It’s open-source. You can view the code base on github if you wish. . It has been audited, but there are to my knowledge at least, no public reports. You can find it here: 

There’s also an open website for bounties that tracks the history of the Oasis Network in relation to bugs being found and addressed: