Skip to content
Adversarial review

Independent review, before an attacker does it for free

An audit is worth paying for when it changes what you ship. We prioritise findings by what they actually cost you if exploited, reproduce each one, and stay available while your team fixes them — rather than delivering a PDF and disappearing.

Findings
Reproduced
Output
Tests, not just a PDF
Scope
Design and code
What we build

The work itself, described plainly

Line-by-line contract review

Manual review by engineers who write production contracts, focused on the economic assumptions as much as the code. Most serious findings are design flaws, not missing modifiers.

Invariant and fuzz test suites

We leave you the tests, not just the report. Property-based suites encoding your protocol's invariants keep catching regressions long after the engagement ends.

Threat modelling and secure design review

Trust boundaries, adversary capabilities and failure modes mapped before implementation, where a fix costs a conversation instead of a migration.

Application penetration testing

Authentication, authorisation, tenant isolation, injection and business-logic abuse, tested against the application as deployed rather than as documented.

Key management and signing policy

How keys are generated, split, stored, rotated and recovered — and a rehearsal of the recovery, because an untested recovery plan is a hope.

Deliverables

What you receive

  • Smart contract audit & invariant testing
  • Threat modelling and secure design review
  • Application penetration testing
  • Key management and signing policy
Questions

Security & Contract Audits, answered

How long does an audit take?

Two to four weeks for most codebases, driven by contract count and economic complexity rather than line count. We scope after reading the code, not before.

Do you provide a public audit report?

Yes, on request. We produce a summary suitable for publication alongside the detailed private report, once findings are resolved or formally accepted.

What if you find something critical?

We tell you immediately rather than saving it for the report, and we stay engaged through remediation and re-testing. Nothing about a critical finding benefits from waiting.

Related

Often scoped together

Need security & contract audits?

Tell us what you are building. You will hear back from an engineer, not a sales development rep — usually within one business day.

San Francisco, CA · Serving clients in 30+ countries