Documentation

How the pipeline works

Everything that runs against your code, with what each stage can and cannot see.

1 ยท Ingest and build

Give us a GitHub repository or a verified contract address. For repos we clone the branch, detect the build system, resolve dependencies, and compile with the exact solc version from the pragma. For addresses we pull verified source from the explorer. The build must succeed before anything else runs.

$ auditor ingest https://github.com/org/protocol --branch main
resolved 34 deps ยท solc 0.8.24 ยท build OK (892 LOC)

2 ยท Static detection sweep

Two analyzers run over the compiled AST, not the source text โ€” generated code and inlined libraries are analyzed as the EVM sees them.

AnalyzerCatches
SlitherReentrancy, access control, unchecked returns, delegatecall, tx.origin auth, uninitialized storage, and the full detector suite.
AderynCentralization risk, unsafe ERC20 operations, missing zero-address checks, unprotected initializers.

A typical 1,000-line protocol produces 150โ€“250 raw findings.

3 ยท Invariant fuzzing

We derive protocol invariants and let two fuzzers falsify them across millions of calls and multi-transaction sequences.

invariant_totalSupply_matchesSumOfBalances()
invariant_onlyOwner_canPause()
invariant_rewardDebt_neverExceedsPool()

$ echidna . --test-limit 4200000
โ†’ 3 invariants falsified โ†’ 3 candidate findings

A falsified invariant is a concrete call sequence that breaks the property โ€” it becomes the seed for the reasoning pass and the basis of the PoC.

4 ยท Claude reasoning โ€” two passes

Claude also correlates across contracts โ€” a modifier in contract A bypassed by a call path through contract B is invisible to per-file analysis. Every finding states a confidence score and an explicit uncertainty field.

5 ยท PoC generation and verification

Each HIGH and CRITICAL gets a generated Foundry test that reproduces the exploit. We run it.

$ forge test --match-test test_exploit_ReentrancyClaim
[PASS] test_exploit_ReentrancyClaim() (gas: 184223)

โœ“ PoC verified โ€” finding ships

If the test does not pass, the finding is not reported. That rule is why a report from us reads differently from an analyzer dump: every HIGH and CRITICAL claim is backed by an artifact you can run.

Coverage per tier

TierStagesPoC scopeTime
Free1โ€“2โ€”~10 min
Quick1โ€“5HIGH + CRITICAL24 h
Deep1โ€“5 + manual + symbolicAll severities3 days
Retainer1โ€“5 per PRHIGH + CRITICALSame day

Supported targets

API access

The retainer tier includes CI/CD integration so every pull request is scanned before it reaches the chain.

POST /v1/audit
{
  "target":   "https://github.com/org/protocol",
  "commit":   "a91f4c2",
  "chain":    "base",
  "tier":     "quick",
  "callback": "https://your-ci.example/webhooks/auditor"
}

โ†’ 202 { "scan_id": "aq_8f2c19da", "status": "queued" }

What we do not claim

An automated pipeline cannot prove a contract is safe. It can only state what it tested and what it found. Reports list every stage run, every stage skipped, and every out-of-scope component.

Data handling

Source is processed on our own infrastructure, retained 30 days for post-fix re-scans, then deleted. NDA on request. For code that cannot leave your premises we run the pipeline against a local checkout โ€” ask for the on-prem variant.

Ready when you are

Free scan first. Ten minutes, no payment.

Scan a contract โ†’