# PactVerity Independent Review Scope v0.1

Status: open request; no reviewer appointed; no audit claimed.

## Objective

Independently assess whether the PactVerity Receipt API and Proof Engine produce deterministic, tamper-evident receipts from explicitly supplied inputs, and whether public claims match the implemented security boundaries.

## In scope

- Receipt construction, canonicalisation and SHA-256 commitments.
- Receipt verification and tamper detection.
- Request validation, size limits, media-type handling and error behaviour.
- Optional wallet-signature verification boundaries.
- Same-origin owner relay restrictions and irreversible mint-ceremony guards.
- Privacy, logging, secret-handling and public-receipt publication boundaries.
- Threat modelling for caller-supplied false evidence, replay, substitution, malformed input and misleading interpretation.

## Required reviewer output

- Reviewer identity, relevant experience and material-conflict disclosure.
- Commit, deployment version and environment assessed.
- Methodology, commands, test fixtures and complete reproducible output.
- Findings rated by severity, affected component and reproduction steps.
- Limitations and areas not assessed.
- Remediation verification for every closed finding.

## Acceptance boundary

An enquiry, proposal, invoice, private message or incomplete review is not an audit. PactVerity may state that a review is complete only after a named reviewer publishes or authorises publication of a final report and its scope.

Never publish credentials, private keys, seed phrases, customer data or exploitable details before coordinated remediation.
