What's the problem?
@maurelian:
"Audits are not always public. We include language in our [legal] contracts reserving the right to publish findings if we believe a client is taking dangerous risks without addressing our concerns."
Why is it a problem?
Without including language like this, as stated, the client could proceed to use the contracts in the audit without implementing any fixes the auditor has determined makes the code unsafe.
Any ideas how to fix it?
Needs discussion