> For the complete documentation index, see [llms.txt](https://docs.sandclock.org/current/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.sandclock.org/current/technical-documentation/security.md).

# Security

Audits, formal verification, and compliance reports

Sandclock takes security seriously. Every contract deployed to mainnet has been independently audited. Lindy Labs also runs formal verification to catch issues that traditional audits miss — see [Aegis](https://lindylabs.net/articles/introducing-aegis).

## SOC 2 Report

Lindy Labs is SOC 2 Type 1 compliant, covering the systems and controls that underpin Sandclock. Independent attestation reports are available below.

{% file src="/files/ZVloUukR1h5noehTB5Fa" %}

{% file src="/files/3jhXOg1bgNUQpc8mmj6x" %}

## Smart Contract Audits

All deployed contracts have been reviewed by independent security firms. Reports are organized by component.

### ERC4626 Vault

The core vault contracts were audited twice ahead of the v2 launch.

[2023-07, by Trail Of Bits](https://github.com/trailofbits/publications/blob/master/reviews/2023-07-sandclock-securityreview.pdf)

[2023-04, by WatchPug](https://github.com/lindy-labs/sandclock-contracts/blob/main/audits/2023_April_27_WatchPug_Audit_Report.pdf)

### Token

The QUARTZ token contract was audited at launch and again following updates.

[2021-06, by Christoph Michel](https://drive.google.com/file/d/1mOHOeD5bSyQBkValNKnLKqssMFiuGOGv/view?usp=sharing)

[2021-09, by Solidified](https://drive.google.com/file/d/1D-uAeQtWU09G1psZQ6WKTsvGPtx5AtsX/view?usp=sharing)
