Critical
Proposal authorization provenance
Provenance and visibility controls verified.
Opentech OÜ × POSTHUMAN
Independent remediation retest of the Daml smart contracts supporting app.syncvotes.com. The review covered source, contract behavior, application validation, release artifacts and deployed ledger identity.
All retest stages completed. Remediation controls verified.
Completed review process
Release pinned to an immutable source revision.
Governance-v3 and wallet Daml suites executed.
Remediation paths and release boundaries checked.
Backend and frontend checks completed.
DAR hashes, package IDs and ledger metadata matched.
Test and rollout evidence reviewed.
Finding matrix
All six areas from the original review passed the follow-up assessment.
Critical
Provenance and visibility controls verified.
Critical
Proposal execution lifecycle verified.
High
Ballot binding and lifecycle controls verified.
High
Frozen-electorate regression checks passed.
High
Owner-authorized registration verified.
Medium
Policy, validity and proposal-window controls verified.
Validation summary
Reviewed artifacts
Source revision
43a047400582f15eed65f3086b2edb6ad919b3adPackage ID
13e79387c569479b4583a39b53dff28d81b81380964da5dc99c032a660a57114DAR SHA-256
3a6a9290174b9a4969127fbf1e5ec9c9953337c72324ad7cc8a786b3cf72db7bPackage ID
b86d12d9b38588f06f6d52163ce2655a1f3c6a2606322af1d5f3c45f551a0738DAR SHA-256
ee57a96c1b7389eb8f62ef491b22291fcf3fda0732350245b1be8a0411a6a7f8Scope
This point-in-time source-code review is not formal verification or a penetration test.