Three columns. One discipline.
Application review and cryptocurrency audit are the same skill sold to two markets: reading code adversarially, with cryptography competence. Each column is a ladder, and most clients climb it over time.
Applications
Design review, code review, penetration testing and API authorisation — sold as a ladder you climb, not one product.
- Threat model and design review3–5 days
- Before the code exists. We whiteboard the system, map its trust boundaries and enumerate the abuse cases. The cheapest engagement we run and the highest leverage.
- Secure code review10–20 days
- Manual review of authentication, session handling, access control, injection and business logic. Source-available and targeted. Not a scanner run.
- Application penetration test8–15 days
- Black or grey box against a running system. This is what most clients ask for by name, including the ones who need a code review instead.
- API and integration review5–10 days
- Authorisation across service boundaries, token handling, OAuth and JWT misuse. Consistently the richest source of critical findings.
- Remediation verificationIncluded
- A re-test of every fixed finding, issued as a signed addendum. Included in the original fee. We do not bill remediation as a second engagement.
Digital assets
Smart contracts, protocol economics, custody and exchange operations. On-chain and off, because the two attract different buyers and different attacks.
- Smart contract audit
- Solidity, Rust on Solana and CosmWasm, and Move. Reentrancy, access control, oracle manipulation, economic and MEV exposure, and upgrade paths.
- Protocol and economic design review
- The logic above the code: incentive failure, liquidation mechanics, governance capture and bridge trust assumptions. Where the nine-figure losses actually come from.
- Custody and key management review
- HSM configuration, MPC and threshold schemes, multisig policy, seed ceremonies, signer separation and recovery procedures.
- Wallet security review
- Browser extensions, mobile wallets, hardware wallet integrations, and the signing UX that decides whether your users blind-sign.
- Exchange and VASP operational review
- Hot and cold wallet architecture, withdrawal approval flows, insider threat controls and deposit crediting logic.
- Bridge and cross-chain review
- Validator sets, message verification and replay protection. Historically the most catastrophic category in this industry.
Cryptography and keys
The work that proves the other two are one discipline. Implementation review, key management architecture, and the pipeline that signs your builds.
- Cryptographic implementation review
- TLS configuration, JOSE and JWT, custom protocols, RNG sourcing, nonce reuse, padding oracles and misuse of primitives. If you have written your own, treat this as urgent.
- Key management architecture
- Generation, storage, rotation, escrow and destruction. The same review serves a bank's signing keys and an exchange's cold storage.
- Software supply chain and signing
- Dependency risk, build pipeline integrity, artifact signing, SBOM and reproducible builds. The intersection of application security and key management.
Attached to core work, not sold beside it.
- Cloud configuration review
- IAM, network boundaries, secrets management and KMS usage. Attaches easily to any application engagement.
- CI/CD pipeline review
- Frequently the actual path to production compromise, and rarely the one being defended.
- Secure development training
- A two-day workshop for your engineers, built around the findings we keep issuing.
- Post-exploit incident response
- Root-cause forensics on a compromised application or a drained protocol. Narrow by design: we do not run general enterprise incident response.
Scoped, fixed, and re-tested.
- Technical due diligence
- Pre-investment or pre-acquisition review of a target's codebase, key management and security posture. Short, fixed and fast to turn around.
- Security advisory retainer
- A fixed number of days each month as fractional security architecture, for teams who need judgement more often than they need a report.
- Continuous audit
- For protocols shipping frequently: a monthly review of diffs rather than a point-in-time snapshot that is stale the week after it lands.
- Pre-audit readiness
- Preparation for somebody else's assessment. We tell you what they will find before they find it.
- Regulatory-facing assessment
- Technical findings mapped to the regime that applies to you. This is technical assessment against a framework, not legal advice, and we state that boundary in our terms.
- Fixed-scope work is quoted fixed-fee. Day rates are for advisory and open-ended work only.
- Remediation re-testing is included in the original fee. We never bill for it separately.
- Engagements starting inside 48 hours carry an emergency rate.
How we work, in four moves
We start with what an attacker wants and what your system is worth to them. That decides where the days go, not the line count.
Manual review by people who have built this kind of system. Tools find the patterns; the findings that matter come from reading the code.
Every critical finding carries the path to reach it. Where we cannot demonstrate exploitability we grade it honestly rather than inflate the report.
Once you have remediated we verify each finding and issue a signed addendum. It is in the original fee, never billed as a second engagement.
Step 01 / 04
Request a scope call. We tell you what it needs.
Tell us what the system is and what you are worried about. The call takes about thirty minutes and ends with a fixed-scope, fixed-fee proposal. It costs nothing and we do not send a salesperson.
- hello@cernosec.com
- Response time
- One working day.