Security help in whatever shape you need it, from day-one design to ongoing advisory.
An audit is one part of security and an opsec review is another, but there's more to it than either. This is the engagement for everything else: planning a protocol with security in mind from day one, architecting it, ongoing advice, retainers for multisig or upgrade security, and whatever else you need. It's fully custom, shaped around you.
A point-in-time audit catches the bugs in the code you've written. An opsec review hardens the process around it. But a lot of security happens before and between those: the architecture decisions you make on day one, the design trade-offs that are cheap to change early and expensive later, the questions that come up mid-build with no obvious owner. This engagement is for all of that.
Our team comes from across the security world, runtime exploitation, DeFi economics, reverse engineering, web and application security, operational security. That breadth means we can give useful advice on almost anything security-adjacent, not just Solana program bugs. If it touches your protocol's safety, we can probably help you think it through.
It takes whatever shape fits. A standing retainer that reviews every multisig change or upgrade before it ships. A few hours of design review while you are architecting a new system. A line to call when something looks wrong at 3am. A second opinion on someone else’s audit. We scope it with you rather than forcing it into a fixed plan.
Because every team’s needs are different, there is no standard term, no fixed hour bucket, no set on-call window. We work out what you actually need, agree on how we will work together, and adjust as that changes. The only constants are that it is Solana, and it is senior researchers doing the work.
Designing a protocol with security in mind from day one, before the code locks in the trade-offs.
A standing line for design reviews, second opinions, and the security questions that come up mid-build.
Retainers that review signer changes, upgrades, and privileged operations before they ship.
A team with diverse security backgrounds, so the engagement can cover almost anything that touches your safety.
We start from your actual situation rather than a fixed package, whether that is day-one architecture or an ongoing safety net.
We agree on the shape, cadence, and focus of the engagement, and adjust it as your needs change.
Design review, threat modelling, multisig and upgrade review, on-call, or a mix, drawing on the whole team's backgrounds.
No standard term, hour bucket, or on-call window. The engagement stays shaped around what you actually need.
Submit your protocol for review and we'll respond within 24 hours. Our researchers have prevented 50+ critical exploits across the Solana ecosystem.