Twenty-two documents, in reading order. Everything here is published deliberately: webapp/vite.config.ts's publishDocs() names each file, and nothing reaches primes.live/docs/audit/ that is not on that list. The repo holds further working notes that are not part of this pack — regenerated churn reports, internal design drafts and dated run logs — and they are not published, not because they are secret but because nothing in them is an auditor's business.
Status: pre-launch. Testnet only. No mainnet deployment, no real money, no third-party integration. CONCEPT.md is the specification the contracts are written against; where a document here and CONCEPT.md disagree, CONCEPT.md wins and the disagreement is a bug.
Several of these are regenerated from HEAD by a script, not written by hand — those say so in their own first lines, and the script is named there. A regenerated document cannot drift from the code without the generator being wrong, which is the point of generating it.
Every outbound-message site in every contract, classified by destination. TON leaves a contract only through these, so "no admin withdraw path" is a property of this set.