About
A small firm that says what it is.
SENTRYX is a specialist smart contract security practice operating under Avanteia Private Limited, a registered technology company in Goa, India. Deep EVM and DeFi focus, and a policy of not claiming anything we cannot show you.
Why this firm exists
The smart contract audit market has a credibility problem, and it is not the one people usually name. It is not that audits are expensive or slow. It is that the artefact a buyer receives — a PDF with a logo on it — looks identical whether it took three weeks of adversarial reading or three days of running Slither and reformatting the output.
A team choosing between two firms cannot tell those apart from the outside. So the market competes on the things that are visible: brand, client logos, turnaround time, and increasingly large numbers on landing pages. None of which correlate with whether anyone actually understood your liquidation logic.
We built SENTRYX around the opposite bet: make the work inspectable. Publish the methodology in full. Show a complete sample report so you can judge the depth of analysis before you pay for it. Ship a runnable proof of concept with every serious finding, so nothing rests on our authority. And leave the counters on this site as visible placeholders until there are real, linkable numbers behind them.
What we are good at
Solidity and the EVM, and specifically DeFi: value flows, oracle dependencies, liquidation mechanics, share and fee accounting, upgrade paths, and the economic attacks that are profitable even when every line of code does exactly what it says. That is where our depth is, and it is where the majority of value at risk in this industry sits.
We are also good at testing infrastructure — invariant suites, fuzzing campaigns, CI pipelines — because the highest-leverage thing a security engagement can leave behind is not a report. It is a set of properties that keep getting checked against every commit for the next two years.
What we are not
We are not a large firm and we are not going to pretend otherwise on a page like this. We are a small senior team with a partner network. That means we take fewer engagements than a firm with thirty auditors, that our calendar is a real constraint, and that for Rust, Move, Cairo or formal verification we bring in specialists and tell you who they are.
We do not have years of public reports behind us, because SENTRYX is new. What we have is a methodology you can read in full, a sample report you can judge, and the willingness to do a paid trial on a single contract before you commit to a full engagement. If that is not enough for your risk tolerance, that is a legitimate position — and we would rather you hire someone with the track record you need than take a job we cannot back up.
How we handle disagreement
Teams disagree with findings. It is healthy, and it is often where the interesting conversation is. Our rule is simple: we do not quietly downgrade a finding because a client pushed back, and we do not overstate one to look thorough. Where you disagree with a severity, your position goes in the report next to ours. The reader can decide.
The same applies after an incident. If a protocol we audited is exploited through something we should have caught, we will say so publicly and publish the analysis. An audit report that cannot survive being wrong in public was never worth much.
The parent company
SENTRYX operates as a brand of Avanteia Private Limited, a registered technology company based in Goa, India. Avanteia runs technology education programmes and IT services; SENTRYX is its dedicated web3 security practice, kept deliberately separate so that security work is never a side product of a consultancy.
How we staff
Small on purpose.
We do not publish researcher profiles. We do tell you, in writing and before you sign, exactly who is assigned to your engagement and what they have done before.
Two independent reads
Every standard audit gets two independent reads of the full scope. Not a junior pass with a senior sign-off — two complete, separate readings, reconciled afterwards. Independence is what makes the second read worth anything.
No silent subcontracting
Where an engagement needs a chain or a technique outside our in-house depth, we bring in a vetted partner and name them to you before you sign. You always know who is reading your code, even though the public site does not.
We turn down work
If we cannot staff an engagement properly, or if it needs expertise we do not have and cannot source, we say no and point you elsewhere. Overbooked auditors are how reports get written by whoever was free.
Judge for yourself
Read the methodology before you read our pitch.
The full process is public and the sample report is complete. That is the whole case.