Access and capabilities
Privileged paths, capability ownership, visibility, and every function that can change protected state.
Security Audit
A secure language removes entire bug classes. It does not replace adversarial review of custom business logic.
Privileged paths, capability ownership, visibility, and every function that can change protected state.
Creation, transfer, wrapping, destruction, recovery, and the invariants that must survive each transition.
Pricing, accounting, rounding, incentives, and adversarial transaction sequences against the intended model.
Trust boundaries across packages, oracles, dependencies, migration paths, and operational controls.
Targeted agents help reviewers trace complex call paths and test more hypotheses without replacing human judgment.
Critical properties are specified precisely and proved against the implementation for suitable engagements.
0 writeups
Incident writeups are being prepared.
2 writeups
Map actors, assets, trust boundaries, invariants, and the exact commit included in scope.
Probe authorization, state transitions, and economic edge cases with manual review, targeted tests, and formal methods.
Record impact, affected code, a reproducible path, severity rationale, and a practical fix for every finding.
Review the remediation commit and mark each finding as resolved, acknowledged, or still open.
Send the repository, target commit, documentation, and expected launch window. We will reply with scope and availability.