Security
Audits
Privacy that can’t be reviewed isn’t privacy you should trust. Cowl’s circuits and contracts go through independent audits before mainnet, with reports published here.
Scope
| Area | What’s reviewed |
|---|---|
| ZK circuits | Soundness, completeness, and constraint coverage of the proving system |
| Contracts | Shielded pool, verifier, relayer, and compliance modules |
| Cryptography | Commitment/nullifier scheme and stealth-address derivation |
Reports
Audit reports are published here once available. Until then the protocol is testnet-first and should not hold mainnet funds.
Disclosure
Found something? Responsible disclosure goes to security@cowlprotocol.com. A bug-bounty program opens alongside the first mainnet release.
No status theater
We don’t claim “audited” before the reports exist. When they land, they land here, in full.