Services
Scope and price depend on how much code there is and how much of it moves money. Below is what each engagement actually includes.
Security review
Scoped per engagementA full read of your contracts, delivered as a written report you can act on.
Includes
- ›Line-by-line review of the contracts in scope
- ›A runnable reproduction for every finding — you can verify each claim yourself
- ›Findings ranked by impact, with the conditions each one requires
- ›Concrete remediation for each issue, at the code level
- ›A follow-up pass on your fixes once they land
Does not include
- ›A certification, seal, or claim that your code is 'secure' — no honest reviewer offers that
- ›Front-end, infrastructure, or off-chain systems unless separately scoped
Ongoing review
Monthly retainerFor teams shipping continuously, where an annual audit window doesn't match how you work.
Includes
- ›New and changed contracts reviewed as they land
- ›A standing channel for design questions before you build, not after
- ›Priority turnaround when something needs looking at urgently
Does not include
- ›Incident response or on-call coverage — ask if you need this and we'll scope it
Contract Reader
FreeAutomated source analysis. A starting point, not a substitute for review.
Includes
- ›Privileged capabilities named to the function that grants them
- ›Proxy resolution — reads the implementation, not the shell
- ›An explicit statement of what it could not determine
Does not include
- ›Anything requiring on-chain state: holder distribution, liquidity, trading behaviour
- ›Economic modelling or exploit paths — those need a person
Not sure what you need?
Send the contracts and a sentence about what worries you. We'll tell you what we'd look at and what it would take — and if a review isn't worth it for you right now, we'll say that instead.
Get in touch