An audit is necessary and not sufficient. Audited protocols get exploited when the audit covered different code than what shipped, when scope excluded the integration that failed, or when admin keys were mishandled. Our process treats the audit as one layer: threat modeling, invariant tests, and static analysis come before it, and monitoring, timelocks, and incident response come after. We coordinate the audit itself, manage findings to closure, and make sure the deployed bytecode matches what was reviewed.