> For the complete documentation index, see [llms.txt](https://novacont.gitbook.io/nova-docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://novacont.gitbook.io/nova-docs/audit-and-security/overview.md).

# Overview

<figure><img src="/files/bmrgNPPdQfC6Ib65cCBN" alt="" width="563"><figcaption></figcaption></figure>

This section transparently documents the security posture of the NovaCont and NovaCont Lite contracts. Here you'll find:

* Results of internal security reviews conducted by the developer
* The static analysis tools used and their findings
* Known limitations and design-related risks
* The Bug Bounty program for community-driven security verification

**Note:** The reviews in this section are not an independent third-party audit. They were conducted by the project's developer and may inherently contain blind spots. As NovaCont's user base and locked value grow, the goal is to commission a professional audit from an independent security firm. This effort will be funded through \[protocol fees / grants / community contributions].

| Check                  | NovaCont (Base)                                                           | NovaCont Lite (TON)                    |
| ---------------------- | ------------------------------------------------------------------------- | -------------------------------------- |
| Internal Review        | Completed                                                                 | Completed                              |
| Static Analysis        | Slither v0.11.5                                                           | Misti                                  |
| Static Analysis Result | 0 Critical/High, 4 Medium candidates reviewed and closed (false positive) | 0 Critical/High/Medium vulnerabilities |
| Manual Findings        | None                                                                      | 6 (1 High, 1 Medium, 4 architectural)  |
| Independent Audit      | Not yet                                                                   | Not yet                                |
| Bug Bounty             | Planned                                                                   | Planned                                |

### About the Developer

Knowing who conducted these reviews and audits matters for weighing how much confidence to place in them. For the developer's background and profile, see the **About the Developer** section.
