You get a written report, not a call.
What you receive:
Every defect found, ordered by severity, each with the consequence spelled out: what breaks, under what conditions, and what you or your users would see when it does.
Reproduction steps for each one.
An explicit verdict - PASS, REQUIRES_FIXES or BLOCKED - tied to conditions agreed with you before I start, not invented afterwards.
A prioritised fix plan.
A list of what automated checks cannot establish, and the manual checklist to cover it.
What I audit: payout and settlement flows, exchange API integrations, token deployment tooling, balance and reconciliation logic, key handling.
What I will not do: soften a verdict because a deadline is close, or report a finding I cannot demonstrate.
A redacted sample of the methodology is attached to my profile, along with an open-source TRC-20 deployment bot I built and audited the same way (134/134 tests passing).