Services

Scope and price depend on how much code there is and how much of it moves money. Below is what each engagement actually includes.

Every audit record is signed, timestamped, and hash-chained — self-scored 16/20 against an independent standard →

Security review

$2,000–$75,000

A full read of your contracts, delivered as a written report you can act on. Priced by TVL — $2,000–$5,000 under $5M, $5,000–$8,000 at $5M–$30M, $15,000–$75,000 above that or once we have a track record together. Turnaround is 1–2 weeks, scaling with scope; rush delivery in 3–5 business days is available at 2x the rate.

Includes
  • Line-by-line review of the contracts in scope
  • A runnable reproduction for every finding — you can verify each claim yourself
  • Findings ranked by impact, with the conditions each one requires
  • Concrete remediation for each issue, at the code level
  • A follow-up pass on your fixes once they land
Does not include
  • A certification, seal, or claim that your code is 'secure' — no honest reviewer offers that
  • Front-end, infrastructure, or off-chain systems unless separately scoped

Ongoing review

$8,000–$20,000/month

For teams shipping continuously, where an annual audit window doesn't match how you work.

Includes
  • New and changed contracts reviewed as they land
  • A standing channel for design questions before you build, not after
  • Priority turnaround when something needs looking at urgently
Does not include
  • Incident response or on-call coverage — ask if you need this and we'll scope it

Contract Reader

Free

Automated source and on-chain analysis, across 23 chains. A starting point, not a substitute for review.

Includes
  • Contracts: privileged capabilities named to the function that grants them
  • Wallets: real on-chain activity — balance, transaction count, age, recent transfers
  • Proxy resolution — reads the implementation, not the shell
  • An explicit statement of what it could not determine
Does not include
  • Anything requiring off-chain state: holder distribution reasoning, trading behaviour
  • Economic modelling or exploit paths — those need a person
Use the tool

Deep report

$19 one-time

A security researcher personally reads the contract's verified source and writes the report — not an automated re-run of the free check.

Includes
  • The same 7 owner-power categories as the free check, reviewed in full — mint authority, ability to disable trading, blacklist power, mutable fees, upgradeability, privileged withdrawal, whether ownership is still active
  • 4 extra categories the free tier doesn't cover: exact current fee values and where they're set, whether ownership itself can be transferred (and to whom), hardcoded or owner-settable exceptions to fees/limits/blacklist, and external contracts this one calls out to and trusts
  • No token-window truncation — a person reading the code isn't limited by an LLM's context size the way the free tier is
  • Every finding cited to the specific function or modifier it comes from
  • A written report emailed to you within 24 hours: plain-English summary, every finding with evidence, and what the review could not determine from source alone
Does not include
  • A safety verdict — same rule as the free version: capabilities, not certification
  • On-chain state, liquidity depth, holder concentration, or deployer behavior — this is a source-code capability review, not a full audit
  • A substitute for a full manual review on anything holding real funds
Run a check to unlock it

API access

$29/month

Programmatic access to the Contract Reader and OFAC sanctions screening for teams that want it in their own tooling, not a one-off web check — real value against bank-priced tools like Chainalysis/Elliptic.

Includes
  • 100 Contract Reader checks/day + 500 sanctions screenings/day, tracked independently — one doesn't draw down the other
  • Same analysis engine as the free tools — contracts, wallets, and OFAC counterparty screening, 23 chains
  • No UI required — built for scripts, bots, and internal dashboards
  • Never blocked by your own plan limit — go over it and the request still succeeds; we just get notified so we can raise it for you
Does not include
  • Deep-report-level extra categories — API responses match the free tier's depth
  • SLA or uptime guarantees — ask if you need this and we'll scope it
Read the API docs

Not sure what you need?

Send the contracts and a sentence about what worries you. We'll tell you what we'd look at and what it would take — and if a review isn't worth it for you right now, we'll say that instead.

Get in touch
See the representative review workflow →
✉️Email us