> For the complete documentation index, see [llms.txt](https://hinkal-team.gitbook.io/hinkal/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://hinkal-team.gitbook.io/hinkal/security-and-compliance/security-audits.md).

# Security audits

Hinkal mitigates smart contract risk through three ways: independent audits of the code, transaction screening of the funds that enter it, and standing bounties.

#### **Audits**

Hinkal's contracts and circuits have been reviewed by six independent firms: zkSecurity, Zokyo, Quantstamp, Secure3, Hexens, and Neodyme.\
\
The reviews cover the Solidity contracts, the Circom circuits, and the interaction between them - the zero-knowledge layer is audited separately from the on-chain layer, since a bug in either would break the privacy guarantees.

<table><thead><tr><th>Firm</th><th width="192">Status</th><th>Report</th></tr></thead><tbody><tr><td><a href="https://zksecurity.xyz/"><strong>zkSecurity</strong></a></td><td>Completed ✅</td><td><a href="https://www.zksecurity.xyz/reports/hinkal-audit">Documentation</a></td></tr><tr><td><a href="https://zokyo.io/"><strong>Zokyo</strong></a></td><td>Completed ✅</td><td><a href="https://github.com/zokyo-sec/audit-reports/blob/main/Hinkal/Hinkal_Zokyo_Feb20th_2024.pdf">Documentation</a></td></tr><tr><td><a href="https://quantstamp.com/"><strong>Quantstamp</strong></a></td><td>Completed ✅</td><td><a href="https://certificate.quantstamp.com/full/hinkal-protocol/66b9b783-8b42-4a4e-89ed-3ef2a2df5958/index.html">Documentation</a></td></tr><tr><td><a href="https://secure3.io/en"><strong>Secure3</strong></a></td><td>Completed ✅</td><td><a href="https://github.com/Secure3Audit/Secure3Academy/tree/main/audit_reports/Hinkal">Documentation</a></td></tr><tr><td><a href="https://hexens.io/"><strong>Hexens</strong></a></td><td>Completed ✅</td><td><a href="https://drive.google.com/file/d/1A0kGmlg04X88-_c4uU0F5WvaMGTDUT3s/view?usp=sharing">Documentation</a></td></tr><tr><td><a href="https://neodyme.io/en/"><strong>Neodyme</strong></a></td><td>Completed ✅</td><td><a href="https://drive.google.com/file/d/1SclKWU99HSVgVxfIh7zz4BWuJO46Jd9W/view?usp=sharing">Documentation</a></td></tr></tbody></table>

***

#### **KYT screening** - Continuous

Every deposit is screened against Chainalysis before it enters the private balance, and depositor addresses are re-screened continuously as sanctions and risk data update. Funds from sanctioned or high-risk addresses cannot be transferred privately; they can only be withdrawn publicly to the address they came from.

This protects the protocol as well as its users: no legitimate user's funds are ever commingled with flagged funds, and anything leaving Hinkal can be treated by exchanges and counterparties as pre-screened. Screening is of wallet addresses, not identity - no KYC, no personal data collected.

See [Compliance](/hinkal/security-and-compliance/compliance.md) for the mechanics.

***

#### **Bug Bounties**

Hinkal's contracts and circuits are open to independent researchers through public bug bounty programs, with rewards based on severity.

| Platform                                    | Status                                                          | Link                                                                |
| ------------------------------------------- | --------------------------------------------------------------- | ------------------------------------------------------------------- |
| [**Immunefi**](https://immunefi.com/)       | Completed ✅                                                     | [Documentation](https://immunefi.com/boost/hinkal-iop/leaderboard/) |
| [**HackenProof**](https://hackenproof.com/) | [Ongoing](https://hackenproof.com/programs/hinkal-bug-bounty) ⏳ | -                                                                   |

***

***Researchers who find an issue should report it to the Hinkal Team rather than publicly.***
