Access control
Every privileged function, every modifier, every role. The most common source of critical findings in real codebases.
Automated tools find the easy bugs. The ones that cost money need someone to read the code and reason about what happens when an attacker does the unexpected. That is the whole service.
Every engagement runs through the same checklist, scaled to the scope you have bought.
Every privileged function, every modifier, every role. The most common source of critical findings in real codebases.
Ordering of effects and interactions, including cross-function and read-only reentrancy paths that guards miss.
Rounding direction, precision loss, unchecked blocks, downcasting, and anywhere a fee or share is computed.
Token assumptions, oracle sources, callback surfaces, and what happens when an integration behaves badly.
Proxy initialisation, storage layout, timelocks, and who can change what after deployment.
Included from the project tier upward. Incentive design, liquidation paths, and manipulation under flash-loan capital.
Not better across the board, but different, in ways that matter if you are small.
| Large audit firms | InverseZero | |
|---|---|---|
| Entry price | Typically $25,000+ | $400, or free for one contract |
| Pricing | Quote on request | Published on the site |
| Queue | Often 4–8 weeks | Days |
| Who reviews | Assigned from a pool | A named auditor you can talk to |
| Track record | Hundreds of published audits | Building ours in public, see below |
| Brand value to investors | Substantial | Limited, honestly |
If you are raising from institutional investors who want a recognised name on the report, a large firm is the right choice and we will say so. Our advantage is price, speed and access, not reputation, which we are still building.
Our audits start at $400 for a single contract under 500 lines and run to around $6,000 for a multi-contract protocol review. Larger firms typically start at $25,000. Full pricing is published on our pricing page.
Three to five days for a single contract, seven to ten days for a project audit, and two to three weeks for a full protocol review. We agree the date before starting and we do not compress it.
Yes. We review Rust programs on Solana and Move modules on Sui and Aptos, as well as Solidity across Ethereum, Base and other EVM chains.
Only with your written permission. We ask, because a published report is worth more to your users than a private one, but the decision is entirely yours.
We tell you that, and we do not invent findings to justify the fee. A clean report on a well-written contract is a legitimate outcome.
Yes, in every paid tier. Once you have fixed the issues we raised, we verify the fixes at no extra cost. We do not bill twice for the same code.
The fastest way to judge whether we are any good is to let us review something and read what comes back.