Choosing a security approach

Audit, contest, bounty or big firm?

Four different instruments that get confused with each other, compared honestly — including the cases where you should not hire us. Most protocols need two of these, not one.

Boutique audit

Specialist firm

$3k–$30k · 1–5 weeks

  • +Methodology and a full sample report you can evaluate before signing
  • +Written threat model and systematic coverage
  • +Direct access to the person reading your code
  • +Remediation verification included
  • Small bench — calendar is a real constraint
  • Less brand recognition for investors
Request an audit
Large firm

Brand-name audit

$30k–$200k+ · 3–10 weeks

  • +Recognisable badge for investors and listings
  • +Deep bench across many chains and languages
  • +Formal verification and specialist teams in-house
  • You rarely choose your researchers
  • Long lead times, less direct contact
  • Quality varies by who was available that month
Contest

Audit competition

$20k–$100k prize pool · 1–3 weeks

  • +Dozens of independent researchers at once
  • +Pay for outcomes, not hours
  • +Excellent at the findable-quickly classes
  • Duplicate-heavy; deep areas get less attention
  • No threat model, no walkthrough, no relationship
  • Triage burden lands on your team
Bounty

Bug bounty

Payout on finding · ongoing

  • +Standing coverage after launch
  • +Only pay when something real is found
  • +Covers the code you shipped last week
  • Coverage is opportunistic, never systematic
  • Needs real budget to attract real researchers
  • You are learning about the bug after deployment
Where we would tell you to go elsewhere

Three cases where SENTRYX is the wrong choice.

You need a badge more than a review. If an exchange listing or an investor term sheet names a specific firm, hire that firm. We cannot give you their logo and it would be dishonest to pretend the review substitutes for the requirement.

Your system is primarily non-EVM. A Solana-first or Move-first protocol should hire a firm whose core team lives in that ecosystem. We deliver those engagements with partner researchers and we will say so — but if the whole protocol is Rust, the partners should be the principals.

You need ten researchers next Monday. We are small on purpose. If your launch date requires a bench we do not have, an overbooked auditor is worse than a different auditor.

What we would actually do

Most protocols need two of these.

Security is layered, not chosen. Here is the sequence we recommend most often, and roughly what it costs.

Stage 1 · pre-launch

Audit the contracts that hold funds

Systematic coverage of the code where loss is possible, with a threat model you keep. Narrow the scope before you narrow the depth.

Stage 2 · pre-launch

Invariant suite in CI

The highest-leverage artefact from any engagement. It keeps testing every commit long after the report is filed.

Stage 3 · at launch

Bug bounty

Standing coverage with real payout bands. Complements the audit; does not replace it.

Stage 4 · ongoing

Retainer or re-audit

Because the code you audited is not the code you are running three months later.

Deciding

Questions teams ask us before choosing.

See also pricing and the methodology.

Different instruments. An audit gives you named accountability, a threat model, a walkthrough and someone who will answer the phone in six months. A contest gives you many eyes for a fixed prize pool and is excellent at finding what is findable quickly. If you can only afford one before launch, take the audit — then run a contest or a bounty as ongoing coverage.

Sometimes, and be honest about which reason applies. If you need the brand on your landing page for investors or an exchange listing, that is a real commercial reason and a large firm delivers it. If you need the code read carefully, firm size does not predict that — the individual researchers assigned to you do, and at a large firm you usually cannot choose them.

Whatever is cheap enough to find relative to the payout. Bounty hunters are rational: they look where the expected value is highest. That makes bounties excellent standing coverage and poor systematic coverage, because nobody is paid to read the boring parts of your codebase.

No, and forks deserve particular care. The base is well-tested, so teams assume the whole thing is safe and the diff gets less scrutiny than a greenfield build would. Every assumption the original design relied on may have been broken by your changes, and nobody has checked.

A pre-deployment assessment on the contracts that hold funds, plus an invariant suite in CI, plus a bug bounty at launch. That combination costs less than a full audit and covers more ground than any single instrument. We will tell you if that is the right shape for your budget rather than quoting for something larger.

Not sure which you need?

Tell us the constraint, not the product.

Budget, launch date, what the code does. We will tell you the shape that fits — including when it is not us.