We recently have completed a few rounds of security audit for our smart contract, conducted by NCC Group. Additionally, we have added the upgradable and extensible part of the Cardstack Token Mechanism and the vesting features, improved the whitelisting capabilities, as well as implemented the proxy patterns with Ethereum Name Service (ENS) support. The source code will be open-sourced soon for a more public review. You can read about our approach to token vesting in our Medium blog post: https://medium.com/cardstack/building-a-token-vesting-contract-b368a954f99