Security

Audits

Privacy that can’t be reviewed isn’t privacy you should trust. Cowl’s circuits and contracts go through independent audits before mainnet, with reports published here.

Scope

AreaWhat’s reviewed
ZK circuitsSoundness, completeness, and constraint coverage of the proving system
ContractsShielded pool, verifier, relayer, and compliance modules
CryptographyCommitment/nullifier scheme and stealth-address derivation

Reports

Audit reports are published here once available. Until then the protocol is testnet-first and should not hold mainnet funds.

Disclosure

Found something? Responsible disclosure goes to security@cowlprotocol.com. A bug-bounty program opens alongside the first mainnet release.

No status theater
We don’t claim “audited” before the reports exist. When they land, they land here, in full.