Scope Mapping
Map contracts, roles, deployment scripts, protocol docs, tests, launch dates, and review priorities into a scoped audit plan.
We help Web3 teams review smart contracts, protocols, chains, rollups, bridges, RPC nodes, validators, sequencers, and blockchain infrastructure. AI accelerates scope mapping, attack-surface inventory, tool orchestration, risk triage, and reporting support while expert reviewers validate findings and recommendations.
AI accelerates the workflow; expert review remains responsible for final severity, remediation guidance, and client-facing findings.
Map contracts, roles, deployment scripts, protocol docs, tests, launch dates, and review priorities into a scoped audit plan.
Identify assets, trust assumptions, admin paths, price dependencies, upgrade controls, and high-impact state transitions.
Queue static analysis, dependency checks, invariant candidates, test review, and pattern matching as inputs for expert validation.
Review protocol logic, access control, accounting paths, upgradeability, oracle assumptions, and failure modes with security judgment.
Assign severity from impact plus likelihood, including affected assets, exploitability, privilege requirements, and operational consequence.
Produce findings, remediation guidance, assumptions, and retest notes for fixes reviewed in the agreed revision.
AI drives scope mapping, attack-surface inventory, tool orchestration, risk triage, and reporting support. It does not replace expert review or prove complete vulnerability discovery.
Focused review tracks for teams preparing a mainnet launch, upgrade, integration, or remediation cycle.
Review Solidity/EVM contracts, access control, upgrade paths, accounting logic, oracle assumptions, and high-impact state transitions.
Map protocol architecture, trust assumptions, roles, admin controls, dependency risk, economic assumptions, and cross-contract interactions.
Review chain architecture, node/RPC exposure, validator or sequencer assumptions, bridge messaging, rollup upgrade governance, signing infrastructure, and emergency controls.
Assess deployment controls, upgrade/admin-key paths, monitoring handoff, incident preparation, and known-risk signoff before launch or upgrade.
Each review is scoped around what was provided, what was examined, what was found, and what should happen next.
Plain-language risk overview for founders, protocol leads, and security owners.
Reviewed contracts, commit references, dependencies, deployment assumptions, and excluded areas.
Issue title, affected component, severity, status, and recommended next action.
Impact, likelihood, affected assets, exploitability, and operational consequence for each finding.
Steps, reasoning, or proof detail sufficient for the engineering team to validate the issue.
Concrete fix direction, design alternatives, and follow-up questions for the implementation team.
Fix verification status for reviewed findings in the specified revision.
Deployment, monitoring, admin control, and known-risk items to review before launch.
| Level | How it is used |
|---|---|
| Critical | Direct path to severe loss, protocol takeover, or irreversible asset impact. |
| High | Material exploit path with strong impact or realistic preconditions. |
| Medium | Meaningful risk requiring fixes, additional checks, or design clarification. |
| Low | Limited impact, hard preconditions, or defense-in-depth improvement. |
| Informational | Documentation, clarity, hardening, or operational recommendation. |
Severity is assigned from impact plus likelihood, including affected assets, exploitability, privilege requirements, and operational consequence.
Retest validates whether reported findings appear addressed in the reviewed revision; it is not a new full audit unless separately scoped.
Launch readiness connects audit findings to deployment controls, operating assumptions, and known-risk decisions.
Review deployment process, release authority, script assumptions, and final commit references.
Inspect privileged roles, timelocks, multisig assumptions, emergency paths, and ownership transfer risk.
Review RPC exposure, node access paths, validator or sequencer trust assumptions, relayer roles, and infrastructure blast radius.
Document message validation, relayer trust, finality assumptions, bridge governance, and emergency stop paths.
Document price feeds, external integrations, library dependencies, and failure conditions.
Review emergency controls, governance handoff, and conditions for using privileged interventions.
Identify events, alerts, dashboards, and escalation owners needed after deployment.
Track accepted findings, unresolved assumptions, and decision owners before launch.
Launch readiness is a risk-based review and recommendation, not a certification, warranty, or insurance product.
Tell us what needs review, what artifacts are available, and who needs the output. The Worker records your request in D1 and returns a submission ID for scope review.
Security review reduces risk; it is not proof that vulnerabilities are absent.
Findings are based on the agreed scope, provided materials, and review window.
MVP intake accepts links and scope metadata only. File upload storage is reserved for a later R2-backed phase.