> For the complete documentation index, see [llms.txt](https://docs.zestprotocol.com/start/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.zestprotocol.com/start/stacks-market-smart-contracts/audits.md).

# Audits

## Battle-Tested Security

Zest V2 has undergone multiple comprehensive security audits, building on V1's foundation as one of the most thoroughly reviewed protocols on Stacks. The V2 architecture includes:

* Enhanced position validation with Risk Group transition protection
* Improved pausability mechanisms with grace periods for emergency responses
* Robust health check systems that validate positions before and after every operation
* Time-based precision using block timestamps for accurate interest and oracle calculations

**Zest Protocol V2 has been audited by:**

* [**Clarity Alliance**](https://x.com/ClarAllianceSec) - Leading Clarity security firm
* [**Asymmetric Research**](https://x.com/asymmetric_re) - Blockchain security specialists
* [**Greybeard Security**](https://github.com/greybeard-security/) - Pair of senior white hat web3 SRs: [100proof](https://x.com/1_00_proof) and [neumo](https://x.com/neumoXX)

### Audit Reports

* [**Clarity Alliance - Zest Protocol v2**](https://clarity-alliance.github.io/audits/Clarity%20Alliance%20-%20Zest%20Protocol%20v2.pdf) - October 23rd, 2025
* [**Clarity Alliance - Zest Protocol v2 Upgrade**](https://clarity-alliance.github.io/audits/Clarity%20Alliance%20-%20Zest%20Protocol%20v2%20Upgrade.pdf) - December 3rd, 2025
* [**Greybeard Security - Zest Protocol v2**](https://drive.google.com/file/d/1ttWULriHM4yZZ_Y3kMJiSnrFaYee-IMi/view?usp=drive_link) - December 4th, 2025
* [**Clarity Alliance - Zest Protocol v2 Upgrade V2**](https://clarity-alliance.github.io/audits/Clarity%20Alliance%20-%20Zest%20Protocol%20v2%20Upgrade%20V2.pdf) - December 20th, 2025

An active **bug bounty program** is running in partnership with Immunefi. Details are available [**here**](https://immunefi.com/bug-bounty/zest-protocol-v2/information/)**.**

### **Continuous AI Security Testing**

Audits are a snapshot. Security is a process. Zest Protocol runs a continuous, automated security harness against its contracts around the clock, driven by every frontier AI model from the day it ships.

Each new model release is deployed against the codebase as a fresh adversary, probing for anything that could put user funds or protocol state at risk. Every candidate finding is verified against the live contract code before it counts as a result.

Every released frontier model has been run against the protocol. The record: zero valid bug reports since the start of 2026.

Frontier models keep getting better at finding vulnerabilities. That is exactly why each new one is pointed at Zest Protocol's code first. The strongest attacker on the market is always working for the protocol, not against it.
