Applications
Design review, code review, penetration testing and API authorisation — sold as a ladder you climb, not one product.
- Threat model and design review
- Secure code review
- Application penetration test
- API and integration review
We review application code and cryptocurrency systems the way an attacker would, and tell you exactly which findings will actually be used against you.
The name is Latin. Cernere — to sift, to separate one thing from another. It is the root of discern, and of certain. It is also, precisely, the job.
Anyone can produce length. The work is telling you which three findings an attacker will actually reach, proving that they can be reached, and saying plainly that the rest is noise.
View more“Security is not about seeing more. It is about separating what matters from what doesn’t.”
Design review, code review, penetration testing and API authorisation — sold as a ladder you climb, not one product.
Smart contracts, protocol economics, custody and exchange operations. On-chain and off, because the two attract different buyers and different attacks.
The work that proves the other two are one discipline. Implementation review, key management architecture, and the pipeline that signs your builds.
We start with what an attacker wants and what your system is worth to them. That decides where the days go, not the line count.
Manual review by people who have built this kind of system. Tools find the patterns; the findings that matter come from reading the code.
Every critical finding carries the path to reach it. Where we cannot demonstrate exploitability we grade it honestly rather than inflate the report.
Once you have remediated we verify each finding and issue a signed addendum. It is in the original fee, never billed as a second engagement.
Step 01 / 04
/ Smart contract audit · 10–15 days
Reentrancy and access control first, then the economics: what liquidations do when the oracle is stale and the market is moving one way.
View more/ Key management review · 8–12 days
Threshold policy, signer separation, the seed ceremony, and whether a quorum can be reconstructed by anyone who should not be able to reconstruct one.
View more/ API review · 5–10 days
Authorisation across service boundaries, token handling, and the OAuth and JWT decisions that are usually where the criticals turn out to live.
View moreTell us what the system is and what you are worried about. The call takes about thirty minutes and ends with a fixed-scope, fixed-fee proposal. It costs nothing and we do not send a salesperson.