Applications & infrastructure
- Web applications
- Mobile applications
- APIs
- Backend services
- AWS / GCP / Azure
- Kubernetes & containers
- CI/CD pipelines
- Identity & SSO
- Internal networks
SECURITY REVIEWS
Each targets a different layer of the system. Find yours below, or tell us the scope and a principal will point you to the right review.
Review targets
Find your system below, and the review that covers it. If your scope crosses categories, we combine the right specialists into one engagement.
Timing
Challenge trust assumptions before they become expensive to reverse.
Review the system once its behavior and critical paths are stable enough to test.
Reassess upgrades, migrations, new integrations, custody, or infrastructure changes.
Reconstruct failure paths and determine what must change before confidence is restored.
Process
Identify the system, workflow, or change that needs independent security judgment.
Confirm the assets, trust boundaries, critical paths, evidence, exclusions, and decision the work must support.
Match the target to reviewers with the relevant code, protocol, cryptography, infrastructure, custody, or AI expertise.
Work through findings, verify agreed fixes, and deliver the technical or executive readout.
Typical engagement team
The exact team depends on the scope. Every engagement has a principal who owns it from scoping through delivery, joined by the specialists the system calls for, and whoever is assigned is named in your proposal.

Founder & Partner
Led a security engineering practice for Rust and non-EVM systems across Substrate and NEAR. Earlier, built vulnerability-detection engines at Invicti used by Fortune 50 and public-sector organizations.

Principal Advisor
Head of Security at Agora, responsible for security, data protection, and corporate IT risk. Earlier at EY, led assessments across financial services, healthcare, and government.
Currently
Head of Security, Agora
$45B+ in volume

Specialist Advisor
Offensive security specialist with 10+ years, 100+ public audits across eight ecosystems, and OSCP, OSCE, eWPT, and eWPTX certifications. At ING and Binance, worked across red teaming, exploit development, infrastructure, and high-scale digital asset systems.
Inspectable proof
Each card shows one highlighted finding, not the full result. Open the report for every finding and its severity.
NEAR Intents Security Review
Potential Funds Stealing From Users Via Repeating Failed Intents
Web Application Security Review
Vulnerable to React2Shell
Pallet Pass Security Review
DoS of The Main Functionality Through Session Key Hijacking
Onchain Orderbook and Perpetual Trading Security Review
Order Placement with Negative/Zero Margin Ratio Is Possible
Related services
Next step
Share the target, architecture, repo, timeline, and the decision you need the review to support.
Discuss your scope