Engagement agreement for a professional security audit of smart contract code, covering scope, deliverables (written report with severity classifications), timeline, responsible disclosure, and liability.
The Smart Contract Audit Agreement is a ready-to-use technology & digital template you can send for signature in minutes. It is written for 2 signers (client and auditor) and, by default, expires 30 days after it is sent if left unsigned. It covers smart contract, security, audit. Like every Abundera Sign template it is a convenience draft structured for ESIGN Act and UETA compliance, not a substitute for legal advice. Each signed copy is sealed with PAdES-LTA digital signatures, dual RFC 3161 timestamps, and a tamper-evident evidence package in WORM storage.
Document Preview
# Smart Contract Audit Agreement This Smart Contract Audit Agreement (this "Agreement") is entered into as of the date last signed below (the "Effective Date") by and between: **Client:** ___________, a ___________ with a principal address at ___________ ("Client"); and **Auditor:** ___________, a ___________ with a principal address at ___________ ("Auditor"). --- ## 1. Engagement Overview 1.1 **Nature of Services.** Client engages Auditor to perform a security review and audit of certain smart contract source code (the "Audit"). The Audit is a professional security assessment, not a guarantee that the code is free from all vulnerabilities. Smart contract security is inherently complex; no audit eliminates all risk. 1.2 **Audit Type.** The Audit to be performed is: ___________. 1.3 **Engagement Commencement.** The Audit shall commence on ___________, subject to Client's delivery of all materials specified in Section 2. --- ## 2. Scope of Work 2.1 **In-Scope Contracts.** The Audit covers the following smart contracts and repositories: ___________ (collectively, the "Contracts"). 2.2 **Blockchain / Language.** The Contracts are written in ___________ and are intended for deployment on ___________. 2.3 **Commit Hash / Version.** Client shall provide Auditor with the specific repository URL and the git commit hash or tag to be audited: ___________. Changes to the codebase after the audit commences may require a scope change and additional fees. 2.4 **Out-of-Scope Items.** The following are expressly excluded from the Audit unless specifically agreed in writing: (a) Off-chain components, front-end applications, APIs, or infrastructure; (b) Economic model or tokenomics analysis (unless a DeFi-risk assessment module is separately engaged); (c) Third-party contracts or libraries incorporated by reference but not provided in source form;