SMART-CONTRACT SECURITY

Find the cause. Prove the fix.

Deterministic audit tools and an AI review panel go through your EVM-compatible contracts or your DAML source and turn raw tool output into a findings list your team can act on.

0 points
01 · INPUT

Audit a Solidity contract

Upload a source file — deterministic tools and the AI review panel run together, correlated into one report.

TOOLS + AI JURY
or
Advanced: branch/tag and subfolder
or
02 · RESULTS

Audit findings

Run an audit to turn tool output into an actionable review list.

WAITING

These findings are automated evidence for a qualified engineer to review — not a certification that the contract is 100% issue-free. Confirm exploitability and remediation yourself before relying on this in production.

Findings
High severity
Tools completed
No audit has been run yet.
01 · LOAD

Load a previous report

Upload your updated contract(s) and the .json report from a previous audit. Loading is free — no run, no payment, no AI call — but every re-check round after it is paid. Just finished an audit? Use Fix & re-check on the Audit code tab instead and skip this step.

SETUP
02 · TRACK

Fix, justify, re-check

Load a report on the left and this becomes the engagement: every finding, its status, and every round you have run.

NOT STARTED
No engagement loaded yet.

Mark each finding fixed — describing what you changed, if you want it in the report — or accept the risk with a written justification. Submit updated source for a re-check round and every claim is verified rather than taken on your word, so nothing is marked resolved without being checked.

01 · SUGGESTION

Tell us what is working, and what is not

Read by a person, not a queue. If something in a report was wrong, misleading, or missing, that is the most useful thing you can send us.

02 · MODELS

Request a model

The review panel runs several models against your contract. Tell us which one you want added and we will count the requests — the models people actually ask for are the ones worth the integration work.

Requests for the same model are grouped however you spell it, and asking again updates your note rather than adding a second vote.

03 · CUSTOM WORKSPACE

A review panel of your own

Several model families reviewing in parallel, a jury that argues findings before any reach you, and rulebooks written around your protocol’s own invariants — the architecture behind our EVM and DAML reviews, built for your codebase and your definition of a finding.

HISTORY

Everything on this account

Audits and the points they cost, in one order. A round that failed shows what came back.

Audits run
Contracts
Points spent

Reports are not stored — regenerating one means re-uploading the same contracts. We keep the record of the run, not your source code.

ADMIN · OVERVIEW

Money and activity

Everything below is derived from the points ledger, which is append-only — no figure here is stored, so all of it reconciles back to individual rows.

Paid in by users
Spent on audits
Unspent credit
Audits run

"Paid in" is cash received. "Spent on audits" is what users actually consumed — that is the revenue you have earned. "Unspent credit" is points bought and not yet used: it is a liability, not revenue, because those audits are still owed.

RECEIVING WALLET (LIVE, ON-CHAIN)

Read straight from the chain, and deliberately not reconciled against the ledger above: withdrawals leave the wallet without touching the ledger, and a transfer sent directly to the address arrives without any app-side record.

AUDITS BY TYPE

AUDITS BY HOW THEY WERE PAID

On-chain rounds appear here and nowhere else: their payment records are swept shortly after they settle, so this history is the only durable trace of them.

ADMIN · NEEDS ACTION

Payments on the wrong chain

Money that reached the receiving address on a network the payment was not created for. It is not credited automatically — each of these is a customer waiting.