> ## Documentation Index
> Fetch the complete documentation index at: https://docs.useotto.xyz/llms.txt
> Use this file to discover all available pages before exploring further.

# What has been audited?

> The audit status of Otto's application and the security material published by the providers and protocols it uses.

**Independent third-party audit of Otto's application code: `Not available`.**

Otto uses connected wallets, Coinbase accounts, earlier Safe accounts, Dynamic-managed vaults, and an OKX TEE sub-wallet in different workflows. Some Safe-based paths use Rhinestone's ERC-7579 and Smart Sessions components. Transactions can also call external protocol contracts or APIs.

An audit of one of those components is evidence about that component at the audited version and scope. It is not an audit of Otto's application, configuration, integration code, account permissions, or end-to-end transaction path.

## Provider and protocol material

| Provider or protocol        | Otto use                                                     | Published material                                                                                                                                                 |
| --------------------------- | ------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| Safe                        | Safe-based account paths                                     | [Security](https://safe.global/security) · [Smart-account audits](https://docs.safe.global/advanced/smart-account-audits)                                          |
| Rhinestone                  | Safe7579 adapter and Smart Sessions on applicable Safe paths | [Safe7579 audits](https://github.com/rhinestonewtf/safe7579/tree/main/audits) · [Smart Sessions audits](https://github.com/erc7579/smartsessions/tree/main/audits) |
| LI.FI                       | Swap and bridge routing                                      | [Security](https://docs.li.fi/security-first) · [Contract audit reports](https://github.com/lifinance/contracts/tree/main/audit/reports)                           |
| Circle CCTP                 | Native-USDC bridge plans                                     | [Documentation](https://developers.circle.com/cctp)                                                                                                                |
| Morpho                      | Supported Base yield workflows                               | [Morpho Blue audits](https://github.com/morpho-org/morpho-blue/tree/main/audits)                                                                                   |
| Aave                        | Supported lending paths                                      | [Security](https://aave.com/security)                                                                                                                              |
| Hyperliquid                 | Perpetual-futures paths                                      | [Audits](https://hyperliquid.gitbook.io/hyperliquid-docs/audits)                                                                                                   |
| Polymarket                  | Prediction-market paths                                      | [CTF Exchange audit](https://github.com/Polymarket/ctf-exchange/tree/main/audit)                                                                                   |
| Dynamic                     | Embedded-wallet and managed-vault infrastructure             | [Security overview](https://docs.dynamic.xyz/security/overview)                                                                                                    |
| Coinbase Developer Platform | Coinbase account and hosted buy/sell paths                   | [Documentation](https://docs.cdp.coinbase.com/)                                                                                                                    |
| OKX X Layer                 | Otto X and its TEE sub-wallet                                | [Documentation](https://web3.okx.com/xlayer)                                                                                                                       |

“Documentation” entries above are architecture or security references rather than audit reports. Audit links can cover particular contracts, commits, or dates; read each report's stated scope before relying on it.

For account-specific signing and control boundaries, see [Accounts & permissions](/account-and-settings/accounts-and-permissions). For operational, protocol, smart-contract, and market risks, see [Safety and risks](/safety-and-security/understanding-risks).
