               | ✓ Standard |
| 7 | Custom Certificate Issuance     | Generate a branded certificate matching the certification body's design. Configurable to exact specifications.                                   | ✓ Standard |
| 8 | QR Code & Registry Verification | Generate QR codes and verification links (e.g. IAF database) embedded in certificates for real-time public verification.                         | ✓ Standard |

<br>

### Module 5 — Auditors

#### Auditor CRM & Credential Management

Centralised auditor relationship management: onboarding, profile management, qualification tracking, and access control.

| # | Function / Feature                 | Description                                                                                                                                       | Tier       |
| - | ---------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------- | ---------- |
| 1 | Auditor Profile Management         | Create and maintain detailed auditor profiles including sector codes, technical codes, industry focus, certifications held, and languages spoken. | ✓ Standard |
| 2 | Auditor Invitation & Onboarding    | Invite auditors by email. Auditors activate their account via invitation link and complete their own profile setup.                               | ✓ Standard |
| 3 | Document & Credential Verification | Auditors upload qualification documents. Certification body manually reviews and approves each auditor.                                           | ✓ Standard |
| 4 | Access Control per Audit           | Define each auditor's access level per audit: Viewer, Auditor, or Lead Auditor.                                                                   | ✓ Standard |
| 5 | Activate / Deactivate Auditors     | Enable or disable auditor access to the platform as required.                                                                                     | ✓ Standard |

<br>

### Module 6 — Consultants

#### Partner Portal & Referral Management

Manage consulting partner companies that refer clients and assist with the application process on their behalf.

| # | Function / Feature                | Description                                                                                                                                              | Tier       |
| - | --------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------- |
| 1 | Consultancy Management            | Add and manage consulting companies and their associated client relationships.                                                                           | ✓ Standard |
| 2 | Authorised Email Management       | Define which email addresses within a consultancy are permitted to create and submit applications on behalf of clients.                                  | ✓ Standard |
| 3 | Consultant Portal Access          | Consultants log in via a dedicated portal using their authorised email, create applications, share them with clients, and submit completed applications. | ✓ Standard |
| 4 | Application Volume Tracking       | Track and view the number of applications submitted by each consultancy partner.                                                                         | ✓ Standard |
| 5 | Activate / Deactivate Consultants | Enable or disable individual consultant access at any time.                                                                                              | ✓ Standard |

<br>

### Module 7 — Clients

#### Client CRM

Complete client relationship management with full audit history, billing, contracts, certificates, and contact records.

| # | Function / Feature             | Description                                                                                           | Tier       |
| - | ------------------------------ | ----------------------------------------------------------------------------------------------------- | ---------- |
| 1 | Client Profile & History       | Full client profile with all audit orders, history, and linked certification cycle information.       | ✓ Standard |
| 2 | Billing & Financial Records    | Billing information, payment history, and financial documents accessible per client.                  | ✓ Standard |
| 3 | Contract & Document Repository | All contracts, quotes, and generated audit documents linked to and accessible from the client record. | ✓ Standard |
| 4 | Certificate Overview           | View all issued certificates per client with validity periods and associated audit records.           | ✓ Standard |
| 5 | Contact Management             | Manage multiple contacts per client organisation with roles and contact details.                      | ✓ Standard |

<br>

### Module 8 — Analytics

#### Business Intelligence & Performance Monitoring

Business intelligence and performance monitoring across the certification body's operations.

| # | Function / Feature                  | Description                                                                                                  | Tier       |
| - | ----------------------------------- | ------------------------------------------------------------------------------------------------------------ | ---------- |
| 1 | Audit Volume & Activity             | Monitor audit activity over time with lifetime and monthly views. Track open, ongoing, and completed audits. | ✓ Standard |
| 2 | Standards & Certification Analytics | Breakdown of audits by ISO standard, certification type, and scheme.                                         | ✓ Standard |
| 3 | Revenue & Financial Analytics       | Revenue tracking, billing summaries, and financial performance indicators.                                   | ✓ Standard |
| 4 | Conversion Analytics                | Sales funnel analysis from application submissions through to signed contracts and completed certifications. | ✓ Standard |
| 5 | Efficiency Metrics                  | Operational efficiency indicators including audit duration, planning time, and document turnaround.          | ✓ Standard |
| 6 | Consultancy Analytics               | Track and compare referral and application volumes per consultancy partner.                                  | ✓ Standard |

<br>

### Module 9 — Configuration: Organisation Profile

#### Branding, Signatories & Operational Defaults

Central settings for the certification body's identity, branding, and operational defaults.

| # | Function / Feature        | Description                                                                                                 | Tier       |
| - | ------------------------- | ----------------------------------------------------------------------------------------------------------- | ---------- |
| 1 | Organisational Details    | Company name, registration details, address, and official organisational information.                       | ✓ Standard |
| 2 | Branding & Whitelabelling | Upload logos and configure brand colours used across client-facing portals, documents, and communications.  | ✓ Standard |
| 3 | Authorised Signatories    | Register authorised signatories and their signature images for use on contracts, reports, and certificates. | ✓ Standard |
| 4 | Operational Defaults      | Configure default currency, time zones, support contacts, and system-wide defaults.                         | ✓ Standard |

<br>

### Module 10 — Configuration: ISO Standards & Rates

#### Standard Portfolio & Fee Management

Manage the portfolio of offered certification standards and all associated financial and accreditation settings.

| # | Function / Feature       | Description                                                                                                                            | Tier       |
| - | ------------------------ | -------------------------------------------------------------------------------------------------------------------------------------- | ---------- |
| 1 | Standard Management      | Add, activate, and deactivate ISO standards. Active standards are selectable in the client application form.                           | ✓ Standard |
| 2 | Audit Type Configuration | Define which audit types are available per standard: initial certification, surveillance, recertification, transfer audit, and others. | ✓ Standard |
| 3 | Fee & Rate Configuration | Set audit day fees, registration fees, and default or promotional discounts per standard and currency.                                 | ✓ Standard |
| 4 | Auditor Payment Rates    | Define payment rates by auditor role: Lead Auditor, Auditor, Technical Expert, and others.                                             | ✓ Standard |
| 5 | Accreditation Details    | Store accreditation numbers, validity dates, accreditation body links, and related documentation per standard.                         | ✓ Standard |

<br>

### Module 11 — Configuration: Audit Plan Templates

#### Session Structure & Effort Allocation

Define the structure and time allocation for audit sessions by ISO standard to enable automated plan generation.

| # | Function / Feature              | Description                                                                                                                                                            | Tier       |
| - | ------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------- |
| 1 | Session Template Builder        | Define audit sessions per ISO standard (e.g. opening meeting, HR review, access control review) with associated clauses, controls, and story-point effort allocations. | ✓ Standard |
| 2 | Fixed & Scaled Sessions         | Set sessions to a fixed duration or scaled proportionally to total audit days using story points.                                                                      | ✓ Standard |
| 3 | Multiple Templates per Standard | Create multiple plan templates per ISO standard selectable during audit planning.                                                                                      | ✓ Standard |

<br>

### Module 12 — Configuration: Execution Configuration

#### Rating Scales, Clause Guidance & AI Training

Customise the audit execution environment: rating scales, clause-level guidance, and AI assistant configuration.

| # | Function / Feature             | Description                                                                                                                                                                 | Tier       |
| - | ------------------------------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------- |
| 1 | Custom Rating Scale            | Define the conformity rating scale used during execution (e.g. conformity, minor nonconformity, major nonconformity, opportunity for improvement) per standard or globally. | ✓ Standard |
| 2 | Clause & Control Configuration | For each clause and control, configure expected evidence, key questions, audit phase mapping, and rating criteria.                                                          | ✓ Standard |
| 3 | AI Assistant Configuration     | Clause-level expectations and evidence requirements feed directly into the AI assistant to enable automated evidence analysis and rating suggestions.                       | ⬡ AI       |

<br>

### Module 13 — Configuration: User Management

#### Roles, Permissions & User Lifecycle

Manage internal team users, roles, permissions, and access across the ISO OS platform.

| # | Function / Feature                 | Description                                                                                                     | Tier       |
| - | ---------------------------------- | --------------------------------------------------------------------------------------------------------------- | ---------- |
| 1 | Role Management                    | Create custom roles with granular permission assignments across modules, sub-modules, and individual functions. | ✓ Standard |
| 2 | Default Role Templates             | Load pre-configured permission sets as a starting point. Fully editable by the certification body.              | ✓ Standard |
| 3 | Role-Based Access Control (RBAC)   | Assign one or more roles to each user to govern their access across the platform.                               | ✓ Standard |
| 4 | Discretionary Access Control (DAC) | Override or fully customise permissions at the individual user level, independent of assigned roles.            | ✓ Standard |
| 5 | User Invitation & Onboarding       | Invite users by email. Users activate via invitation link and complete profile setup.                           | ✓ Standard |
| 6 | User Lifecycle Management          | Activate, deactivate, and reactivate users. Resend invitations. Reset passwords.                                | ✓ Standard |
| 7 | User Activity Logs                 | Full activity log per user with timestamps, IP addresses, and action records. Exportable as CSV.                | ✓ Standard |

<br>

### Module 14 — Security & Platform

#### Authentication, Encryption & Data Residency

Platform-wide security controls and authentication mechanisms.

| # | Function / Feature              | Description                                                                                           | Tier       |
| - | ------------------------------- | ----------------------------------------------------------------------------------------------------- | ---------- |
| 1 | Two-Factor Authentication (2FA) | All users authenticate with password plus a one-time password (OTP) delivered by email.               | ✓ Standard |
| 2 | Automatic Session Expiry        | Users are automatically logged out after inactivity or when access is detected from a new IP address. | ✓ Standard |
| 3 | Data Encryption                 | All data encrypted in transit and at rest using industry-standard protocols.                          | ✓ Standard |
| 4 | EU Data Residency               | Data stored within the European Union to support GDPR and data sovereignty requirements.              | ✓ Standard |
| 5 | Comprehensive Audit Logs        | Platform-wide action logging for oversight, compliance, and security monitoring.                      | ✓ Standard |

<br>

## Advanced Modules

Advanced modules are optional add-ons. Inclusion in the contract is subject to separate agreement and pricing. AI-tagged functions require the Advanced tier.

### Advanced Module A1 — AI Readiness Check

#### Pre-Audit Document Gap Analysis

Pre-audit AI agent that reviews all uploaded client documents and flags missing or insufficient evidence before fieldwork begins.

| # | Function / Feature    | Description                                                                                                                           | Tier |
| - | --------------------- | ------------------------------------------------------------------------------------------------------------------------------------- | ---- |
| 1 | Document Gap Analysis | Automatically scans all uploaded documents against required evidence and policies per standard. Flags missing items.                  | ⬡ AI |
| 2 | Readiness Report      | Generates a structured readiness summary with identified gaps, enabling the certification body to notify the client before the audit. | ⬡ AI |

<br>

### Advanced Module A2 — AI Auditor Guidance

#### AI Auditor Assistant & Evidence Analysis

AI assistant embedded in the audit execution interface to accelerate evidence review, question generation, and finding suggestions.

| # | Function / Feature            | Description                                                                                                                 | Tier |
| - | ----------------------------- | --------------------------------------------------------------------------------------------------------------------------- | ---- |
| 1 | Evidence Extraction & Tagging | Processes all uploaded documents and automatically tags relevant content to corresponding clauses and controls.             | ⬡ AI |
| 2 | Suggested Audit Questions     | Generates targeted audit questions per clause and control based on identified evidence gaps.                                | ⬡ AI |
| 3 | Automated Finding Suggestions | Suggests conformity ratings and findings per clause and control based on evidence analysis against configured expectations. | ⬡ AI |

<br>

### Advanced Module A3 — Phishing Simulator

#### Security Awareness Training

Built-in phishing simulation tool to run security awareness training exercises for clients.

| # | Function / Feature           | Description                                                                                                     | Tier       |
| - | ---------------------------- | --------------------------------------------------------------------------------------------------------------- | ---------- |
| 1 | Phishing Campaign Management | Design and launch phishing simulation campaigns targeting client employees to test security awareness.          | ★ Advanced |
| 2 | Results & Reporting          | Track click rates, reporting rates, and employee behaviour. Generate reports for awareness training programmes. | ★ Advanced |

<br>

### Advanced Module A4 — KYC / KYB Services

#### Identity & Business Verification

Integrated Know Your Customer and Know Your Business verification services.

| # | Function / Feature          | Description                                                                                            | Tier       |
| - | --------------------------- | ------------------------------------------------------------------------------------------------------ | ---------- |
| 1 | Identity Verification (KYC) | Digital identity verification for individual contacts, integrated into the client onboarding workflow. | ★ Advanced |
| 2 | Business Verification (KYB) | Corporate entity verification to confirm legitimacy and ownership structure of client organisations.   | ★ Advanced |

<br>

### Advanced Module A5 — Blockchain Certificate Publishing

#### Immutable, Publicly Verifiable Certification Records

Publish issued ISO certificates to the blockchain for immutable, publicly verifiable proof of certification.

| # | Function / Feature          | Description                                                                                    | Tier       |
| - | --------------------------- | ---------------------------------------------------------------------------------------------- | ---------- |
| 1 | On-Chain Certificate Record | Issue a cryptographic record of the certificate on the blockchain. Immutable and tamper-proof. | ★ Advanced |

<br>

### Advanced Module A6 — Single Sign-On (SSO)

#### Enterprise Identity Federation

Enterprise identity federation allowing users to authenticate via your organisation's existing identity provider.

| # | Function / Feature            | Description                                                                                                                  | Tier       |
| - | ----------------------------- | ---------------------------------------------------------------------------------------------------------------------------- | ---------- |
| 1 | SSO Integration (SAML / OIDC) | Connect ISO OS to your corporate identity provider (e.g. Okta, Azure AD, Google Workspace) using SAML 2.0 or OpenID Connect. | ★ Advanced |
| 2 | Automated User Provisioning   | Automatically provision and deprovision user access based on identity provider group membership.                             | ★ Advanced |

<br>

### Advanced Module A7 — Self-Hosted Deployment

#### On-Premises & Private Cloud

Deploy ISO OS on your own infrastructure for maximum data control and sovereignty.

| # | Function / Feature                     | Description                                                                                     | Tier       |
| - | -------------------------------------- | ----------------------------------------------------------------------------------------------- | ---------- |
| 1 | On-Premises / Private Cloud Deployment | Full deployment of ISO OS on the certification body's own servers or private cloud environment. | ★ Advanced |
| 2 | Dedicated Support & Maintenance        | Dedicated technical support, update management, and SLA package for self-hosted instances.      | ★ Advanced |

<br>

### Advanced Module A8 — Custom Development & Integrations

#### Bespoke Features & White-Label Configuration

Bespoke features, custom integrations, and tailored configurations developed specifically for the certification body.

| # | Function / Feature             | Description                                                                                                                  | Tier       |
| - | ------------------------------ | ---------------------------------------------------------------------------------------------------------------------------- | ---------- |
| 1 | Custom API Integrations        | Connect ISO OS to third-party systems (ERP, HRMS, billing, compliance tools) via custom API development.                     | ★ Advanced |
| 2 | Custom Document Templates      | Design and implement fully customised document templates aligned with the certification body's brand and legal requirements. | ★ Advanced |
| 3 | Custom Workflow Development    | Development of tailored workflows, approval chains, or features specific to the certification body's operational needs.      | ★ Advanced |
| 4 | Full White-Label Configuration | Custom domain, custom email domain, and removal of AuditOne branding. Full white-label deployment.                           | ★ Advanced |


# Free Tools

<table data-view="cards"><thead><tr><th align="center"></th></tr></thead><tbody><tr><td align="center"><a href="/pages/sSJSVJzObSeMGRwTgVh5"><strong>Price Calculator</strong></a></td></tr><tr><td align="center"><a href="/pages/iuvRw7xRUfDzVZkEsr2D"><strong>Security Checklist</strong></a></td></tr><tr><td align="center"><a href="/pages/MLCFZQxzXKxlxjeGJldS"><strong>EU Compliance Checker</strong></a></td></tr></tbody></table>


# EU Compliance Checker

The EU AI Compliance Checker: Navigating the AI Act

Regulatory landscapes are shifting. With the EU AI Act now in force, businesses must move beyond innovation to ensure their AI systems are legally resilient. The AuditOne EU AI Compliance Checker is a high-precision tool designed to categorize your AI projects within the EU’s risk-based framework, identifying whether your system is classified as Minimal, Limited, High-Risk, or Prohibited.

#### From Risk to Readiness

Our checker doesn't just identify risks; it provides a roadmap for market entry. By evaluating your system’s architecture and intended use, the tool identifies critical gaps in:

* High-Risk Classification: Determining if your project falls under Annex III (e.g., finance, healthcare, or HR) and requires a formal conformity assessment.
* Transparency Obligations: Ensuring users are informed of AI interactions and that synthetic content is correctly labeled.
* Governance Standards: Mapping your project against requirements for human oversight, data quality, and technical documentation.

#### Why Compliance is Non-Negotiable

For AI systems operating in sensitive sectors, non-compliance is a significant business risk. Our tool integrates with your AI-native ISO OS workflow to streamline the generation of the mandatory technical documentation and logs required by EU regulators. Utilizing this checker ensures your business is positioned to lead in the EU market with systems that are not only advanced but demonstrably trustworthy and compliant.

Launch the EU Compliance Checker [here](https://eu-ai-compliance.auditone.io/).&#x20;


# Security Checklist (Web3)

The Security Checklist aims to assess and evaluate the security measures implemented across different phases of a project, particularly in the Web3 ecosystem. The checklist aims to:

**Evaluate Security Practices:** Gather key information about the project's development, pre-deployment, and post-deployment phases. Identify whether best practices are implemented, such as static analyzers, multisig wallets, or hardware wallets.

**Measure Security Readiness:** Calculate the overall security preparedness by assigning scores to various phases based on the answers provided. Provide an overall security percentage score (e.g., 95%) reflecting the project is well-secured.

**Identify Gaps:** Highlight areas needing improvement, such as whether penetration testing or bug bounty programs have been conducted. Encourage proactive security measures such as incident management and on-chain monitoring.

**Provide Security Guidance:** Offer actionable insights through resources like the "CTO's Guide to Web3 Security" to strengthen the project's security posture.

In essence, the checklist is a comprehensive tool to ensure Web3 projects are resilient against potential threats while promoting best practices in security management.

You can try the Security Checklist [here](https://services.auditone.io/security-checklist).<br>


# Price Calculator (Web3)

The AuditOne Price Calculator Get an instant, tailored estimate for your smart contract audit. By inputting key project metrics such as repository size (SLOC), coding language, and project phase. Our tool generates a detailed cost breakdown specific to your security needs.

[Try the Price Calculator](https://www.google.com/search?q=Link)<br>


# Services

<table data-view="cards"><thead><tr><th align="center"></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td align="center"><a href="https://www.auditone.io/iso-os"><strong>ISO OS</strong></a></td><td></td></tr><tr><td align="center"><a href="/pages/H8Y3nEfJPy2YDQGWPv7p"><strong>Penetration Testing</strong></a></td><td></td></tr><tr><td align="center"><a href="/pages/Q2mDWkU67bU3cwfUG8mE"><strong>Smart Contract Audit</strong></a></td><td></td></tr><tr><td align="center"><a href="/pages/CQQ3YQcQP1yoTpCUjqee"><strong>Bug Bounty</strong></a></td><td></td></tr><tr><td align="center"><a href="/pages/HxrEEbAblYCZQj9Aur0E"><strong>Trust Layer for Platforms</strong></a></td><td></td></tr><tr><td align="center"><a href="/pages/uqEI8ai2sWExYQ4qfMcB"><strong>360-Degree Audit</strong></a></td><td></td></tr><tr><td align="center"><a href="/pages/VoRr6S3Uj0NOIT8wSquq"><strong>KYC/KYB</strong></a></td><td></td></tr><tr><td align="center"><a href="/pages/wBY9fR9BbRlcbi2YujKn"><strong>AI Systems Audit</strong></a></td><td></td></tr><tr><td align="center"><a href="/pages/KPRzSPsJegvGO9X67rEh"><strong>Phishing Simulator</strong> </a></td><td></td></tr></tbody></table>

<br>


# Penetration Testing

Strategic Penetration Testing

Proactive security is the cornerstone of trust. AuditOne leverages a global network of 50+ elite certified penetration testers to identify and neutralize vulnerabilities before they can be exploited. By applying the rigorous lessons of Web2 security to the frontiers of Web3 and AI, we provide a holistic defense across your entire digital surface.

#### Core Testing Specializations

Our methodology utilizes Black Box, Grey Box, and White Box testing to ensure deep coverage across all environments:

* Web & Mobile Applications: Comprehensive analysis of application logic to prevent data breaches, unauthorized access, and insecure data storage.
* Cloud & Infrastructure: Hardening corporate networks, servers, and cloud environments against misconfigurations and outdated software.
* Blockchain & Browser Extensions: Specialized security for the decentralized stack, focusing on transaction integrity and protecting users from malicious browser-based functionality.

#### The AuditOne Methodology

Powered by our AI-native ISO OS, our penetration testing workflow balances automated efficiency with deep manual expertise:

1. Expert-Led Research: We deploy independent white-hat hackers who focus on manual exploitation—the only way to catch complex, non-linear logic flaws.
2. Incentivized Excellence: Our "Base + Performance" payment model ensures testers are highly motivated to find even the most obscure vulnerabilities.
3. Institutional Reporting: Deliverables are generated through our standardized reporting tool, ensuring every report is compliant with global industry standards.

#### Elite Certification Standards

Our testers hold the industry’s most prestigious credentials, ensuring your project is handled by experts:

* Offensive Security: OSWE, OSCE, OSCP, and OSWP.
* Red Teaming: CRTO and CRTP.
* Specialized: eCXD, eCPPT, and Burp Suite Certified Practitioners.

#### General Scope: OWASP Top 10 Framework

We align our testing with the latest OWASP standards to ensure global compliance and rigorous coverage:

| **Category**              | **Focus Area**                     | **Example Risk**                         |
| ------------------------- | ---------------------------------- | ---------------------------------------- |
| Broken Access Control     | Unauthorized privilege escalation. | IDOR, bypassing access logic.            |
| Cryptographic Failures    | Exposure of sensitive data.        | Weak encryption, insecure storage.       |
| Injection                 | Untrusted data in commands.        | SQLi, NoSQL, and Command Injection.      |
| Insecure Design           | Flaws in the architecture.         | Insecure workflows, unprotected APIs.    |
| Security Misconfiguration | Hardening of environments.         | Default passwords, verbose error logs.   |
| Vulnerable Components     | Supply chain security.             | Outdated libraries, unpatched CVEs.      |
| Auth Failures             | Identity verification flaws.       | Session hijacking, brute-force.          |
| Integrity Failures        | Software/Data verification.        | Insecure updates, malicious plugins.     |
| Logging/Monitoring        | Detection capabilities.            | Lack of alerts, insufficient forensics.  |
| SSRF                      | Server-side request forgery.       | Exploiting servers to ping internal IPs. |

<br>


# Phising Simulator

The AuditOne Phishing Simulator is our cybersecurity awareness service that allows organizations to test employees and provide training in relation to phishing threats. The simulator is designed to mimic a phishing scenario to determine how an employee may interact with a phishing threat. They can then be assigned training in order to close gaps that phishing attacks exploit in an organization.

**Key features:**

* Simulate phishing situations, e.g, clone phishing, spear phishing, and more.&#x20;
* Track employees who interact with the emails (opened, clicked, ignored)&#x20;
* Detailed reporting to improve organizational security awareness.&#x20;
* Assist an organization in identifying and minimizing insider threats.

**What are the Advantages of Using the Phishing Simulator**

* Replicate phishing tactics of real-world attacks (clone phishing, credential harvesting, spear phishing)&#x20;
* Understands what an employee does when they receive a malicious email.&#x20;
* Identify the employee who consistently fails phishing attacks and offer targeted training. &#x20;
* Aids in compliance training, decreases social engineering risks by bringing awareness to potential exploits.&#x20;
* Customize content for realistic simulations (branding and company communication styles)&#x20;
* Detailed reports highlighting individuals who opened and clicked the email.<br>

{% embed url="<https://youtu.be/15WBz8Y-Psw?si=PyCPhgfgqntAA5N>\_" %}

### Onboarding Flow Explained

To start using the AuditOne Phishing Simulator, clients first need to fully complete a company data information form, which ensures the simulator is reflective of the company's branding and communication style. Company name, logo, industry, location, and company size are all required fields.&#x20;

Once we get through that setup phase, we move into creating a phishing simulation. First, users can choose the type of phishing attacks they want, simulated. Once they have the attack type set, they choose the employees that will be targeted by either uploading a contact list.&#x20;

After that is done, they move on to personalizing their phishing email. AI-generated templates allow customizing items to increase this feeling of realism.

Once the configuration is completed, users can test the simulator or launch the simulated emails, and the simulator logs behavior in real-time. The core metrics we track are the delivery status, open rates, link clicks, and repeat offenders (those who click links consistently). We provide a lot of value to security teams for identifying where awareness is apparent in user interaction.

With this information, organizations can better understand their internal risk and enhance their security culture. Lastly, organizations can use the data to inform employee education with further cybersecurity training initiatives. Organizations can improve their awareness programs, update internal security policies, and better prepare their employees against real phishing attacks.<br>


# Whitelisting Guide

To start phishing and training your users, you need to whitelist AuditOne. This ensures that our training notifications and simulated phishing security tests (PSTs) reach your users' inboxes. If you don’t whitelist our emails, your mail server or spam filter may block or filter them.

<mark style="background-color:green;">**Note:**</mark> <mark style="background-color:green;"></mark><mark style="background-color:green;">For Microsoft 365 users, we recommend Microsoft's Advanced Delivery Policies feature. Advanced Delivery bypasses some of Microsoft's security configurations and allows you to create a secure connection for phishing simulations.</mark>

### Whitelisting Best Practices

To ensure you receive our emails, follow these best practices based on your mail server and spam filter.

1. If you do not use a cloud-based spam filter, whitelist our hostnames in your mail server. See the "Whitelist Your Mail Servers" section for guidance.
2. If you have a cloud-based spam filter whitelist by hostname in your spam filter. Refer to the sections on "Whitelisting Your Mail Servers" and "Whitelisting Your Email and Web Filters" for details.

### AuditOne's Hostnames

Here is our hostname. You need this information to allow your mail server and spam filter to accept our messages.&#x20;

```
auditone.xyz
@auditone.xyz
```

### Whitelisting Your Spam Filter

Here is a list of Docs that can help you whitelist your spam filter. When you whitelist, follow the instructions in these Docs and make sure you have our [hostnames](#whitelisting-best-practices).

If you are whitelisting for web filtering on endpoints, you might need our phishing and landing domain list. To get this list, please contact AuditOne’s support team (<hello@auditone.io>).

<mark style="background-color:green;">**Note:**</mark> <mark style="background-color:green;"></mark><mark style="background-color:green;">Your spam filter may have rate limits that could slow down or block our PSTs from being delivered. We suggest you check the rate-limiting rules for your spam filter to ensure our PSTs reach your users’ inboxes.</mark>

### Whitelisting a Domain in the Google Workspace Admin Console

You can create a list of approved senders, which can include entire domains. Emails from these domains will bypass Gmail's spam filters. Here are the general steps:

1. Log in to your Google Admin console. You'll need administrator privileges to access these settings.
2. Navigate to Gmail settings. From the main menu, go to Apps > Google Workspace > Gmail.
3. Go to Spam, Phishing, and Malware. Here you will find various settings to control how emails are handled.
4. Configure "Spam" list. You will need to either create a new address list or edit an existing one to include the domain you wish to whitelist. In the spam settings, you can then choose to "Bypass spam filters for messages received from addresses or domains within these approved sender lists."

{% embed url="<https://www.loom.com/share/621c351eaa3d4524b81d05344dd41637?sid=bca72e77-8d30-4cc9-be1b-c6ae0263ba4b>" %}

### <mark style="color:blue;">Microsoft 365: Whitelist Non-Phishing Emails from AuditOne</mark>

If you're not receiving admin/system emails or employee messages from AuditOne (not training or phishing simulations), you'll need to whitelist their domains in Microsoft 365. Here's how:

1. Go to Microsoft 365 Admin Center > Exchange.
2. Navigate to Mail Flow > Rules, then click (+) to create a new rule.
3. Name the rule (e.g., Whitelist Emails from AuditOne), then click More options.
4. Set "Apply this rule if..." to "The sender's domain is...", and enter:
   1. auditone.io
   2. auditone.xyz
5. For "Do the following...", choose Modify the message properties > set the spam confidence level (SCL) to Bypass spam filtering.
6. Click Save.

### Sending a Demo Test&#x20;

After setting up the phishing criteria, it's a good idea to run a test to ensure it's working correctly.

Include only yourself or a small group of users in this test. You or the test users should confirm that you received the phishing simulation test (PST) from the campaign. Finally, have one of the users click a simulated phishing link in the PST to check that clicks are being tracked successfully.

### Avoiding Link Testing and Intent Analysis

Some spam filters, like Barracuda, Symantec, Websense, and MessageLabs, may have features that follow or inspect links. If these features are on, they might cause misleading click-through rates, possibly showing 100%.&#x20;

### Troubleshooting

If you need help, check the subsections below. If you don't find your issue, please contact AuditOne’s support team (<hello@auditone.io>).&#x20;

### Email from AuditOne Sent to Junk or Spam&#x20;

We send you emails about updates to our products, such as new features and templates. Our employees may also check in to see how things are going. To make sure you receive these emails, whitelist addresses from <hello@auditone.io>.

If you use Microsoft 365, read our Doc on [how to whitelist emails from AuditOne](#whitelist-non-phishing-emails-from-auditone).

### Third-Party Whitelisting Assistance

Our support team can help with whitelisting, but many spam filters and email providers are different. We recommend contacting your service provider for further assistance.

You can use the template below to request help from your service provider's support team:

Our organization uses AuditOne, a platform for security awareness training that includes simulated phishing tests. We want to make sure all of AuditOne’s phishing test notifications reach our employees' inboxes. Please help us with whitelisting these communications.


# Copy of Whitelisting Guide

To start phishing and training your users, you need to whitelist AuditOne. This ensures that our training notifications and simulated phishing security tests (PSTs) reach your users' inboxes. If you don’t whitelist our emails, your mail server or spam filter may block or filter them.

<mark style="background-color:green;">**Note:**</mark> <mark style="background-color:green;"></mark><mark style="background-color:green;">For Microsoft 365 users, we recommend Microsoft's Advanced Delivery Policies feature. Advanced Delivery bypasses some of Microsoft's security configurations and allows you to create a secure connection for phishing simulations.</mark>

### Whitelisting Best Practices

To ensure you receive our emails, follow these best practices based on your mail server and spam filter.

1. If you do not use a cloud-based spam filter, whitelist our hostnames in your mail server. See the "Whitelist Your Mail Servers" section for guidance.
2. If you have a cloud-based spam filter whitelist by hostname in your spam filter. Refer to the sections on "Whitelisting Your Mail Servers" and "Whitelisting Your Email and Web Filters" for details.

### AuditOne's Hostnames

Here is our hostname. You need this information to allow your mail server and spam filter to accept our messages.&#x20;

```
auditone.xyz
@auditone.xyz
```

### Whitelisting Your Mail Server&#x20;

Here is a list of Docs to help you whitelist your mail server. When will need our IP addresses, hostnames, or header information.&#x20;

<mark style="color:red;">Please contact AuditOne’s support team (<hello@auditone.io>) to whitelist IP Addresses and hostnames.</mark>&#x20;

Please note that your mail server might use rate limiting, which can slow down or block the delivery of our PSTs. We recommend checking the rate-limiting rules for your mail server to make sure our PSTs reach your users’ inboxes.

If your mail server is Microsoft 365, see the Docs listed below:

* How to Use Advanced Delivery Policies in Microsoft 365
* Need Delivery Policies in Microsoft 365
* [Exchange 2013, 2016, & Microsoft 365 (Whitelist by Email Header)](#whitelist-by-email-headers-in-microsoft-365-microsoft-exchange-2016-and-microsoft-exchange-2019)
* Whitelisting Training Notifications in Microsoft 365 (Whitelist by Email Header)
* [Configure Focused Inbox on Outlook or Microsoft 365 (PowerShell)](https://docs.microsoft.com/en-us/office365/admin/setup/configure-focused-inbox?view=o365-worldwide)

If your mail server is Google Workspace, see the Docs listed below:

* [Whitelisting by IP Address in Google Workspace](#whitelist-by-ip-address-in-google-workspace-1)
* [Whitelisting by Email Header in Google Workspace](#whitelist-by-email-headers-in-microsoft-365-microsoft-exchange-2016-and-microsoft-exchange-2019)
* [Whitelisting by Content Compliance in Google Workspace](#whitelisting-by-content-compliance-in-google-workspace-auditone)

<mark style="background-color:green;">**Important:**</mark> <mark style="background-color:green;"></mark><mark style="background-color:green;">If you use Google Workspace, make sure to turn off the return-path header in our PSTs.</mark>

### Whitelisting Your Spam Filter

Here is a list of Docs that can help you whitelist your spam filter. When you whitelist, follow the instructions in these Docs and make sure you have our [IP addresses, hostnames, or header information](#whitelisting-best-practices).

If you are whitelisting for web filtering on endpoints, you might need our phishing and landing domain list. To get this list, please contact AuditOne’s support team (<hello@auditone.io>).

<mark style="background-color:green;">**Note:**</mark> <mark style="background-color:green;"></mark><mark style="background-color:green;">Your spam filter may have rate limits that could slow down or block our PSTs from being delivered. We suggest you check the rate-limiting rules for your spam filter to ensure our PSTs reach your users’ inboxes.</mark>

### Sending a Demo Test&#x20;

After setting up the phishing criteria, it's a good idea to run a test to ensure it's working correctly.

Include only yourself or a small group of users in this test. You or the test users should confirm that you received the phishing simulation test (PST) from the campaign. Finally, have one of the users click a simulated phishing link in the PST to check that clicks are being tracked successfully.

### Additional Configurations

After you have whitelisted following our recommendations, you may need to make additional configurations. See the sections below for more information.

### Adding AuditOne to Your SPF Records&#x20;

To let AuditOne send PSTs for you, add AuditOne to your Sender Policy Framework (SPF) records.&#x20;

### Adding DKIM Signatures&#x20;

All our training notifications automatically include a DKIM (DomainKeys Identified Mail) signature.&#x20;

You can also add a DKIM signature to our PSTs. For more details, please contact AuditOne support.&#x20;

### Avoiding Link Testing and Intent Analysis

Some spam filters, like Barracuda, Symantec, Websense, and MessageLabs, may have features that follow or inspect links. If these features are on, they might cause misleading click-through rates, possibly showing 100%.&#x20;

### Troubleshooting

If you need help, check the subsections below. If you don't find your issue, please contact AuditOne’s support team (<hello@auditone.io>).&#x20;

### Email from AuditOne Sent to Junk or Spam&#x20;

We send you emails about updates to our products, such as new features and templates. Our employees may also check in to see how things are going. To make sure you receive these emails, whitelist addresses from <hello@auditone.io>.

If you use Microsoft 365, read our Doc on [how to whitelist emails from AuditOne](#whitelist-non-phishing-emails-from-auditone). If you use Google Workspace, refer to our [Doc on whitelisting by IP address](#whitelist-by-ip-address-in-google-workspace-1).

### Third-Party Whitelisting Assistance

Our support team can help with whitelisting, but many spam filters and email providers are different. We recommend contacting your service provider for further assistance.

You can use the template below to request help from your service provider's support team:

Our organization uses AuditOne, a platform for security awareness training that includes simulated phishing tests. We want to make sure all of AuditOne’s phishing test notifications reach our employees' inboxes. Please help us with whitelisting these communications.

## Support

### <mark style="color:blue;">Whitelist Non-Phishing Emails from AuditOne</mark>

If you're not receiving admin/system emails or employee messages from AuditOne (not training or phishing simulations), you'll need to whitelist their domains in Microsoft 365. Here's how:

1. Go to Microsoft 365 Admin Center > Exchange.
2. Navigate to Mail Flow > Rules, then click (+) to create a new rule.
3. Name the rule (e.g., Whitelist Emails from AuditOne), then click More options.
4. Set "Apply this rule if..." to "The sender's domain is...", and enter:
   1. AuditOne.io
5. For "Do the following...", choose Modify the message properties > set the spam confidence level (SCL) to Bypass spam filtering.
6. Click Save.

### <mark style="color:blue;">Whitelist by IP Address in Google Workspace</mark>

Due to Google’s upcoming changes, Direct Message Injection (DMI) is the preferred method for whitelisting AuditOne emails in Google Workspace. If you're not using a cloud-based spam filter, follow the steps below to whitelist by IP address:

#### Whitelist AuditOne by IP in Google Workspace:

1. Go to Admin Console > Apps > Google Workspace > Gmail.
2. Click Spam, Phishing, and Malware (under “Advanced settings” for older versions).
3. Select your domain (IP whitelisting applies to entire domains).
4. In the Email whitelist section, enter AuditOne’s IP addresses (from their Whitelisting Guide).
5. Click Save.

#### Add IPs as Inbound Gateways (to suppress Gmail banners):

1. From the same Spam, Phishing, and Malware section:
2. Add AuditOne’s IPs under Inbound Gateway.
3. Configure:&#x20;
   1. Don’t check "Reject all mail not from gateway IPs"
   2. Don’t enable "Automatically detect external IP"
      * Enable "Require TLS"
      * Add a spam header
   3. Enable "Disable Gmail spam evaluation on mail from this gateway"
4. Click Save (it may take \~1 hour to propagate).

### <mark style="color:blue;">Update Your Microsoft 365 Permissions</mark>

To create, modify, or remove settings in an advanced delivery policy, you’ll need to be a member of the Security Administrator role group in the Microsoft Security & Compliance Center and the Organization Management role group in Microsoft Exchange Online.

For read-only access to an advanced delivery policy, you’ll need to be a member of the Global Reader or Security Reader role groups.

### <mark style="color:blue;">Whitelist by Email Headers in Microsoft 365, Microsoft Exchange 2016, and Microsoft Exchange 2019</mark>

Note: As of April 2023, Microsoft no longer supports Exchange 2013. For more information, see the [Exchange 2013 end-of-support roadmap](https://learn.microsoft.com/en-us/exchange/troubleshoot/administration/exchange-2013-end-of-support) document from Microsoft.

In this Doc, you'll learn how to whitelist by email header in Microsoft 365, Exchange 2016, and Exchange 2019. This method ensures your Phishing Security Tests (PSTs) bypass your spam filters and reach your users’ inboxes.&#x20;

<mark style="background-color:green;">**Note:**</mark> <mark style="background-color:green;"></mark><mark style="background-color:green;">We typically recommend whitelisting by IP address or hostname. However, if you use Exchange or Microsoft 365 without Defender for Office 365, you may need to whitelist by email headers to ensure PSTs are delivered.</mark>&#x20;

If you don't have a spam filter, Microsoft requires that you use advanced delivery policies to ensure email delivery.&#x20;

### <mark style="color:blue;">Whitelist by IP Address in Google Workspace</mark>

In this Doc, you can learn how to whitelist AuditOne emails by IP address in Google Workspace. Whitelisting can help you ensure that your users receive our simulated phishing tests and training notifications.

<mark style="background-color:green;">**Important:**</mark> <mark style="background-color:green;"></mark><mark style="background-color:green;">To ensure that your user opens are being tracked properly, you may need to add our phish link domains to your Google Workspaces.</mark>&#x20;

We only recommend whitelisting by IP address if you don't have a cloud-based spam filter. If you have a cloud-based spam filter, we recommend whitelisting by email header instead.  For more information, see our Whitelisting by Header in Google Workspace or Whitelisting Guide Docs.

<mark style="background-color:green;">**Note:**</mark> <mark style="background-color:green;"></mark><mark style="background-color:green;">This Doc contains our recommendations for whitelisting in Google Workspace, but Google Workspace may make changes to its features at any time. If you’re experiencing issues with whitelisting by using the instructions below, please contact our support team (<hello@auditone.io>).</mark>

### <mark style="color:blue;">Add AuditOne’s IP Addresses to the Email Whitelist</mark>

To whitelist our IP addresses, you'll need to add our IP addresses to your email whitelist in Google Workspace.

To add our IP addresses to your email whitelist, follow the steps below.

* Log in to your Google Workspace Admin console and click Apps > Google Workspace > Gmail
* Click Spam, Phishing, and Malware.\
  Note: If you use an older version of Google Workspace, you may need to click the Advanced Settings button to see this option.
* In the Organizational Unit section of the page, select your domain.\
  Note: Google Workspace only allows whitelisting by IP address for an entire domain, so you're unable to whitelist by IP Address for individual organizational units (OUs).
* In the Email whitelist section, enter our IP addresses separated by commas.&#x20;
* Click Save.

### <mark style="color:blue;">Add AuditOne IP Addresses as Inbound Gateways</mark>

When your users receive a simulated phishing email from AuditOne, banners may display in Gmail to say, "This message seems dangerous" or "Be careful with this message". To prevent these banners from displaying, we recommend that add our IP addresses as inbound gateways. <br>

To add our IP addresses as inbound gateways, follow the steps below:

Important: While we've found that these steps help to prevent Google banners from displaying, these steps aren't documented as a whitelisting recommendation by Google.

* Log in to your Google Workspace Admin console.
* Section above. These steps will take you to your Spam, Phishing, and Malware settings.
* Configure the Inbound gateway.

Fill out your information to match the screenshot below:

* IP addresses/ranges: Enter AuditOne's IP addresses.&#x20;
* Ensure the Reject all mail not from gateway IPs check box isn't selected.  \ <mark style="background-color:green;">**Note:**</mark> <mark style="background-color:green;"></mark><mark style="background-color:green;">The automatically detected external IP setting may interfere with whitelisting for AuditOne. Unless you use other IP addresses that require you to enable this setting, we recommend that you don't select the Automatically detect external IP check box. For more information, see Google's</mark> [<mark style="background-color:green;">Set up an inbound mail gateway</mark>](https://support.google.com/a/answer/60730?hl=en#zippy=%2Cexample-how-gmail-determines-the-source-ip%2Cstep-enter-gateway-ip-addresses-and-options) <mark style="background-color:green;">Doc.</mark>
* Select the Require TLS for connections from the email gateways listed above check box.
* Select the Message that is considered spam if the following header regexp matches the check box. Then, enter a spam header tag that is unlikely to be found in a Phishing Security Test email. For example, you could enter random letters such as "kzndsfgklinjvsdnfioasm".
* Select the Disable Gmail spam evaluation on mail from this gateway; only use the header value check box.
* Click Save. This setting may take up to an hour to deploy to all of your users.

<mark style="background-color:green;">**Note:**</mark> <mark style="background-color:green;"></mark><mark style="background-color:green;">Before creating simulated phishing tests, you should also disable the return-path header in your KSAT Account Settings.</mark>

### <mark style="color:blue;">Whitelisting by Email Header in Google Workspace (AuditOne)</mark>

* **Recommended Method:** Use Direct Message Injection (DMI) due to upcoming Gmail changes.
* **Purpose:** Allows AuditOne's phishing test emails to bypass spam filters by matching a custom email header.
* **Steps:**
  * Go to Google Admin > Apps > Google Workspace > Gmail > Compliance.
  * Under Content Compliance, add a new rule.
  * Target Inbound and Internal - receiving emails.
  * Match emails with the header: X-PHISHTEST (or your custom one).
  * Set rule to Bypass spam filter.
  * Save the rule.
* **Additional Setup:**
  * Add AuditOne’s phish link domains to Google’s Image URL proxy allowlist.
  * Use this method only if you have a cloud-based spam filter. Otherwise, whitelist by IP address instead.
  * Disable the return-path header in AuditOne account settings before tests.
  * Run a test campaign to confirm setup; allow up to 1 hour for changes to apply.
* Need help? Reach out to AuditOne support if issues arise.

### <mark style="color:blue;">Whitelisting by Content Compliance in Google Workspace (AuditOne)</mark>

* Recommended: Use Direct Message Injection (DMI) due to upcoming Gmail changes.
* Purpose: Bypass spam filters to deliver AuditOne phishing simulations via IP and header-based content rules.

#### Two-Step Whitelisting Process:

1\. Add AuditOne’s IP Addresses to Google Workspace:

* Go to Google Admin > Apps > Google Workspace > Gmail > Spam, Phishing, and Malware.
* Under your entire domain (not sub-OUs), add AuditOne IPs to the Email Whitelist.
* Separate IPs with commas.<br>

2\. Create Content Compliance Rule:

* Go to Google Admin > Apps > Google Workspace > Gmail > Compliance.
* Add a rule under Content Compliance:
  * Affect: Inbound messages.
  * Expressions:
    * Source IP match (add each AuditOne IP).
    * Header match: Full headers contain X-PHISHTEST.
* Actions:
  * Bypass spam filter
  * Require TLS encryption

#### Notes:

* This only applies to full domains (not individual OUs).
* Disable the return-path header in KSAT settings before phishing tests.
* Run a test campaign to verify the setup.
* Issues? Contact AuditOne support.

\
\
\ <br>


# Smart Contract Audit

The AuditOne Auditor Hub: Elite Expertise, Standardized Excellence

The AuditOne Auditor Hub is a premier ecosystem connecting projects with top-tier smart contract security experts. Every audit is powered by a decentralized network of audit pools, where specialized teams of 3–4 verified auditors collaborate to ensure no vulnerability goes unnoticed. Our selection process is rigorous: every professional must pass mandatory KYC protocols and clear the AuditOne Skill Exam, a benchmark that guarantees only the top echelon of security talent enters our network.

To ensure consistency and clarity, AuditOne utilizes a standardized audit reporting tool. This proprietary interface streamlines the documentation process, allowing auditors to transform complex technical findings into actionable, comprehensive security reports. By combining human ingenuity with standardized, AI-enhanced reporting, we provide clients with a clear roadmap to a secure deployment.

[Learn how we define the new standards for security services.](/what-makes-us-different)


# AI Systems Audit

AuditOne's AI System Audit is a comprehensive evaluation designed to enhance trust, bolster brand reputation, and ensure regulatory compliance for AI startups.

**Key Benefits:**

* **Enhance Stakeholder Trust:** Audits build customer confidence by increasing transparency in AI operations, enabling greater reliance on AI solutions.
* **Increase Brand Reputation:** Addressing biases through audits demonstrates a commitment to ethical AI, elevating your brand's image.
* **Stay Ahead of Regulations:** In a dynamic regulatory environment, audits help maintain compliance, minimizing risks and potential obstacles.

**AuditOne's STARED Framework:**

AuditOne employs the **STARED** framework, focusing on:

* **S**ecurity
* **T**echnical Assessment
* **R**egulatory Compliance
* **E**thics
* **D**ata Governance

This holistic approach ensures a thorough evaluation of AI systems.

**You can read bout AuditOne's AI Systems in our** [**Litepaper**](https://docsend.com/view/j5kac3ey7yp78wzz)**.**

<br>


# 360-Degree Audit

AuditOne comprehensively reviews the company’s operations, financials, and technology. It provides an in-depth analysis of the company’s current prospects and potential risks associated with the venture.

Our 360 Degree Audit provides a comprehensive assessment tailored to the blockchain industry, covering business analysis (reviews business objectives, scalability, GitHub activity, codebase, funding, and documentation), team analysis (evaluates team skills, structure, advisors, income, and leadership in marketing and development), tokenomics audit (uses proprietary tools to analyze token allocation, vesting periods, distribution, trading volume, and supply strategy), marketing and social media performance (assesses community engagement, platform moderation, social media growth, and content quality across various channels).&#x20;

Clients can opt for a full audit or select specific areas, and our report clearly details what was audited.

<br>


# KYC

Project and user KYC

Our KYC service ensures that the team behind a project is legitimate and trustworthy. We use a combination of automated and manual processes to verify the identity of the team members. This includes verifying their identity documents, such as passports and driver's licenses, and conducting background checks.

At AuditOne, we understand the importance of trust and security in blockchain. Our KYC service assures customers that a legitimate and trustworthy team manages their projects.

#### KYC Process

1. Visit the AuditOne Services platform to [request a KYC at AuditOne Services](https://services.auditone.io/kyc).
2. Pay for the service.
3. Follow the verification.
4. Once verified, you will receive our soulbound NFT with the KYC verification.

<div><figure><img src="/files/4rNJeBQn6W2kfxmW4gKw" alt=""><figcaption></figcaption></figure> <figure><img src="/files/KPIsnQnf8Wx8x6UueMpd" alt=""><figcaption></figcaption></figure></div>


# Bug Bounty

We also offer bug bounty programs to any projects interested in hosting it on our website. Additionally, we provide bug bounties to projects after completing a smart contract audit, demonstrating our commitment to the ongoing security of smart contracts. We allocate 20% of the audit cost towards the bug bounty program, which projects can increase to attract more auditors.

Currently there are over 1,000+  verified auditors on AuditOne's platform. This large talent pool enables AuditOne to conduct Bug bounties on our platform.

The bounty's size and conditions are entirely up to your project team, with larger bounties increasing the likelihood of hackers reporting issues.<br>

**What do we need from you to launch a Bug Bounty?**

* Scope
* Size
* Conditions
* A signed agreement (which you can request from us via <hello@auditone.io>)


# Trust Layer for Platforms

Our primary purpose is to build trust and to make sure that people are not scammed or affected by smart contract hacks.

Integrating the trust layer on platforms as a service from AudiOne involves a comprehensive suite of services that ensure the security and integrity of the smart contracts. It includes security audit, a comprehensive security audit of the smart contract code, and 360 degree audit Due Diligence, which provides a comprehensive assessment covering business analysis, team analysis, tokenomics audit, and marketing and social media performance. KYC (Know Your Customer) is a process of verifying the customer's identity.

Our integration is automated with API. After a user has completed a verification process, we will update you on the user's status. Usually, our partners add a field to a project profile where all security badges are displayed. For every user that uses our services, you earn a 5% cut on our commission.

#### Services Offered Through Trust Layer

* Security Audit
* KYC
* 360-degree Audit
* Pen-testing

<figure><img src="/files/hbIui0mGfC2Ll21yJy1l" alt=""><figcaption><p>Schematics of how Trust Layer integration works</p></figcaption></figure>

#### Example of Trust Layer integration

{% embed url="<https://youtu.be/Dyd7iSnhGyg?si=1X9qfNiaSr8u-Erk>" %}
KYC Verification
{% endembed %}


# On-chain Agent: The Audit Oracle

The Trust Layer for Agents & Degens

To make Web3 verifiable, auditable, and accountable, the Audit Oracle establishes a universal trust layer for the agent to agent economy. Humans can interact with our agent via the AuditOne terminal for secure trading, portfolio mgt., news & analytics.

**User Interface**: \
<https://agent.auditone.io/>

**Agent on Virtuals:** <https://app.virtuals.io/prototypes/0xb17a7581c9A006E8B5fDA85506cFD3448ed75746><br>

Trading is powered by [Near Intents](https://docs.near-intents.org/near-intents).

The following tokens are currently supported for **trading** (E.g.: "Trade X ETH on Base for BTC on Bitcoin with Bitcoin receiver address Y"):

<table><thead><tr><th width="99.625">Symbol</th><th width="696.1640625">Chains</th></tr></thead><tbody><tr><td>ETH</td><td>Base, Ethereum, Optimism, Arbitrum, Near</td></tr><tr><td>wETH</td><td>Gnosis</td></tr><tr><td>BTC </td><td>Bitcoin</td></tr><tr><td>wBTC</td><td>Ethereum, Near</td></tr><tr><td>cbBTC</td><td>Base</td></tr><tr><td>USDC</td><td>Base, Ethereum, Optimism, Arbitrum, Near</td></tr><tr><td>USDT</td><td>Ethereum, Near, Solana, Optimism, Arbitrum, Tron, Avalanche, Polygon, BSC, Gnosis</td></tr><tr><td>EURe</td><td>Gnosis</td></tr></tbody></table>

Note: Make sure to mention always the right destination address where you want to get your funds transferred to. E.g.: Native Bitcoin requires a Bitcoin address, USDC on Base or Ethereum an EVM compatible address and so on. We cannot recover lost funds.

**Other actions to execute via the agent terminal:**\
Security & Audit Details: Provides you with security and audit details of a token\
Analyze my Portfolio: Assesses the tokens in your portfolio\
Overall Analysis: A general assessment of a token\
Market Metrics:  Market specific stats for a token\
Trending Tokens: Tokens trending based on recent activity\
Recent Activity: Recent news from X displayed

<br>


# $AUDIT Tokenomics

$AUDIT Relaunch through Virtuals\
<https://app.virtuals.io/prototypes/0xb17a7581c9A006E8B5fDA85506cFD3448ed75746>\
\
Key Features: \
• Know Your Agent (KYA / KYB / KYC) \
• Credit system: $AUDIT is used as credit for all agent & chat interactions: <https://agent.auditone.io/> \
• Trust Oracle Reputation Scoring & Due Diligence of Projects: <https://www.coinintel.xyz/>

Furthermore, all utilities from The old $AUDIT token (on IOTA EVM) will be transitioned to the Virtuals $AUDIT token. Please find here more information: <https://www.auditone.io/blog-posts/audit-token-utilities-features>\
\ <br>


# How to bridge AUDIT tokens between the IOTA and BASE networks

How to bridge AUDIT tokens from the IOTA network to the BASE network, follow these steps:

**Step 1:** Access the AuditOne Services Page and select [Bridge AUDIT Token](https://services.auditone.io/).

**Step 2:** AuditOne provides a bidirectional bridge, allowing AUDIT tokens to move between the BASE and IOTA networks.

**Step 3:** Ensure your wallet is connected to the correct network and verify that you have a sufficient balance of AUDIT tokens. If needed, you can obtain AUDIT tokens [here](https://app.magicsea.finance/liquidityv2/manual/:8822/add/0xba7ac526ee9d29209baedccb67c6d3a228644982?showTop=true).\
\
*AUDIT Token Address (On IOTA) : 0x159366809b6062960c97BC4eDd548BAFCd7812D8*\
*AUDIT Token Address (On Base) : 0xd449f79df0397840371dc51c9b48b755d8b2ec58*&#x20;

**Step 4:** Choose IOTA as the source network or BASE as the destination. Enter the amount you want to bridge. Follow the on-screen instructions to approve the token transfer and confirm the transaction in your wallet.

**Step 5:** Use the bridging platform's interface or a [LayerZero ](https://layerzeroscan.com/)blockchain explorer to monitor the status of your transfer. Once the transfer is confirmed, the AUDIT tokens will appear in your BASE network wallet.


# How to lock AUDIT tokens

**Step 1: Get AUDIT Tokens**

* Purchase AUDIT tokens from [MagicSea](https://app.magicsea.finance/fairlaunch/:8822/audit).

**Step 2: Lock AUDIT Tokens**

1. Visit the [Audit One Services ](https://services.auditone.io/)website.
2. Navigate to the Lock AUDIT Token option.
3. Select Client as your role.
4. Connect your wallet to the platform.
5. Select the option to lock your tokens.
6. Ensure the minimum lock amount of 4000 AUDIT tokens is met.
7. Submit and confirm the transaction to lock your tokens.

**Step 3: Check Locked Token Status**

1. Select Client as your role and connect your wallet.
2. Choose the option to check the status.
3. View details like:
   1. Staked amount
   2. Discount rate
   3. Date since locked

**Step 4: Unlock Tokens**

* Normal Withdrawal:
  * Withdraw without penalties after the lock period is complete.
  * Full funds are returned to your wallet.
* Emergency Withdrawal:
  * Withdraw before the lock period ends with a 50% penalty.
  * Confirm and execute the withdrawal process.


# For Clients

<figure><img src="/files/1AHCD2ZuUkuNbLjLRfJC" alt=""><figcaption><p>Audit Process</p></figcaption></figure>

\ <br>


# Preparation & Pricing

What is the process?

**What a project can expect once they request an audit.**&#x20;

1. **Day 1:** You request a service using this form [here](https://www.auditone.io/), including high-level details of your project. After submitting  the form and requesting the audit, we can will review your codebase and prepare a quote for the services.
2. **Day 2:** AuditOne organizes a meeting within 48 hours to clarify any unclear details about the project based on their quote request form. You can utilize our[ price calculator](https://publictools.auditone.io/pricecalculator) to get an estimate for an audit.&#x20;
3. **Day 3:** A deposit of 60% is required before the audit can start. Then an audit pool is created based on auditors' availability and experience level. Next, a discord channel is made for auditors and project to communicate freely.&#x20;
4. **Day 4:** Auditors and projects meet in a kickoff meeting, and the lead auditors are selected here.&#x20;
5. **Day 5-7:** The audit starts with four auditors, and all work independently. Once the audit is complete, they will receive a base payment and added bounties per finding.
6. **Day 19-21:** Cross-Validation of all findings with the four auditors and one independent reviewer. A preliminary report is drafted. The AuditOne team and all the auditors meet to discuss the finding, and the project is given time to improve the codebase. Moreover, the project has two weeks from receipt of the preliminary report to make the final payments.
7. **Day 28-X:**  Finally, auditors reviewed and acknowledged the updates as fixed/resolved. If no high-severity issues are found, projects will pay less.
8. **End:** Receiving the final audit report from AuditOne.&#x20;

**Note:**&#x20;

**Refund policy:** Before the audit can start, a deposit of 50% of the audit fees is needed. The audit will begin 3 days after the payment is received. If the audit is canceled, AuditOne will not refund the deposit, and the auditors must be paid for their time. If you cancel before the audit starts, you will get a refund of 50%.

#### Audit Pricing and Time

<table data-header-hidden><thead><tr><th width="166"></th><th align="center"></th><th align="center"></th><th align="center"></th><th align="center"></th></tr></thead><tbody><tr><td><strong>nSLOC</strong></td><td align="center">1,000</td><td align="center">3,000</td><td align="center">5,000</td><td align="center">10,000</td></tr><tr><td><strong>Solidity Pricing</strong></td><td align="center">≈ $7,000</td><td align="center">≈ $21,000</td><td align="center">≈ $45,000</td><td align="center">≈ $100,000</td></tr><tr><td><strong>Rust Pricing</strong></td><td align="center">≈ $14,000</td><td align="center">≈ $42,000</td><td align="center">≈ $90,000</td><td align="center">≈ $220,000</td></tr><tr><td><strong>Audit Duration</strong></td><td align="center">2 weeks</td><td align="center">4 weeks</td><td align="center">6 weeks</td><td align="center">10-12 weeks</td></tr></tbody></table>

**Note:** The prices provided are estimates based on SLOC and may vary depending on the complexity of each individual case. If you need an audit for programming languages not listed, please share the details, and we’ll accommodate your request.\
\ <br>


# Before the audit

Audit Readiness & Integration

#### Preparing for a Successful Engagement

To ensure the highest level of security and efficiency, AuditOne requires projects to reach a "Code Freeze" state before the audit begins. Auditing an evolving codebase is counterproductive, as new commits can introduce vulnerabilities into previously validated segments.

Our Readiness Standards:

* Finalized Codebase: All development must be completed or the final commit hash provided.
* Code Freeze: No further changes should be made during the active audit period.
* Test Coverage: We expect protocols to have comprehensive test suites in place to validate core functionalities.

We offer full flexibility during this preparation phase; no deposit is required to reserve your auditing window. If your team is uncertain about the specific scope or architecture requiring review, our lead auditors will provide strategic guidance during the Project Kickoff Meeting.

[Deep Dive: How to Prepare for a Successful Audit](https://www.auditone.io/blog-posts/how-to-prepare-for-a-successful-smart-contract-audit)

#### Collaborative Communication via Discord

Transparency and real-time communication are central to our methodology. Upon payment of the deposit, we establish a dedicated, secure AuditOne Discord Channel to bridge the gap between your developers and our auditor pools.

This direct line of communication facilitates:

* Rapid Clarification: Auditors can query logic directly, reducing the time spent on false positives.
* Technical Knowledge Transfer: Your developers gain insights into security best practices through a healthy back-and-forth.
* Agile Remediation: Receive immediate feedback during the fix phase to ensure vulnerabilities are correctly mitigated.

<br>

\ <br>


# Post-Audit Continuity: Sustaining Security

Follow-up reviews

Security is an iterative process, not a one-time milestone. As protocols evolve, even minor updates can introduce new attack vectors. At AuditOne, we advocate for Continuous Security Monitoring to ensure that your project remains resilient against emerging threats and maintains alignment with evolving regulatory standards.

#### When to Request a Follow-up Audit

We recommend a formal re-audit under the following circumstances:

* Codebase Iterations: Whenever significant logic is updated or new features are deployed following the initial audit.
* Bi-Annual Reviews: To maintain institutional trust and compliance (e.g., DORA), we recommend a comprehensive security review every six months.
* Post-Exploit Analysis: In the event of a market-wide vulnerability trend, a targeted review of existing infrastructure is advised.

<br>

<br>


# For Auditors

Join and work at AuditOne.

This document outlines how AuditOne operates and how auditors and security researchers can join the platform to earn income.

#### About AuditOne

AuditOne is an auditor aggregator & bug bounty platform that provides security services and tools to ensure the safety and reliability of smart contracts and AI systems. AuditOne utilizes a decentralized pool of pre-vetted auditors and researchers for efficient resource allocation and expertise matching, benefiting both auditors/researchers and clients. We look forward to welcoming you to our community!

1. **Where do I register?**

   Auditors can register to join the AuditOne community here: <https://app.auditone.io/>&#x20;

   Please provide a detailed description of your professional background, relevant skills, and experience.

2. **How do I become eligible for an audit?**

   **KYC:** Complete the KYC (Know Your Customer) verification process as instructed during the application. Your identity is kept private, but clients want to know that their auditors have been thoroughly vetted.

   <mark style="color:blue;">The Know Your Customer (KYC) process takes approximately 5 min and will be reflected in the app.</mark>

   **Pass Exam:** Prospective auditors must complete one of two AuditOne verification exams (Solidity or Rust) to demonstrate their skill level to AuditOne and potential clients.&#x20;

   <mark style="color:blue;">Exam results will be processed within 2 weeks.</mark>

   You will be eligible to participate in an audit after completing KYC and passing one of the exams.

3. **When and how are auditors notified of new audit listings?**

   **Availability:** Auditors must set their availability in the AuditOne dashboard to receive notifications for upcoming audits. Verified auditors are notified of upcoming audits based on availability and relevant **experience**.

   **Notification:** You will receive notifications through the AuditOne app, Discord, and email when a new audit matches your expertise. Please carefully review the project details and scope.

4. **How does the selection process work?**

   **Apply:** If you are interested, please submit your application for the specific project you are qualified for and would like to audit.

   **Selection:** We meticulously select auditors based on their relevant experience and skills, ensuring they match the project requirements, availability, prior performance, previous audit quality, and workload capacity.

5. **What are the compensations?**

   Auditors at AuditOne are not paid a fixed salary. Instead, after completing an audit, they are rewarded based on their XP levels, the severity of the issues discovered, and bug bounties.

   Earning XP can help auditors acquire $AUDIT Tokens and increase their salaries. The XP program measures an auditor's experience, and as their XP rises, so do their levels and opportunities to participate in more audits.

6. **How do I get paid?**

   Complete the invoice information before completing an audit, and AuditOne will generate the invoice within the app and pay it to your desired account.

<br>


# Auditor Levels and Rewards

Path of an auditor

Auditors gain experience points (XP) by completing their profile, sharing their professional experience and skills, completing KYC and AuditOne’s verification exam, and more. Once registered on our platform, an auditor is assigned level 0. Each rank requires more XP to level up, and XP does not reset after reaching the next level:

### The Auditor Level Journey: A Howl Through the Ranks

In the thrilling ecosystem of AuditOne, auditors take on the guise of skillful wolves, each more powerful and savvy than the last. The wolf NFTs represent different auditor levels, marking auditors with symbols of status, expertise, and cunning. Let's embark on an adventure to understand what each auditor-wolf level entails and the quests needed to advance to the next stage.

{% tabs %}
{% tab title="Starter" %}

#### Level 0 - The Lone Pup (Starter)

<figure><img src="/files/PITM49l8sr0oe7tcX048" alt="" width="188"><figcaption><p>Lone Pup NFT</p></figcaption></figure>

**Skills and Achievements:**

At this level, you're a Lone Pup just entering the wilderness of auditing. Your skills are fledgling, but you have an insatiable curiosity and a basic understanding of the auditing landscape. You've just joined the pack, and the world of auditing awaits your exploration.

**Quest to Next Level:**

To evolve into a Security Researcher, you'll need **400 XP**. To achieve this milestone:

* Complete your profile for a fast **60 XP**;&#x20;
* Complete KYC and show us your skills by completing our Rust/Solidity exam for **100 XP** each; voila, you've leveled up!
* Next, an audit must be completed, and issues must be identified to reach the XP threshold of 400 XP. The points for each type of issue are as follows:

  * High-severity issues: 100 XP each
  * Medium-severity issues: 50 XP each
  * Low-severity issues: 10 XP each

  Any combination of these issues can total 400 XP, earning you enough points to progress to the next level.
  {% endtab %}

{% tab title="Security Researcher" %}

#### Level 1 - The Security Howler (Security Researcher)

<figure><img src="/files/hRoLJQnpjEblfmi9PEbx" alt="" width="188"><figcaption><p>Security Howler NFT</p></figcaption></figure>

**Skills and Achievements:**

As a Security Howler (>400 XP), you've let out your first howls in the field of security research. You are familiar with basic security protocols and can conduct rudimentary audits. You're not just following the pack now but contributing to its safety.

**Quest to Next Level:**

To ascend to the realm of the Auditor Expert, you must accumulate a total of **1,000 XP**. Consider these quests:

* Complete **2 audits** with AuditOne **(800 XP)**.
  * Find **two high** issues during an audit and earn **100 XP** each.
  * Find **four medium** issues during an audit and earn **50 XP** each.
    {% endtab %}

{% tab title="Auditor Expert" %}

#### Level 2 - The Silver Pathfinder (Auditor Expert)

<figure><img src="/files/km3zyer6xjLTlMiGr03x" alt="" width="188"><figcaption><p>Silver Pathfinder NFT</p></figcaption></figure>

**Skills and Achievements:**

As a Silver Pathfinder (>1,000 XP), you demonstrate exceptional agility and proficiency in navigating the complexities of the auditing wilderness. Your strong grasp of various auditing tools and methods has led to your success and enabled you to guide sub-packs on quests to secure the digital realm.

**Quest to Next Level:**

Your eyes are set on becoming an Auditor Master, requiring **5,000 XP**. If starting from Level 2:

* Complete 5+ audits as a lead auditor with AuditOne
* Find high, medium, and low issues.
  {% endtab %}

{% tab title="Auditor Master" %}

#### Level 3 - The Moon Whisperer (Auditor Master)

<figure><img src="/files/TQB3MDgrHKkfl6h9BiEC" alt="" width="188"><figcaption><p>Moon Whisperer NFT</p></figcaption></figure>

**Skills and Achievements:**

Ah, the Moon Whisperer (>5,000 XP)! You're at one with the mysteries of the auditing universe, achieving mastery over complex techniques. You howl, and the pack listens, following you as you lead high-stakes missions.

**Quest to Next Level:**

Ready to become the god-like Auditor Deus? You'll need a grand total of **25,000 XP**. Starting from Level 3:

* Complete 30+ audits as a lead auditor with AuditOne.
* Find 40+ high issues during these audits.
* Finding a **medium and low** issue during an audit.

**Note:** If an auditor with Auditor Master or Auditor Deus status doesn't perform an audit within 90 days, their level drops one tier, and their XP adjusts to the highest point of the new level.
{% endtab %}

{% tab title="Auditor Deus" %}

#### Level 4 - The Alpha of Alphas (Auditor Deus)

<figure><img src="/files/lCMGcXJ6EzYEacNSaYXH" alt="" width="188"><figcaption><p>Alpha of Alphas NFT</p></figcaption></figure>

**Skills and Achievements:**

You are the Alpha of Alphas, the Auditor Deus (>25,000 XP). Your howl resonates in every corner of the auditing realm. You're a thought leader, an expert so skilled that your techniques become the gold audit standard. You're not just leading the pack; you're defining its future.

**Note:** If an auditor with Auditor Master or Auditor Deus status doesn't perform an audit within 90 days, their level drops one tier, and their XP adjusts to the highest point of the new level.
{% endtab %}
{% endtabs %}

#### How much XP is awarded for each task?

<table data-header-hidden><thead><tr><th width="525"></th><th></th></tr></thead><tbody><tr><td>Professional Experience and Skills:</td><td><strong>25 XP</strong></td></tr><tr><td>Basic information: </td><td><strong>25 XP</strong></td></tr><tr><td>KYC: </td><td><strong>100 XP</strong></td></tr><tr><td>Rust/Solidity verification exam: </td><td><strong>100 XP</strong></td></tr><tr><td>Audit completed outside AuditOne with submitted report:</td><td><strong>10 - 15 XP per audit</strong></td></tr><tr><td>Professional Certification:</td><td><strong>15 XP</strong></td></tr><tr><td>Audit completed with AuditOne:</td><td><strong>400 XP per audit</strong></td></tr><tr><td>Finding a high issue during an AuditOne audit or Bug Bounty:</td><td><strong>100 XP</strong></td></tr><tr><td>Finding a medium issue during an AuditOne audit or Bug Bounty: </td><td><strong>50 XP</strong></td></tr><tr><td>Finding a low issue/QA during an AuditOne audit or Bug Bounty:</td><td><strong>10 XP</strong></td></tr><tr><td>Completing courses on our education platform:</td><td><strong>10 XP per course</strong></td></tr></tbody></table>

Our platform will have an auditor leaderboard indicating the top 10 auditors by level & findings. Once our token economy launches, auditors will be rewarded with an $AUDIT equivalent (also for the XP that has already been obtained).


# Audit Process

### **Auditing Phase:**

* Auditors will have a private repository on GitHub in collaboration with AuditOne, where they can create issues based on the templates provided by AuditOne for the audited projects. These issues will not be visible to the project team or any other members of the audit pool.
* After the audit period, auditors must move any issues to the private audit review repository created by AuditOne, where all auditors and AuditOne are initially collaborators.

### **Review Phase:**

### **Stage 1: Peer Review (For Auditors)**

* The review repository will have all the issues found by the auditors participating in the audit.
* Every auditor is supposed to go through the issues found by other auditors and
  * Use 👍 if you agree with the finding.
  * Comment your argument if you do not agree with the findings; use the '**duplicate**' label if you find a similar issue to what you have identified, and comment on the issue number you are referring to.
* The duration of the peer review phase varies depending on the codebase size. Check the timeline for more details on each phase duration.

### **Stage 2: Review by the Project Team**

* The Project team will review the issues found by auditors once added as a collaborator to review the repository.
* The project team will use the issue labels –
  * '**Acknowledged**' – If you accept the issue.
  * '**Will fix'** – If you want to resolve the issue.
  * '**Resolved**' – If you have resolved the issue.
  * '**Question**' – If you disagree with the finding and need further information, comment on the points where the finding is unclear, mentioning the issue owner.
  * '**Invalid**' – If you find the issue invalid, comment on the reason, mentioning the issue owner.
* During this phase, auditors and the project team will use labels and comments to discuss the audit findings, and the project team will have time to fix the issues.
* This phase lasts for two weeks (10 working days) after phase 1 ends, i.e., from when the project team is added as a collaborator to review the repository.

### **Stage 3: Review by Issue Owner (For Auditors)**

* Issue owners should review the issues after the project team has fixed or acknowledged them and update the status to **'validated by issue owner**.'
* Once the validation is done, you can use the '**include in report**' label.

### **Important Note:**

* Base payment: Usually, the base payment is paid to every participating auditor. However, if the valid issues of an individual do not sum up to at least 20% of the total issues (excluding QAs), AuditOne will decide on a case by case study if and to what extent the individual receives a base payment.
* Mandatory Peer Review: All auditors must participate in peer reviews within their pool. Clearly indicate if you agree or provide your opinion on why you think an issue is invalid or uncertain. Failure to conduct peer reviews properly will result in a 20% deduction from the total payment.
* Inflationary Reporting: If the number of invalid issues submitted by an auditor exceeds the valid ones, or if the indicated severity is significantly inaccurate, a 25% deduction will be applied to the total payment.


# Audit Contest Process

### **Pre-Contest Phase:**

* Auditors can express their interest in the audit contest through the app.
* AuditOne will create a private GitHub repository individually for each interested auditor within 24 hours, equipped with an issue template and labels for contributing to the audit contest.
* Note: Auditors with a repository can start contributing to issues in existing repositories.
* Only the AuditOne audit team and the respective auditor can access the private repository. AuditOne will provide a link to the repository within the app.

### **Contest Phase:**

* During the contest period, auditors work individually within their private repositories to identify and document vulnerabilities. They must use the provided issue template and labels to categorize vulnerabilities based on severity.

### **Post-Contest Phase:**

* After the contest period ends, all the documented issues are transferred to a central review repository.
* Judges at AuditOne evaluate these issues to determine their validity and severity.
* After the issues have been reviewed, the project team is given access and time to resolve them.
* Bounties will be paid out for all validated issues. AuditOne will process bounty payments in the weeks after the audit contest concludes.
* Auditors participating in the Aurora bug bounty must provide an **AURORA address** to receive their bounty payments, which will be in USD equivalent based on the exchange rate on the transfer day. For all other bounties, auditors can provide any **EVM-compatible wallet address** for their payments.


# Auditor Pooling

AuditOne allows auditors to join a pool from Level 1 and above, with the size of the pool depending on the complexity and length of the code. Generally, a pool has 3-4 auditors. The pool is manually created with at least one auditor at Level 4, one at Level 3, and two auditors below Level 3. The criteria for selection include the auditor's level, availability, skill set, and prior experience with the project type.


# GitHub Tracking

**Just before the Audit begins**

1. The Auditor pool will be given access to the repo as collaborators if it is private, or the project will provide a link if it is public.&#x20;
2. AuditOne checks if all pool auditors have a private repo. Else creates one for them.

**During audit**

1. Auditors will have a private repository on GitHub in collaboration with AuditOne, where they can create issues based on the templates provided by AuditOne for their auditing projects. These issues will not be visible to the project team or any other members of the audit pool.
2. After the audit period, auditors must move any issues to the private project repository created by AuditOne, in which all auditors and AuditOne are initially collaborators. A meeting with our head of security and triage will be held to finalize the issues and their severity.
3. The Project team is invited to collaborate and provide feedback on the findings discussed in the meeting. They can express their disagreement with any of the issues raised or accept them to resolve them before the final report is submitted.

**After audit**

1. AuditOne will check the issues finalized and issue a final report.&#x20;


# Compensation

The compensation for auditors is based on the payment received by a project, which ultimately depends on the codebase's size, complexity, and programming language.

For example, we assume a project is quoted 17,500€ for 2,500 nSLOC.

**13,125€ (75%)** of the payment is allocated to the auditors. **4,375€ (25%)** is allocated to the treasury of AuditOne (used for operations, development, marketing, and sales).

**3,937.50** € (30%) of the payment is the base salary for the auditors.

**9,187.50** € (70%) will be used as bounty distributed as follows:

Payment structure can be tailored to each clients specific needs and preferences, ensuring flexibility and accommodating their unique requirements:<br>

| Category                     | Amount    | %   |
| ---------------------------- | --------- | --- |
| High (& Critical) issues pot | 5,512.5€  | 0.6 |
| Medium issues pot            | 2,756.25€ | 0.3 |
| Low issues / QA pot          | 918.75€   | 0.1 |

The bounties will be awarded and split between all the auditors that find high/medium/low issues. If we assume that the following issues were identified and validated: 1 H, 3 M, and 8 L.\
The auditor who found 1 H, 1 M, and 1 L would receive the following:<br>

| Type                           | Amount   |
| ------------------------------ | -------- |
| Base payment                   | 1,312.5€ |
| High (& Critical) issue bounty | 5,512.5€ |
| Medium issue bounty            | 909.5€   |
| Low issue bounty               | 115€     |
| **Total payment**              | 7849.5€  |

**Key takeaways:**

• The Auditors gain most of the revenue as opposed to working for an audit firm.&#x20;

• More auditors look through the code compared to traditional audit firms.

• The project pays less for an audit if no issues are found for specific severity bounties.

• The Auditors are rewarded for finding issues while receiving a base income.&#x20;

<br>


# Severity Classification

<table data-full-width="true"><thead><tr><th width="160">Severity Level</th><th>Impact</th></tr></thead><tbody><tr><td>Critical</td><td><p>- Network not able to confirm new transactions (total network shutdown)</p><p>- Unintended permanent chain split requiring hard fork (network partition requiring hard fork)</p><p>- Direct loss of funds</p><p>- Permanent freezing of funds (fix requires hard fork)</p><p>- Manipulation of governance voting results deviating from the voted outcome and resulting in a direct change from the intended effect of original results</p><p>- Direct theft of any user funds, whether at rest or in-motion, other than unclaimed yield</p><p>- Direct theft of any user NFTs, whether at-rest or in motion, other than unclaimed royalties</p><p>- Permanent freezing of NFTs</p><p>- Unauthorized minting of NFTs</p><p>- Predictable or manipulable RNG that results in abuse of the principal or NFT</p><p>- Unintended alteration of what the NFT represents (e.g. token URI, payload, artistic content)</p><p>- Protocol insolvency</p></td></tr><tr><td>High</td><td><p>- Unintended chain split (network partition)</p><p>- Temporary freezing of network transactions by delaying one block by 500% or more of the average block time of the preceding 24 hours beyond standard difficulty adjustments</p><p>- Causing network processing nodes to process transactions from the mempool beyond set parameters</p><p>- RPC API crash affecting projects with greater than or equal to 25% of the market capitalization on top of the respective layer</p><p>- Theft of unclaimed yield</p><p>- Theft of unclaimed royalties</p><p>- Permanent freezing of unclaimed yield</p><p>- Permanent freezing of unclaimed royalties</p><p>- Temporary freezing of funds</p><p>- Temporary freezing of NFTs</p><p>- Complete bypass of transaction fees or gas costs, resulting in free or heavily discounted transactions</p><p>- Cross-chain attacks causing disruption or instability in interconnected blockchains or networks</p><p>- Exploitable weaknesses in decentralized governance mechanisms, resulting in unfair voting outcomes or manipulation of governance decisions</p></td></tr><tr><td>Medium</td><td><p>- Increasing network processing node resource consumption by at least 30% without brute force actions, compared to the preceding 24 hours</p><p>- Shutdown of greater than or equal to 30% of network processing nodes without brute force actions, but does not shut down the network</p><p>- A bug in the respective layer 0/1/2 network code that results in unintended smart contract behavior with no concrete funds at direct risk</p><p>- Smart contract unable to operate due to lack of token funds</p><p>- Block stuffing</p><p>- Griefing (e.g. no profit motive for an attacker, but damage to the users or the protocol)</p><p>- Theft of gas</p><p>- Unbounded gas consumption</p><p>- Excessive transaction fees due to a bug or miscalculation in the fee calculation mechanism</p><p>- Vulnerabilities in smart contract logic or tokenomics resulting in suboptimal user experiences or inefficiencies</p></td></tr><tr><td>Low</td><td><p>- Shutdown of greater than 10% or equal to but less than 30% of network processing nodes without brute force actions but does not shut down the network</p><p>- Modification of transaction fees outside of design parameters</p><p>- Contract fails to deliver promised returns but doesn't lose value</p><p>- Low-risk issues related to documentation, code comments, or code style that do not directly affect security or functionality</p><p>- Minor inconsistencies in calculations within the smart contract that do not affect critical operations</p></td></tr></tbody></table>

Note: For our audits we include 'critical' issues within the classification 'high' issues.&#x20;


# Community

Community Points (CP):

AuditOne is excited to distribute community points to those participating in our ecosystem and help spread the word about AuditOne. Once our tokens have been launched, you can convert these community points into $AUDIT tokens. Here is a breakdown of the distribution of community points.

**Quest/Daily Quest**&#x20;

* Re-tweet - 15 CP
* Like - 10 CP
* Subscription - 20 CP

**Quiz**

* Participation - 40 CP
* Getting into weekly Top 5 Score - 60 CP
* Getting into monthly Top 3 Score - 150 CP

**Memes Contest**

* Meme creation - 40 CP
* Winning Challenge - 100 CP

**CTF Challenge**

* Participation - 40 CP
* Getting into Top 3 Score - 100 CP
* Winning - 150 CP


# Ambassadors program


# Write an Article -1000 $AUDIT

1. The text should be unique and not plagiarized, not written with AI.
2. The article should contain 1000 words minimum.
3. The article should be well structured: introduction, main part, and conclusion; the main part should have subheadings.
4. The article can be published on your own website, Medium, Mirror, and other resources but contain 1-2 do-follow links to any relevant pages of the AuditOne website.

\
**Good to have:**

* References to the sources you use for it, if applicable
* Illustrations
* If you use any bullet points, do not use more than 4 in one paragraph

**The number of articles:**

*You can submit no more than 2 articles/per month.*<br>

**USEFUL LINKS:**\
\
Logo - <https://rb.gy/9h7dj4>\
Litepaper - <https://docsend.com/view/myxikr4dx2wduwnh>\
Docs - <https://docs.auditone.io/>

**Please submit the link to your publication using this form. Also, provide your EVM wallet address:**

[ ](https://forms.gle/cQ6SZRAr8SoKRa6x6)<https://forms.gle/cQ6SZRAr8SoKRa6x6>

*<mark style="color:red;">\*The team reserves the right not to give an award if the content seems inappropriate to us.</mark>*<br>


# Create Instagram Reels | YouTube Shorts | TitTok - 200 $AUDIT/video

1. The vertical video duration must be 30-60 sec.&#x20;
2. The video should be unique and contain useful or fun content to promote AuditOne.
3. The description must contain a link to the AuditOne website. In Instagram, "auditone.io" should be mentioned in the Reels description.

\
**The number of videos:**\
*You can submit no more than 4 videos per month.*

**USEFUL LINKS:**\
\
Logo - <https://rb.gy/9h7dj4>\
Litepaper - <https://docsend.com/view/myxikr4dx2wduwnh>\
Docs - <https://docs.auditone.io/>

**Please submit the link to your post using this form. Also, provide your EVM wallet address:**

[h](https://forms.gle/sd89Wm7CWSq7acnT6)<https://forms.gle/cQ6SZRAr8SoKRa6x6>

*<mark style="color:red;">\*The team reserves the right not to give an award if the content seems inappropriate to us.</mark>*<br>


# Create Twitter | Instagram | Facebook | Threads | Reddit Post - 200 $AUDIT/Post

1. Each next publication should be unique and related to AuditOne.
2. The publication can contain an illustration such as a picture or a video created by yourself or AuditOne.
3. The text must contain a link to the AuditOne website, or "auditone.io" should be mentioned in the text in case of Instagram or Threads.
4. Re-posts and re-tweets won't we considered as unique publications.

**The number of posts:**

*You can submit no more than 4 posts per month.*<br>

**USEFUL LINKS:**\
\
Logo - <https://rb.gy/9h7dj4>\
Litepaper - <https://docsend.com/view/myxikr4dx2wduwnh>\
Docs - <https://docs.auditone.io/>

**Please submit the link to your video using this form. Also, provide your EVM wallet address:**

<https://forms.gle/cQ6SZRAr8SoKRa6x6>

*<mark style="color:red;">\*The team reserves the right not to give an award if the content seems inappropriate to us.</mark>*<br>


# Create Youtube Horizontal Video - 200 $AUDIT/Video

1. This format may fit you if you own your own channel and regularly make highly professional content, such as reviews and tutorials.
2. The video should be not less than 4 minutes long.
3. The content shouldn't be plagiarized, and every next video should be unique.<br>

**The number of videos:**\
You can submit no more than 4 videos per month.<br>

**Where to find inspiration?**

* AuditOne’s new App's interface contains a lot of new features to describe
* Participated in Quizzes or CTF challenges? Tell about your unique experience with AuditOne.
* Actively trading and staking $AUDIT? Tell about your experience.&#x20;
* The $AUDIT token utilities and benefits are a huge piece of content to find the right topic.

**Which format to select?**

It can be a Tutorial or Guide or Review; It can be either fun or serious as you wish.<br>

**USEFUL LINKS:**\
\
Logo - <https://rb.gy/9h7dj4>\
Litepaper - <https://docsend.com/view/myxikr4dx2wduwnh>\
Docs - <https://docs.auditone.io/>

**Please submit the link to your post using this form. Also, provide your EVM wallet address:**

<https://forms.gle/cQ6SZRAr8SoKRa6x6>

*<mark style="color:red;">\*The team reserves the right not to give an award if the content seems inappropriate to us.</mark>*<br>


# The all-in-one audit platform

<table data-view="cards"><thead><tr><th align="center"></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td align="center"><a href="/pages/LzchaMQrtnt5d79Hr8Jq"><strong>Academy</strong></a></td><td></td></tr><tr><td align="center"><a href="/pages/MrYmbEy7lj2XIpaf2cbL"><strong>Audit Tools</strong></a></td><td></td></tr><tr><td align="center"><a href="/pages/FQrbXJJAQCY3l3Y9MFSu"><strong>Auditors</strong></a></td><td></td></tr><tr><td align="center"><a href="/pages/AGbm7MegKZk4AlLeRek3"><strong>Bug Bounty</strong></a></td><td><a href="/pages/fi0YT6hHFRoSw5oBdax5">/pages/fi0YT6hHFRoSw5oBdax5</a></td></tr></tbody></table>


# Academy

AuditOne Academy is where auditors can learn about our various tools to make auditing more efficient. AuditOne rewards learners with **10 XP** for completing each course. Senior auditors can collaborate with the AuditOne team to conduct workshops or develop courses.


# Tools

We offer free tools to help you pre-analyze your smart contracts and evaluate AI systems for compliance with the EU AI Act. These tools enable you to assess smart contract security and ensure your AI systems align with EU regulations.

* Static Analyzers
* Audit Assistant
  * [Validate AI Findings](/platform/auditors/validate-ai-findings)
* Code Visualizer
* EU Compliance Checker
* Report Generator (Coming Soon)

**You can access the tools at** <https://app.auditone.io/tools>.

We also offer:

* [**Price Calculator**](https://services.auditone.io/price-calculator)**:** Estimates the cost of a smart contract audit based on various project parameters.
* [**Security Checklist**](https://services.auditone.io/security-checklist)**:** Evaluate your project's security posture by analyzing key aspects across development, pre-deployment, and post-deployment phases.


# Auditors

Our auditors must complete KYC and an onboarding exam in Solidity or Rust. After submitting the tests, our senior smart contract auditors analyze the findings to determine whether the applicant is approved or rejected. Onboarding auditors in this manner ensures a minimum degree of security expertise. We have currently onboarded over 900+ auditors. Our top auditors are featured on a leaderboard here.&#x20;

Because we have a wide pool of auditors to pull from, this large supply reduces project waiting time before an audit can begin.

<br>

<br>


# Join & work at AuditOne

<table><thead><tr><th width="221">Process</th><th>Details</th></tr></thead><tbody><tr><td>Where to Register</td><td><a href="https://app.auditone.io/">Register here</a>. Provide a detailed description of your professional background, skills, and experience.</td></tr><tr><td>Eligibility Requirements</td><td><p><strong>KYC:</strong> Complete the KYC verification 5 minutes.</p><p><strong>Exam:</strong> Pass one of two exams (Solidity or Rust). Results in 2 weeks.</p></td></tr><tr><td>Notification of Audits</td><td><p><strong>Set Availability:</strong> Indicate availability in the dashboard.</p><p><strong>Notifications:</strong> Receive through app, Discord, and email.</p></td></tr><tr><td>Selection Process</td><td><p><strong>Apply:</strong> Submit an application for projects.</p><p><strong>Selection:</strong> Based on experience, skills, availability, previous performance, and capacity.</p></td></tr><tr><td>Compensation</td><td>A fixed and performance based compensation. Rewards are based on XP levels, issue severity, and bug bounties. Earn $AUDIT Tokens and increase your salary with XP.</td></tr><tr><td>Payment Process</td><td>Complete invoice info before the audit. The invoice will be generated in-app and paid to your desired account.</td></tr></tbody></table>


# Validate AI Findings

## Compensation System

We have designed our system in a way that promotes the accuracy of validations. Participants evaluate AI-generated issues over a one-month period with performance-based rewards.

### Evaluation Process

1. 100 AI findings are uploaded for review every month
2. Each finding is initially labeled by 3 validators; if they have full agreement (3/3), the validation is accepted, and the finding is labeled and removed from the evaluation. If the validators don’t agree on the validity of the finding, the finding is disputed.
3. Disputed findings receive 2 more evaluations. In the case of a 4/5 agreement, the finding is accepted, labeled, and removed from the evaluation. If there is no such agreement, the review is escalated to the Head of Security of AuditOne who reviews it and labels it.
4. Senior Auditor from AuditOne checks a random sample of findings for accuracy calculations.

### Performance & Payment

Auditors are evaluated based on Senior Auditor labels. Payments are in stablecoin at month-end.&#x20;

* Base Pay: $2 per labeled finding.
* Total Pay = Base Pay + Accuracy Bonus.

| Accuracy | Bonus/Finding                 |
| -------- | ----------------------------- |
| ≥ 90%    | $1.50                         |
| 80–90%   | $0.70                         |
| 70–80%   | $0.30                         |
| < 70%    | No base payment and no reward |

Example:\
You labeled 100 findings; 17 spot-checked, 15 matched → 88% accuracy (Tier 2) → \*$270 earned ($200 base + $70 bonus).

**Start validating finding here:** <https://app.auditone.io/tools/validate-findings>&#x20;

<br>


# Bug Bounty

Auditors will compete to identify vulnerabilities during an audit, with a portion of the project's initial fees funding the prize. If no major issues are detected, projects will not be required to pay the prize; however, if issues are detected, the total audit charge will be higher as the project must include the reward in the final payment.


# General rules and regulations

for hackers

**General rules:**

* The program may be canceled at any time, and awards are at the sole discretion of the bug bounty panel.
* Participants must not be on any sanctions lists or reside in countries on sanctions lists (e.g., North Korea, Iran, etc.).
* Proof of identity is required due to local laws.
* Participants are responsible for any applicable taxes.
* All awards are subject to applicable law.
* Participants must adhere to the reporting guidelines provided.

**Eligibility for Rewards:**

* Issues without a Proof of Concept (POC) are not eligible for bounty rewards.
* Duplicate reports of the same vulnerability are not eligible for additional rewards.
* Publicly disclosing a vulnerability before it's resolved makes it ineligible for a bounty.
* The vulnerability report should not be related to activities that violate the service's terms of service or any laws.

**Vulnerability Submission:**

* One report per vulnerability&#x20;
* The first report for a specific vulnerability is accepted.
* Reports for vulnerabilities already known are not accepted.
* Reports submitted for vulnerabilities explicitly listed as out of scope are not accepted.
* If a chain security vulnerability is detected using multiple security vulnerabilities, separate reporting is allowed.
* Higher rewards are paid for clear, well-written submissions.
* A Proof of Concept (POC) must be included to be eligible for rewards. Please include test code, scripts, and detailed instructions. The easier we can reproduce and verify the vulnerability, the higher the reward.
* Include a clear description of how to fix the issue.
* Vulnerability reports should be submitted through the designated channels.

**Testing Guidelines:**

* Testing must not violate any law or compromise any data that the participant does not own.
* Participants should not access or modify other users' data during testing and should only use accounts under their control.
* Vulnerabilities allowing access to user data should be reported responsibly, without unauthorized access.
* Testing should be limited to verifying the presence and impact of the vulnerability.

**Prohibited Actions:**

* Social engineering methods (e.g., phishing, vishing, smishing) and physical attacks (e.g., computer theft, SIM card copying) are strictly prohibited.
* Denial of Service (DoS) attacks must not be attempted.
* Any actions that could compromise the integrity or availability of our system

**Submission Requirements:**

* Reports must be submitted in English.
* All details about the vulnerability must be shared, and a Proof of Concept (PoC) must be provided.
* If multiple vulnerabilities are discovered, researchers should submit separate reports for each distinct issue.


# Bug Bounty Q\&A

The following questions will help you understand our service offering. If you cannot find an answer to your question, please contact us at hello\@auditone.io.

### **Background Information.**    &#x20;

<details>

<summary>Please can you share an overview of you and your bug bounty program?</summary>

AuditOne is a decentralized community of 400+ white hat hackers/auditors who would be offered a bounty for identified bugs/vulnerabilities.

</details>

### **Bounty Location**

<details>

<summary>Please can you share the URL where the bounties will be posted?</summary>

<https://www.auditone.io/bug-bounty>&#x20;

</details>

### **Coverage & Scope**

<details>

<summary>Please can you detail what kind of coverage, scope, bugs, or potential exploits you think we should include as an L1/L2? Do you have detailed definitions for these that we could use?</summary>

\- Stealing or loss of funds

\- Unauthorized transaction

\- Transaction manipulation

\- Price manipulation

\- Fee payment bypass

\- Balance manipulation

\- Contracts execution flows

\- Consensus flaws

\- Peer-to-peer network flaws

\- Cryptographic flaws

</details>

### **Recommended Bounties**

<details>

<summary>Please could you outline your recommendation on how we would structure the bounties? E.g. how are severities defined, and how do we define which bugs deserve what level of payout?</summary>

We usually advise that a critical bug bounty should be up to 10% of the TVL (as all could be stolen/controlled in this case).

Low issues could be just a few k while medium could be something in the range of 5-20k.

</details>

### **Commercials**

<details>

<summary>Is there an upfront fee? </summary>

No.

</details>

<details>

<summary>Any ongoing maintenance fees?</summary>

No.

</details>

<details>

<summary>Any fees for % of bounties paid out?</summary>

Only a 5% fee on payout (and paid by the auditor from the bug bounty reward). No other fees.

</details>

### **Bug Validation, Reporting & Screening**

<details>

<summary>What’s the process for validating whether a bug is real and/or true?</summary>

We screen them initially. If they are no spam, alerts will be sent to assigned devs on your side. We can also assess and triage them, but this would cost on a monthly base TBD.

</details>

<details>

<summary>Can you please describe how bugs would be reported to us and/or screened by you (if relevant)?</summary>

We screen them initially. If they are no spam, alerts will be sent to assigned devs on your side. We can also assess and triage them, but this would cost on a monthly base TBD.

</details>

<details>

<summary>What happens in case a highly critical / zero day/crisis level bug is discovered and requires urgent attention? Do you have resources in place to quickly escalate this and report this to us for swift resolution?</summary>

We exchange personal contact details with lead devs. Furthermore, we have real-time alert systems in place for email & TG contact.

</details>

<details>

<summary>How are reports kept confidential so they cannot be exploited by others?</summary>

We have a proper user management system in our app, and we can share reports only within trusted systems.

</details>

### **Legal & Arbitration**

<details>

<summary>Please can you describe the process for how the bug bounty program would be legally structured?</summary>

For the beginning it just on paper and you will pay them directly.

</details>

<details>

<summary>What if there’s a dispute? How would this work?</summary>

In terms of arbitration, there will be a committee of 5 members, 2 from AuditOne, 2 from your team, and 1 from Kleros.io.&#x20;

</details>

<details>

<summary>Where is your entity domiciled that we would engage with?</summary>

Germany.

</details>

<details>

<summary>How do you structure things legally with the white hat hackers?</summary>

They agree to the T\&C on our platform.

</details>

### **Payouts**

<details>

<summary>Can you describe how payouts would be handled?</summary>

It could be paid to an escrow at AuditOne or by you.

</details>

<details>

<summary>Is this in USD and/or stablecoin? Would it be in tokens rebased to USD value?</summary>

The most attractive way to offer bounties is by using stable-coins. It is also fine to use tokens according to pre-defined USD values.

</details>

<details>

<summary>Do you require any funds to be placed in escrow?</summary>

We are developing coverage and escrow pools that can or will be used at a later stage. For now this is not required.

</details>

<details>

<summary>Do you pay the bounty or do we? If so, how is KYC handled?</summary>

We do KYC with the auditors / bounty hunters. How the payment process is handled, can be customized to your needs.

</details>

### **Ecosystem, Reach & Credentials**

<details>

<summary>Please can you describe your ecosystem? E.g., how many active white hat hackers do you have? How experienced are they?</summary>

More than 380 auditors (300+ proficient in Solidity, 50+ proficient in Rust, many pen-testers or from traditional security backgrounds).

</details>

<details>

<summary>How many bounties have you posted and/or paid out in the past? What’s the monetary value of this?</summary>

We are in discussions with a few others, but it takes some time to agree on terms. Our bug bounty feature was just recently developed, and legal contracts were drafted. It is your chance to be one of the first bounties, and therefore, outstanding will be much easier.

</details>

### **Differentiation**

<details>

<summary>How do you differentiate from the other bug bounty providers?</summary>

Decentralized, real-time alerts to the communication channels of your choice, largest auditor community.

</details>


# Code of Conduct

for white hat hackers

The AuditOne Bug Bounty Platform fosters a secure, collaborative community for ethical hacking practices. As participants, we expect you to adhere to the following Code of Conduct, ensuring a professional and respectful environment for everyone:

**Responsible and Ethical Conduct:**

* Interactions on the platform should always maintain a standard of professionalism and respect.
* Avoid inundating report threads or sending unnecessary support requests that may hinder the efficiency of the process.
* Refrain from leaving derogatory comments that can negatively impact the community.

**Respect for Confidentiality:**

* Never threaten to disclose sensitive information related to private programs or any other user data without proper authorization.
* Attempting to extract bounties, money, or services through coercion or threats is strictly prohibited.
* Cases of extortion or blackmail will be taken seriously and may be subject to further actions.
* Exposing private program details, such as program name, scope, vulnerability details, bounty structure, account information, or any identifiable information, is strictly prohibited.

**Secure Testing Practices:**

* Hackers must seek permission before engaging in any testing practices that could potentially endanger the platform or services.
* Unauthorized exploitation of vulnerabilities, accessing accounts or production details not sanctioned by the program's policy, modifying production or database data, causing Denial of Service, or negatively impacting customer systems is not allowed.

**Responsible Vulnerability Disclosure:**

* For public programs, adhere to responsible disclosure guidelines.
* Wait for the development and release of a patch before publicly disclosing vulnerabilities.

**Official Communication Channels:**

* Use only authorized communication channels on the AuditOne platform to discuss vulnerabilities submitted.
* Contacting security teams outside the official channels about submitted reports breaches this Code of Conduct.

**Integrity and Fair Play:**

* Multiple accounts cannot evade penalties or gain an unfair advantage on the platform.
* Do not engage in activities that manipulate reputation, such as sharing account access or submitting others' work as your own.
* Improper requests for changes in closure status to maintain reputation are prohibited.
* Unauthorized use of another's intellectual property, including the work of other hackers, is strictly forbidden.
* Attempting to manipulate any party through impersonation, whether of an AuditOne employee, another hacker, a program member, or a security team, without proper authorization is strictly prohibited.

By adhering to this Code of Conduct, we aim to create a safe and productive environment for all AuditOne Bug Bounty Platform participants. Let us work together to uphold these standards and ensure responsible and ethical hacking practices within our community.

<br>


# FAQ Hackers

<details>

<summary>How to participate?</summary>

Sign up to [app.auditone.io](https://app.auditone.io/). Complete KYC and qualify for the exam, if required.

</details>

<details>

<summary>Am I eligible for participation?</summary>

Any white hat hacker that follows the [General rules and regulations](/platform/bug-bounty/general-rules-and-regulations) and adheres to the [Code of Conduct](/platform/bug-bounty/code-of-conduct) is eligible to participate. \
\
Some projects require hackers to have completed a **KYC** to participate.

You must sign up to the AuditOne platform to be able to submit reports.

You must not be on any sanctions lists or reside in countries on sanctions lists (e.g., North Korea, Iran, etc.).

</details>

<details>

<summary>How to submit a report?</summary>

Open our app and navigate to the section ‘submit report’. You will find it in the bug bounty tab.

</details>

<details>

<summary>What should a good vulnerability submission look like?</summary>

Good vulnerability submission should have a detailed explanation of how one can exploit and impact on smart contracts. Steps to reproduce to validate the vulnerability and proof of concept, Recommendations to fix is a good submission.

</details>

<details>

<summary>How are bounties paid out?</summary>

On submission, there will be two reviews - one by AuditOne and the next by the project. If both the reviews are cleared, and the project fixes the issue. The bounty will be released.

</details>

<details>

<summary>Can I disclose found bugs to the public?</summary>

No. Auditors are not allowed to disclose bugs in public at any point in time until Auditone or Project publishes it to the community. Publicly disclosing a vulnerability before it's resolved makes it ineligible for a bounty.

</details>

<details>

<summary>I submitted a bug but didn’t hear back.</summary>

Sometimes, reviews may take additional time due to the unavailability of a concerned person at AuditOne or Project. You can DM us on Discord (@adrien\_re) or check the current status of the review on the AuditOne platform. Our triage team takes higher priority for Critical and High over Low issues.&#x20;

</details>

<details>

<summary>Can I contact the project directly about the bugs I found?</summary>

No. You may not be eligible for the bounty if you contact the project directly. As per our agreement with the projects, all submissions about bugs in the bug bounty scope must be submitted through the AuditOne platform.

</details>

<details>

<summary>Can I edit my bug report after submission?</summary>

No. You must submit a new report.

</details>


# Links and Social

<table data-view="cards"><thead><tr><th align="center"></th><th data-hidden data-card-cover data-type="files"></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td align="center"><a href="https://discord.com/invite/n9jXmCw5d5"><strong>Discord</strong></a> </td><td></td><td></td></tr><tr><td align="center"><a href="mailto:hello@auditone.io"><strong>Email</strong></a></td><td></td><td><a href="https://twitter.com/auditone_dao">https://twitter.com/auditone_dao</a></td></tr><tr><td align="center"><a href="https://auditone.io/ "><strong>Website</strong></a></td><td></td><td></td></tr><tr><td align="center"><a href="https://twitter.com/auditone_dao"><strong>X</strong></a></td><td></td><td><a href="https://twitter.com/auditone_dao">https://twitter.com/auditone_dao</a></td></tr><tr><td align="center"><a href="https://docsend.com/view/myxikr4dx2wduwnh"><strong>Litepaper</strong></a></td><td></td><td></td></tr></tbody></table>


