> ## Documentation Index
> Fetch the complete documentation index at: https://docs.polygon.technology/llms.txt
> Use this file to discover all available pages before exploring further.

# Security reports

> Public security audits, penetration tests, and certifications for Polygon infrastructure and applications.

<Note>
  The following lists the latest available public external assessments and certifications. For questions about security assessments, [contact the security team](/tools/security/contact/).
</Note>

## Certifications

### ISO/IEC 27001:2022

Polygon Labs has been certified since March 2024.

**Certificate:** <a href="https://www.schellman.com/certificate-directory" target="_blank" rel="noopener noreferrer">Schellman Certificate Directory</a> (search for "Polygon Labs")

**Scope:** The ISO/IEC 27001:2022 certification covers the information security management system (ISMS) supporting Polygon Labs' business of designing and developing blockchain scaling and interoperability solutions, including Polygon PoS Chain, Polygon CDK, and Agglayer, in accordance with the statement of applicability, version 1.3, dated October 6, 2025.

***

## Polygon PoS chain

### Bor and Heimdall

| Auditor          | Type           | Report                                                                                                           |
| ---------------- | -------------- | ---------------------------------------------------------------------------------------------------------------- |
| Informal Systems | Security audit | <a href="https://github.com/0xPolygon/heimdall-v2/" target="_blank" rel="noopener noreferrer">View on GitHub</a> |

### Bridge and staking contracts

| Auditor  | Type            | Report                                                                                                                                  |
| -------- | --------------- | --------------------------------------------------------------------------------------------------------------------------------------- |
| Multiple | Security audits | <a href="https://github.com/maticnetwork/pos-portal/tree/master/audits" target="_blank" rel="noopener noreferrer">PoS Portal audits</a> |
| Multiple | Security audits | <a href="https://github.com/0xPolygon/pos-contracts/tree/main/audit" target="_blank" rel="noopener noreferrer">PoS contracts audits</a> |

### POL token

| Auditor       | Type           | Report                                                                                                                        |
| ------------- | -------------- | ----------------------------------------------------------------------------------------------------------------------------- |
| ChainSecurity | Security audit | <a href="https://github.com/0xPolygon/pol-token/tree/main/audit" target="_blank" rel="noopener noreferrer">View on GitHub</a> |
| SigmaPrime    | Security audit | <a href="https://github.com/0xPolygon/pol-token/tree/main/audit" target="_blank" rel="noopener noreferrer">View on GitHub</a> |

***

## Agglayer

### Agglayer smart contracts

| Auditor     | Type           | Report                                                                                                                                     |
| ----------- | -------------- | ------------------------------------------------------------------------------------------------------------------------------------------ |
| Sigma Prime | Security audit | <a href="https://github.com/0xPolygonHermez/zkevm-contracts/tree/main/audits" target="_blank" rel="noopener noreferrer">View on GitHub</a> |
| Hexens      | Security audit | <a href="https://github.com/0xPolygonHermez/zkevm-contracts/tree/main/audits" target="_blank" rel="noopener noreferrer">View on GitHub</a> |
| Spearbit    | Security audit | <a href="https://github.com/0xPolygonHermez/zkevm-contracts/tree/main/audits" target="_blank" rel="noopener noreferrer">View on GitHub</a> |

***

## CDK

Most CDK components have been reviewed as part of zkEVM's audits.

| Component      | Auditor   | Type             | Date       |
| -------------- | --------- | ---------------- | ---------- |
| Bridge service | Cobalt.io | Penetration test | March 2025 |
| Bridge UI      | Cobalt.io | Penetration test | March 2025 |

***

## Zero

| Auditor         | Type           | Report                                                                                                                           |
| --------------- | -------------- | -------------------------------------------------------------------------------------------------------------------------------- |
| Least Authority | Security audit | <a href="https://github.com/0xPolygonZero/plonky2/tree/main/audits" target="_blank" rel="noopener noreferrer">View on GitHub</a> |

***

## zkEVM

| Auditor    | Type            | Date         | Report                                                                                                                               |
| ---------- | --------------- | ------------ | ------------------------------------------------------------------------------------------------------------------------------------ |
| Verichains | zkEVM-Rom audit | January 2023 | <a href="https://github.com/0xPolygonHermez/zkevm-rom/tree/main/audits" target="_blank" rel="noopener noreferrer">View on GitHub</a> |
| Hexens     | Security audit  | N/A          | <a href="https://github.com/0xPolygonHermez/zkevm-rom/tree/main/audits" target="_blank" rel="noopener noreferrer">View on GitHub</a> |
| Spearbit   | Security audit  | N/A          | <a href="https://github.com/0xPolygonHermez/zkevm-rom/tree/main/audits" target="_blank" rel="noopener noreferrer">View on GitHub</a> |

***

## Related resources

* [Bug bounty programs](/tools/security/bugbounty/): Report vulnerabilities and earn rewards
* [Responsible disclosure](/tools/security/disclosure/): How to report security issues
* [Security overview](/tools/security/overview/): Polygon Labs' security practices
