Skip to content
About

Two markets. One skill.

Application review and cryptocurrency audit are not two businesses. They are the same discipline — reading code adversarially, with cryptography competence — sold to two sets of buyers. Very few firms do both, and the work that needs both is exactly where the losses happen.

About us

A report with ninety findings is not a better report.

The name is Latin. Cernere — to sift, to separate one thing from another. It is the root of discern, and of certain. It is also, precisely, the job.

Anyone can produce length. The work is telling you which three findings an attacker will actually reach, proving that they can be reached, and saying plainly that the rest is noise.

“Security is not about seeing more. It is about separating what matters from what doesn’t.”
Cerno Security — our thesis

Narrow on purpose

We review application code, digital asset systems, and the cryptography that connects them. Work outside that we refer to someone who does it better, and we would rather do that than stretch.

Severity we can defend

Every critical finding arrives with the path to reach it. We would rather issue three findings you act on than ninety you file and forget.

Re-testing is included

When you have fixed the findings we verify them and issue a signed addendum, inside the original fee. Charging twice for one engagement is not a business model we want.

Reports written to be read

One document your engineers, your board and your counterparty can each read without translation. This market judges an auditor by report quality, and that is a fair test.

Lines of code reviewed
340k
Critical findings issued
61
Value secured under review
$2.1bn
What we refer out

The work we say no to.

Not because it does not matter. Because it is a different discipline with different economics, and a boutique that takes on adjacent work stops being good at its own. We will introduce you to someone who does these properly.

  • Managed SOC, MDR and EDR deployment
  • General IT security, endpoint hardening and firewall management
  • Full-scope enterprise red teaming
  • Phishing simulation platforms
  • Compliance certification shepherding
Step by step

How we work, in four moves

  • We start with what an attacker wants and what your system is worth to them. That decides where the days go, not the line count.

Step 01 / 04

Start here

Request a scope call. We tell you what it needs.

Tell us what the system is and what you are worried about. The call takes about thirty minutes and ends with a fixed-scope, fixed-fee proposal. It costs nothing and we do not send a salesperson.

Response time
One working day.

Tell us what you want reviewed