Skip to content
Services

Three columns. One discipline.

Application review and cryptocurrency audit are the same skill sold to two markets: reading code adversarially, with cryptography competence. Each column is a ladder, and most clients climb it over time.

Applications

Design review, code review, penetration testing and API authorisation — sold as a ladder you climb, not one product.

Threat model and design review3–5 days
Before the code exists. We whiteboard the system, map its trust boundaries and enumerate the abuse cases. The cheapest engagement we run and the highest leverage.
Secure code review10–20 days
Manual review of authentication, session handling, access control, injection and business logic. Source-available and targeted. Not a scanner run.
Application penetration test8–15 days
Black or grey box against a running system. This is what most clients ask for by name, including the ones who need a code review instead.
API and integration review5–10 days
Authorisation across service boundaries, token handling, OAuth and JWT misuse. Consistently the richest source of critical findings.
Remediation verificationIncluded
A re-test of every fixed finding, issued as a signed addendum. Included in the original fee. We do not bill remediation as a second engagement.

Digital assets

Smart contracts, protocol economics, custody and exchange operations. On-chain and off, because the two attract different buyers and different attacks.

Smart contract audit
Solidity, Rust on Solana and CosmWasm, and Move. Reentrancy, access control, oracle manipulation, economic and MEV exposure, and upgrade paths.
Protocol and economic design review
The logic above the code: incentive failure, liquidation mechanics, governance capture and bridge trust assumptions. Where the nine-figure losses actually come from.
Custody and key management review
HSM configuration, MPC and threshold schemes, multisig policy, seed ceremonies, signer separation and recovery procedures.
Wallet security review
Browser extensions, mobile wallets, hardware wallet integrations, and the signing UX that decides whether your users blind-sign.
Exchange and VASP operational review
Hot and cold wallet architecture, withdrawal approval flows, insider threat controls and deposit crediting logic.
Bridge and cross-chain review
Validator sets, message verification and replay protection. Historically the most catastrophic category in this industry.

Cryptography and keys

The work that proves the other two are one discipline. Implementation review, key management architecture, and the pipeline that signs your builds.

Cryptographic implementation review
TLS configuration, JOSE and JWT, custom protocols, RNG sourcing, nonce reuse, padding oracles and misuse of primitives. If you have written your own, treat this as urgent.
Key management architecture
Generation, storage, rotation, escrow and destruction. The same review serves a bank's signing keys and an exchange's cold storage.
Software supply chain and signing
Dependency risk, build pipeline integrity, artifact signing, SBOM and reproducible builds. The intersection of application security and key management.
Also available

Attached to core work, not sold beside it.

Cloud configuration review
IAM, network boundaries, secrets management and KMS usage. Attaches easily to any application engagement.
CI/CD pipeline review
Frequently the actual path to production compromise, and rarely the one being defended.
Secure development training
A two-day workshop for your engineers, built around the findings we keep issuing.
Post-exploit incident response
Root-cause forensics on a compromised application or a drained protocol. Narrow by design: we do not run general enterprise incident response.
How engagements run

Scoped, fixed, and re-tested.

Technical due diligence
Pre-investment or pre-acquisition review of a target's codebase, key management and security posture. Short, fixed and fast to turn around.
Security advisory retainer
A fixed number of days each month as fractional security architecture, for teams who need judgement more often than they need a report.
Continuous audit
For protocols shipping frequently: a monthly review of diffs rather than a point-in-time snapshot that is stale the week after it lands.
Pre-audit readiness
Preparation for somebody else's assessment. We tell you what they will find before they find it.
Regulatory-facing assessment
Technical findings mapped to the regime that applies to you. This is technical assessment against a framework, not legal advice, and we state that boundary in our terms.
  • Fixed-scope work is quoted fixed-fee. Day rates are for advisory and open-ended work only.
  • Remediation re-testing is included in the original fee. We never bill for it separately.
  • Engagements starting inside 48 hours carry an emergency rate.
Step by step

How we work, in four moves

  • We start with what an attacker wants and what your system is worth to them. That decides where the days go, not the line count.

Step 01 / 04

Start here

Request a scope call. We tell you what it needs.

Tell us what the system is and what you are worried about. The call takes about thirty minutes and ends with a fixed-scope, fixed-fee proposal. It costs nothing and we do not send a salesperson.

Response time
One working day.

Tell us what you want reviewed