Service catalogue
Everything we do, and who does it.
Fifty-plus engagements across seven groups. Each is tagged with how it is delivered: in-house by our own reviewers, or with vetted partner specialists. Filter by group, or show only what we do ourselves.
We would rather name a partner than overstate our bench.
SENTRYX is a small, specialist firm with deep focus rather than broad coverage. That is a feature for depth and a constraint on breadth, and we would rather tell you which is which than let a service list imply otherwise.
- In-house
- Solidity / EVM and Vyper across Ethereum and L2s; DeFi protocol review; invariant, fuzz and differential testing; oracle, MEV and access-control analysis; upgrade and proxy safety; incident response and forensics; retainers, threat modelling, training and due diligence. Our own reviewers do this work themselves.
- With partners
- Rust (Solana), Move (Aptos, Sui), Cairo (Starknet), formal verification (Certora / Halmos), frontend and dApp security, red-team exercises and tokenomics modelling. Delivered with researchers we have worked with and whose output we review. We name them before you sign.
On track record: SENTRYX is a new brand. We publish reports as engagements complete, and the numbers on this site stay as visible placeholders until there are real, linkable figures behind them. If a security firm shows you a “$4B secured” banner with nothing to click, ask them for the list.
Nothing matches that combination.
Questions
About the catalogue.
Everything on Solidity, Vyper and the EVM: smart contract audits, DeFi protocol reviews, bridge contracts on EVM chains, invariant and fuzz testing, incident response, MEV and oracle analysis, access control and upgrade reviews, and all advisory work. Those are the engagements we run in-house, end to end.
For Rust (Solana), Move (Aptos, Sui), Cairo (Starknet), formal verification and frontend security we bring in researchers we have worked with and whose output we review. We tell you who is on the engagement, what they are responsible for, and who signs the report — before you sign anything. We would rather name a partner than pretend to a depth we do not have in-house.
Yes, and it is common. A live protocol changes the engagement: we review the deployed bytecode against the repository, check the upgrade path and admin keys, and work out what can actually be fixed without a migration. Findings are prioritised by what is exploitable today rather than by textbook severity.
Yes. We design programmes (scope, severity matrix, payout bands) and triage incoming reports — reproducing, classifying and recommending a payout. A bounty is a complement to an audit, not a replacement: bounty hunters optimise for what is cheap to find, which is a different search than a paid adversarial review.
Talk to us. We reserve capacity for public-goods and open-source infrastructure and price it differently. Tell us what you are building and what you can fund.
Not sure which you need?
Describe the system. We'll tell you what it needs.
Most teams come to us asking for “an audit” and leave with a scope that includes an invariant suite and a monitoring plan. Scoping is free.