Skip to content
Application & digital asset assurance

Forty thousand lines.
Three that matter.

We review application code and cryptocurrency systems the way an attacker would, and tell you exactly which findings will actually be used against you.

Lines of code reviewed
340k
Critical findings issued
61
Value secured under review
$2.1bn
About us

A report with ninety findings is not a better report.

The name is Latin. Cernere — to sift, to separate one thing from another. It is the root of discern, and of certain. It is also, precisely, the job.

Anyone can produce length. The work is telling you which three findings an attacker will actually reach, proving that they can be reached, and saying plainly that the rest is noise.

View more
“Security is not about seeing more. It is about separating what matters from what doesn’t.”
Cerno Security — our thesis
What we do

Three columns. One discipline.

Applications

Design review, code review, penetration testing and API authorisation — sold as a ladder you climb, not one product.

  • Threat model and design review
  • Secure code review
  • Application penetration test
  • API and integration review
View more

Digital assets

Smart contracts, protocol economics, custody and exchange operations. On-chain and off, because the two attract different buyers and different attacks.

  • Smart contract audit
  • Protocol and economic design review
  • Custody and key management review
  • Wallet security review
View more

Cryptography and keys

The work that proves the other two are one discipline. Implementation review, key management architecture, and the pipeline that signs your builds.

  • Cryptographic implementation review
  • Key management architecture
  • Software supply chain and signing
View more
Step by step

How we work, in four moves

  • We start with what an attacker wants and what your system is worth to them. That decides where the days go, not the line count.

Step 01 / 04

Use cases

What an engagement looks like

Digital assets

/ Smart contract audit · 10–15 days

A lending protocol before mainnet

Reentrancy and access control first, then the economics: what liquidations do when the oracle is stale and the market is moving one way.

View more
Custody

/ Key management review · 8–12 days

An MPC signing service

Threshold policy, signer separation, the seed ceremony, and whether a quorum can be reconstructed by anyone who should not be able to reconstruct one.

View more
Fintech

/ API review · 5–10 days

A payments backend adding a digital asset product

Authorisation across service boundaries, token handling, and the OAuth and JWT decisions that are usually where the criticals turn out to live.

View more
Start here

Request a scope call. We tell you what it needs.

Tell us what the system is and what you are worried about. The call takes about thirty minutes and ends with a fixed-scope, fixed-fee proposal. It costs nothing and we do not send a salesperson.

Response time
One working day.

Tell us what you want reviewed