Proposal: Security Audit Procurement for Canton's Core Network Components
Development Fund Proposal Submission
Proposal file: proposals/canton-audit-procurement.md
Summary
Complements PR #410. Digital Asset's core-components programme puts 11 third-party audits out to RFQ across EOY 2026 / Q1 2027. Those components span at least five distinct security disciplines — cryptography, distributed-consensus protocol, language runtime, public-API attack surface, and cloud/Kubernetes hardening — and no single firm is elite across all of them.
This proposal offers Procur3 as the procurement layer to run that RFQ: post each component as an RFP, onboard incumbent auditors as-is with no fee, and open each requirement to matched specialist firms for competitive quotes where useful.
Requires zero funding. Free to use, free multi-user access. Commission applies only where an award goes to a firm the Foundation was not already engaged with. 30-minute onboarding, white-glove support. Same model currently running for the Midnight Foundation (7 live audit RFPs).
Checklist
- [ ] Proposal file added under
/proposals/ - [ ] Milestones and funding amounts defined
- [ ] Acceptance criteria included
- [ ] Alignment with Canton priorities described
---
Notes for Reviewers
(Add anything the Tech & Ops Committee should pay attention to.)