No, it is impossible to certify security, it's only possible to certify insecurity.
They could only say something like "it's designed to run exposed" or something like it.
You can pay for the audit if you like and still there would be no certainty.
I assume, before they say something like that they want a completely new API. But this would break every single client.