What we will not audit, at any price.
Low prices attract people who want a logo rather than a review. Our name goes on every report we write, so we screen before we accept, and we publish the criteria rather than applying them quietly.
We decline outright
Teams we cannot reach
Pseudonymous is fine; unreachable is not. Before we take payment we need one call with somebody who can answer questions about the code. If nobody will take that call, we do not take the work.
Contracts with unilateral drain functions
If the deployer can move user funds without constraint, we will say so plainly in writing, and we will not produce a report that could be read as an endorsement. You are welcome to have the code reviewed; you are not welcome to use our report as cover.
Forks with the branding swapped
A copy of an established protocol with a new name, no meaningful changes, and no identifiable team is a pattern we see constantly at the free tier. We decline these.
Timelines that make the work meaningless
We can move quickly. We cannot review two thousand lines overnight. An audit compressed below its honest duration is worse than no audit at all, because it buys confidence that was never earned.
Badge shopping
We do not issue certificates, seals, approval marks or anything else designed to be screenshotted. The deliverable is a report with findings in it. If what you want is a logo for a landing page, we are the wrong firm.
We accept, with conditions attached
- Already-deployed contracts holding user funds. Tell us up front. It changes what we prioritise and how we handle disclosure of anything we find.
- Anonymous teams who will take a call. Common in this industry and entirely legitimate. We just need somebody accountable on the other end.
- Projects with a token launch imminent. Fine, provided the timeline is honest and we are not being used to tick a box hours before listing.
How we decline
Politely, briefly, and without accusation. Something close to: “This one isn’t a fit for us. We’re not able to take it on.” We do not owe an explanation and we do not make public allegations about projects we have chosen not to work with.
Why publish this at all?
Because the alternative (screening quietly) means the clients we do want cannot tell the difference between us and a firm that audits anything for money. Publishing the rules is the only way the policy carries any signal.
Still think you’re a fit?
Most projects are. Send a contract and we’ll take a look.
- Reply written by the auditor who read your code
- No sales sequence, no drip campaign, no retargeting
- We’ll tell you if you don’t need a paid audit yet
- Report published only with your written permission