RETAINER PARTNERSHIP

Security that ships with you

A fixed-scope audit captures one release. Teams that keep iterating need researchers who already know the repo — reading diffs as they land, not scrambling only when a launch date forces a review.

Always in the loop. Already fluent in your codebase.

What a retainer unlocks

Capacity reserved for your cadence — so security work lands in the same week as the change, not the next open slot on someone else's calendar.

PR-level review

Senior auditors read pull requests before merge, scoring risk against your invariants while the change is still cheap to fix.

Incident context

When production hurts, the people answering already know your upgrade paths, privileged roles, and prior findings — no cold start mid-crisis.

Reserved schedule

Audit windows and deep-dive hours sit on your calendar first. Retainer partners do not wait behind cold inbound for the next open week.

Direct channel

A dedicated line to the researchers on your engagement. Architecture questions get answers — not a ticket queue and a status page.

How the partnership runs

Four stages from first embed to standing counsel — designed so each release inherits the context of the last.

Embed

We map architecture, deploy path, privilege boundaries, and prior findings until we can reason about your protocol like an internal team.

Live review

Diffs and patches get reviewed against that model — with concrete, merge-ready feedback instead of a report that arrives after the feature has shipped.

Release audits

Major features and upgrades get scheduled deep reviews with priority calendar access, without restarting scoping from zero each time.

Standing counsel

Threat modeling, design pressure-tests, and architecture calls stay available as the protocol grows — not only in the week before mainnet.