Live Preview
Template Structure
Our Smart Contract Audit Partners — The Firms We Use for Production Deployments
We work with a curated set of independent audit firms across different protocol types and budget ranges. We do not audit code we write ourselves — independence is non-negotiable.
Format
Document
Sections
8
Format
Document
Status
Ready to customize
Primary Audit Partners (By Protocol Type)
DeFi Protocols (Complex):
Trail of Bits — for protocols with novel architecture or economic complexity requiring deep economic attack modeling. Longest engagement time; highest cost; strongest for complex DeFi.
DeFi and NFT (Standard):
OpenZeppelin — for standard DeFi protocol audits and high-value NFT contract audits. The 'institutional seal' — major institutional clients recognize and trust OpenZeppelin reports.
Broad Coverage:
Certik — for teams needing audit coverage at lower cost. Largest public audit database. Best for standard contracts without novel architecture.
Full-Stack (Contract + Application):
Halborn — for exchange infrastructure, custodial systems, or applications where both smart contract and API/application security must be reviewed in one engagement.
Competitive Coverage:
Code4rena — competitive audit (crowdsourced) as a complement to a structured firm audit. We recommend Code4rena for post-structured-audit additional coverage.
Post-Deployment Bug Bounty:
Immunefi — every production protocol we deliver has an Immunefi bug bounty listed. Standard bounty range: $50,000–$500,000 based on protocol TVL.
How We Select Auditors for Your Project
1. Protocol category match — the auditor with the most relevant past audits in your specific protocol type. 2. Current availability — audit queues fluctuate; we check availability before recommending. 3. Budget alignment — audit cost varies significantly; we match to your budget without compromising on independence. 4. Timeline compatibility — audit firm timeline must align with your deployment schedule. We coordinate the audit engagement: kickoff call, technical questions, findings review, remediation verification, final report. You do not need to manage the auditor relationship independently.
Template Guide
How to use this template
Template Overview
We work with a curated set of independent audit firms across different protocol types and budget ranges. We do not audit code we write ourselves — independence is non negotiable.
Primary Audit Partners (By Protocol Type)
DeFi Protocols (Complex):
Trail of Bits — for protocols with novel architecture or economic complexity requiring deep economic attack modeling. Longest engagement time; highest cost; strongest for complex DeFi.
DeFi and NFT (Standard):
OpenZeppelin — for standard DeFi protocol audits and high-value NFT contract audits. The 'institutional seal' — major institutional clients recognize and trust OpenZeppelin reports.
Broad Coverage:
Certik — for teams needing audit coverage at lower cost. Largest public audit database. Best for standard contracts without novel architecture.
Full-Stack (Contract + Application):
Halborn — for exchange infrastructure, custodial systems, or applications where both smart contract and API/application security must be reviewed in one engagement.
Competitive Coverage:
Code4rena — competitive audit (crowdsourced) as a complement to a structured firm audit. We recommend Code4rena for post-structured-audit additional coverage.
Post-Deployment Bug Bounty:
Immunefi — every production protocol we deliver has an Immunefi bug bounty listed. Standard bounty range: $50,000–$500,000 based on protocol TVL.
How We Select Auditors for Your Project
1. Protocol category match — the auditor with the most relevant past audits in your specific protocol type.
2. Current availability — audit queues fluctuate; we check availability before recommending.
3. Budget alignment — audit cost varies significantly; we match to your budget without compromising on independence.
4. Timeline compatibility — audit firm timeline must align with your deployment schedule.
We coordinate the audit engagement: kickoff call, technical questions, findings review, remediation verification, final report. You do not need to manage the auditor relationship independently.