The Guardian Standard
Guardian's comprehensive audit package is designed to bring new releases to production with assurance rated for billions in digital assets.



Jupiter




Two independent teams, maximum security outcome.
One team pushes AI systems to their limits while another focuses on manual analysis and deep fuzzing.
Competitive incentives reward performance, and each team cross-checks the other so the final result is stronger than either workflow alone.
Exhaustive Invariant Suite.
Guardian builds an exhaustive invariant suite around the protocol's core safety properties, then uses it to continuously pressure-test every reachable state.
The suite becomes a reusable security harness for fixes, retesting, and future changes to the codebase.
World-renowned security researchers battle-test your system.
Guardian researchers attack the protocol manually and make the system as air-tight as possible before it faces the public.
Guardian stakes $100,000 in a Defender contest.
We sponsor a $100,000 public contest after the audit, putting our own funds behind the quality of the review and inviting the broader security community and all AI agents to challenge it.
Hosted bounty with $50,000 in matching.
Guardian hosts and manages the bug bounty, with $50,000 in Critical bounty matching.
Six months of update review for the same codebase.
Continued review of any updates the team makes to the same scope within six months after production, up to 2,500 SLOC.
Half the package cost back toward offchain risk.
Get half of the package cost back in credits toward the offchain security services below. Select a service to see what the assessment covers.
01 OpSec Audit People, keys, and operational workflows Access controls Keys & secrets Developer hygiene SaaS admin security Notable incident Drift Protocol 路 $285M stolen
A systematic review of the operational controls protecting your team and production environment. We trace access, key and secret handling, developer devices, deployment workflows, internal communications, and SaaS or social admin accounts to uncover paths to unauthorized action or credential theft.
02 Infrastructure Pentest Cloud, SaaS, CI/CD, and access paths AWS GCP Azure Kubernetes Terraform Docker Notable incident Mixin Network 路 $200M stolen
Examines cloud and SaaS environments鈥攆rom AWS, GCP, and Azure to source control, CI/CD, infrastructure as code, Kubernetes, and edge platforms鈥攆or exploitable misconfigurations. We review IAM, network controls, logging, data protection, exposed assets, and insecure integrations that could lead to privilege escalation or compromise.
03 WebApp Pentest Frontend, authentication, and user flows App flow mapping Auth & sessions Roles & access Business logic Notable incident Crypto.com 路 $34M stolen
Maps the application end to end, then tests how the frontend and backend enforce authentication, roles, sessions, sensitive actions, and business logic. Manual manipulation and fuzzing target access-control bypasses, insecure inputs, workflow abuse, and client or server weaknesses.
04 API Pentest Endpoints, authorization, and data flows REST, GraphQL & gRPC Auth & authorization Input & data Endpoint logic Notable incident 3Commas 路 $22M stolen
Tests REST, GraphQL, gRPC, and other APIs across authentication, authorization, rate limits, input validation, data exposure, and endpoint logic. Real-world attack paths include token abuse, parameter tampering, mass assignment, injection, and multi-step transaction flaws.
05 Keeper/Offchain Automation Pentest Bots, relayers, signers, and scheduled jobs State transitions Key flows Failure & retries Chain interactions Notable incident THORChain 路 $10M stolen
Reviews the autonomous systems that influence onchain behavior鈥攊ncluding schedulers, bots, relayers, oracle updaters, sequencers, and risk engines. We test decision logic, data pipelines, key flows, retries, trust assumptions, race conditions, replay resistance, and unsafe state transitions.
06 Perimeter Security Audit Internet-facing assets and perimeter controls Recon & inventory Ports & exposure CVEs & exploitation WAF & TLS Notable incident CoW Swap 路 $1.2M stolen
Maps the public attack surface through reconnaissance, DNS and subdomain discovery, service enumeration, port and TLS analysis, and vulnerability scanning. Findings are manually validated through safe exploitation, with WAF and Cloudflare controls reviewed and exposed assets inventoried.
Not just an audit,
a launch partner.
Before audit
Independent AI and manual tracks pressure-test the highest-risk surfaces.
During audit
Cross-checking compounds automated depth with expert judgment.
After audit
Public contest, hosted bounty, update review, and Web2 credits extend protection.
View Audit Pricing.
Compare the Guardian Max and Guardian Basic.