Everything that runs against your code, with what each stage can and cannot see.
Give us a GitHub repository or a verified contract address. For repos we clone the branch, detect the build system, resolve dependencies, and compile with the exact solc version from the pragma. For addresses we pull verified source from the explorer. The build must succeed before anything else runs.
$ auditor ingest https://github.com/org/protocol --branch main
resolved 34 deps ยท solc 0.8.24 ยท build OK (892 LOC)
Two analyzers run over the compiled AST, not the source text โ generated code and inlined libraries are analyzed as the EVM sees them.
| Analyzer | Catches |
|---|---|
| Slither | Reentrancy, access control, unchecked returns, delegatecall, tx.origin auth, uninitialized storage, and the full detector suite. |
| Aderyn | Centralization risk, unsafe ERC20 operations, missing zero-address checks, unprotected initializers. |
A typical 1,000-line protocol produces 150โ250 raw findings.
We derive protocol invariants and let two fuzzers falsify them across millions of calls and multi-transaction sequences.
invariant_totalSupply_matchesSumOfBalances()
invariant_onlyOwner_canPause()
invariant_rewardDebt_neverExceedsPool()
$ echidna . --test-limit 4200000
โ 3 invariants falsified โ 3 candidate findings
A falsified invariant is a concrete call sequence that breaks the property โ it becomes the seed for the reasoning pass and the basis of the PoC.
source: reasoning.Claude also correlates across contracts โ a modifier in contract A bypassed by a call path through contract B is invisible to per-file analysis. Every finding states a confidence score and an explicit uncertainty field.
Each HIGH and CRITICAL gets a generated Foundry test that reproduces the exploit. We run it.
$ forge test --match-test test_exploit_ReentrancyClaim
[PASS] test_exploit_ReentrancyClaim() (gas: 184223)
โ PoC verified โ finding ships
If the test does not pass, the finding is not reported. That rule is why a report from us reads differently from an analyzer dump: every HIGH and CRITICAL claim is backed by an artifact you can run.
| Tier | Stages | PoC scope | Time |
|---|---|---|---|
| Free | 1โ2 | โ | ~10 min |
| Quick | 1โ5 | HIGH + CRITICAL | 24 h |
| Deep | 1โ5 + manual + symbolic | All severities | 3 days |
| Retainer | 1โ5 per PR | HIGH + CRITICAL | Same day |
The retainer tier includes CI/CD integration so every pull request is scanned before it reaches the chain.
POST /v1/audit
{
"target": "https://github.com/org/protocol",
"commit": "a91f4c2",
"chain": "base",
"tier": "quick",
"callback": "https://your-ci.example/webhooks/auditor"
}
โ 202 { "scan_id": "aq_8f2c19da", "status": "queued" }
An automated pipeline cannot prove a contract is safe. It can only state what it tested and what it found. Reports list every stage run, every stage skipped, and every out-of-scope component.
Source is processed on our own infrastructure, retained 30 days for post-fix re-scans, then deleted. NDA on request. For code that cannot leave your premises we run the pipeline against a local checkout โ ask for the on-prem variant.