Complex systems
We trace behavior across components, processes, and machines, then test the guarantees those interactions are meant to preserve.
SERVICES / SECURITY ASSESSMENTS
We study the program before looking for vulnerabilities. Clients receive the investigation behind the findings: how the system works, the paths we traced, the tests we ran, and evidence of the impact we could demonstrate.
Discuss your projectWe review systems that take real work to understand: complex architectures, codebases with few prior reviews, and newly implemented behavior. The subject may be a Web3 protocol, browser, kernel component, or another kind of software.
We trace behavior across components, processes, and machines, then test the guarantees those interactions are meant to preserve.
Programs that combine several languages can be difficult to understand end to end. We trace control and data across language boundaries before assessing their security.
We study features with no close precedent and behavior that takes real work to understand. We establish their rules from the implementation, then test how they operate within the wider system.
The relevant components, state transitions, and trust boundaries are mapped to the code that implements them. The model explains the behavior we tested.
See a public research exampleFor each finding, we record the affected path, required conditions, reproduction steps, observed effect, and a remediation direction. We distinguish what the tests show from what remains unverified.
See selected findingsNEXT STEP