Yes, we plan to do that and are working on the specifics. We want to do it when we have a somewhat “steady state” for our codebase so that the audit isn’t immediately invalidated by huge code changes.
I’ve heard good things about Cure53, any other security analysts people have had good experiences reading reports from?