DeFi Security AllianceRequest an audit
Menu

DeFi Security Alliance directory

Find Smart Contract Security Auditors, Reports and Tools

Compare 23 auditor profiles, review the evidence behind their work and prepare an audit request.

Evidence before selection

Choose an auditor for your code and its risks

Compare relevant project experience, the scope of published work and evidence that fixes were checked. A directory listing and an expert recommendation have different requirements.

  1. Match the work. Look for the same language and protocol type.
  2. Read the evidence. Trace findings to code and a defined review scope.
  3. Check the follow-up. Ask who retested the fixes and what remained open.
Read the selection criteria →

Original research · initial source snapshot

17 of 23 profiles had a readable public page in the initial check

On , we fetched official pages for 23 providers. 17 had at least one successful response with 500 or more extracted text characters.

This measures access to public evidence. A failed fetch or JavaScript shell does not establish a lack of security expertise. Later profile research does not change this frozen sample.

Latest articles

  • Auditing AI Generated Smart Contracts: Independent Requirements and Test Evidence

    Tooling

    Auditing AI Generated Smart Contracts: Independent Requirements and Test Evidence

    Generated code needs the same accountable review as any release, with extra attention to shared assumptions between code and tests. Auditing AI generated smart contracts starts with an independent specification, a frozen build and evidence that distinguishes failed analysis from completed checks.

    12 min read

  • Bridge Integration Checklist: Verify the Route, Receiver and Recovery Path

    Verticals

    Bridge Integration Checklist: Verify the Route, Receiver and Recovery Path

    A working transfer proves only one execution path. A bridge integration checklist should bind the selected route to its verification rules, application permissions and recovery behavior; a core messaging address alone does not establish token bridge support.

    12 min read

  • Crypto Security Score: Reading Methodology, Evidence and Unknowns

    Personas and market

    Crypto Security Score: Reading Methodology, Evidence and Unknowns

    A rating is useful when its inputs answer the risk question you actually have. A crypto security score should lead to dated evidence about code, authority and operations; the aggregate alone cannot establish deployment safety or investment suitability.

    12 min read

  • DeFi Insurance for Protocols: Scope, Exclusions and Claims Evidence

    Operations

    DeFi Insurance for Protocols: Scope, Exclusions and Claims Evidence

    Protection depends on a named claimant, position, event and wording. DeFi insurance for protocols can transfer a defined loss exposure, but an inventory entry or audit badge does not establish that cover is available or that a future claim will be paid.

    12 min read

  • Emergency Pause Circuit Breakers: Scope, Guardians and Recovery Tests

    Operations

    Emergency Pause Circuit Breakers: Scope, Guardians and Recovery Tests

    A pause flag works only where the application checks it and exposes an authorized way to change it. Emergency pause circuit breakers need an explicit operation scope, a guardian model and a tested recovery path before they can support incident containment.

    12 min read

  • Smart Contract Security Glossary: Definitions That Point to Evidence

    Audit deliverables

    Smart Contract Security Glossary: Definitions That Point to Evidence

    Security terms become useful when their scope and evidence are clear. This smart contract security glossary defines the objects, authorities and methods readers encounter in reports, then points to the next technical check instead of treating a label as proof of safety.

    14 min read

DeFi Security Alliance

Founder

Dan Daniloff, founder of DeFi Security Alliance
Dan Daniloff, founder of DeFi Security Alliance.

For security companies

Apply with public reports and a clear account of your specializations. The application page explains the evidence packet and published review terms.

Apply to join the alliance Directory methodology

DeFi Security Alliance guidance

Questions about commissioning an audit

Scope, timing and evidence for a review of your release.

Reviewed

What is a smart contract audit, and what does it review?

A smart contract audit is a scoped review of a specific code version. Reviewers examine access control and state or accounting logic. They also assess external calls and integrations as well as upgrade paths and chain-specific assumptions. A useful report identifies the reviewed scope and commit. It records each finding with its severity and affected code. The report also states the remediation status. See the smart contract audit reports collected by DSA.

Does a smart contract audit guarantee that a DeFi protocol is secure?

No. An audit reduces risk within the agreed scope, but it is not a security guarantee. Code outside the scope, later changes, a deployed version that differs from the reviewed commit, privileged key handling and economic or oracle assumptions may remain outside the review. Before launch, confirm that the deployed code matches the audited version and that reported fixes were retested.

When should a project schedule a smart contract audit?

Schedule an audit after the intended release is feature complete and its build instructions, tests and documentation are ready, but before production deployment. Leave enough time to fix findings and complete a remediation review. Significant code changes after the audit may require additional review.

How do I choose a smart contract auditing company?

Match the auditor's evidence to your technology and risk profile. Review public reports for experience with your chain and language as well as your protocol type. Look for explicit scopes and commit identifiers. Check the severity definitions and remediation results. Confirm who will review the code and what is excluded. Ask about the schedule and retest terms. Start with the DSA auditor directory.

What should I send when requesting an audit quote?

Start with a bounded and reproducible scope:

  • Repository, branch or commit and contracts in scope
  • Languages, chains and architecture notes
  • Build/test commands and earlier reports
  • Privileged roles, threat assumptions and deployment plan
  • Preferred review window and retest needs

Begin with the audit request form.

How much does a smart contract audit cost?

There is no reliable flat price for every smart contract audit. Cost depends on scope size and complexity, language and chain, integrations, code maturity, schedule, reviewer count and whether remediation review is included. Compare written proposals by scope, exclusions, deliverables and retest terms instead of headline price alone.

DeFi Security Alliance guidance

Questions about joining DSA

Public application terms for security companies.

Reviewed

Who can apply to join DeFi Security Alliance?

Smart contract security and auditing companies with a verifiable public track record can apply. An application should identify the organization and its technical specializations. It should also link to public audit reports and other relevant security work. Submit the current evidence through the membership application.

How often is DSA membership reviewed?

The published membership policy calls for annual review. A dated badge does not by itself establish that a technical reassessment occurred. See the badge information and request the current membership terms.

Is DSA membership free?

DSA does not publish a fixed public membership fee. Request the current terms through the membership application or contact form before relying on any cost assumption.

What does DSA membership provide?

A member can receive an alliance directory profile and membership badge. Members can share relevant security work and participate in the alliance's knowledge exchange. Available programs and tools can change. Review the current Audit Builder information and contact DSA for the terms that apply to a new member.