Pharos Production

$
$
Pharos Production Inc. is a software engineering company founded in 2013, with headquarters in Las Vegas and an engineering office in Kyiv. It audits Solidity, Vyper, Rust and FunC smart contracts and runs penetration tests, cloud reviews and source code audits for DeFi, crypto exchange and fintech teams. The firm runs a four-stage audit process, publishes price bands ahead of the first call, and holds a 5.0 rating on Clutch across 107 reviews.

Website: https://pharosproduction.com/
Left
Right

DeFi Security Alliance member profile

Pharos Production at a glance

Pharos Production Inc. is a software engineering company founded in 2013 with headquarters in Las Vegas and an engineering office in Kyiv, listed in the DeFi Security Alliance directory as a smart contract audit and cybersecurity provider.

Founded
2013
Legal entities
Pharos Production Inc. (Nevada, USA) and TOV Pharos Production (Kyiv, Ukraine)
Team
90+ engineers
Audit languages
Solidity, Vyper, Rust (Solana and CosmWasm), FunC (TON)
Turnaround
Single contract audit in 5 to 10 business days, a multi-contract system in 2 to 4 weeks, emergency start within 48 hours
Published price bands
Single contract audit from $8,000, DeFi protocol audit $25,000 to $60,000
Report policy
Reports are delivered to the client under NDA. The firm keeps no public archive and offers a sample report on request.
Rating
5.0 on Clutch across 107 reviews, counted . Clutch Top Blockchain Company 2026 award badge held by Pharos Production
Contact
hello@pharosproduction.com or the DSA request form

Who Pharos Production is

Pharos Production was founded in 2013 as a generalist engineering firm working across AI, FinTech and Web3 projects. Its security practice sits next to its product teams rather than as a separate business, and the firm sells audits and other security work on their own, without a development contract attached. The company operates as two registered entities: Pharos Production Inc. in Nevada, registry number E0342392013-7, and TOV Pharos Production in Ukraine, EDRPOU 42559443, both listed on the firm's contacts page. The Nevada office is at 5348 Vegas Dr, Las Vegas, NV 89108, and the Kyiv office is at 44-B Eugene Konovalets Str., Suite 201, Kyiv 01133.

The firm's founder is Dr. Dmytro Nasyrov, listed as Founder and CTO, with a PhD in Artificial Intelligence and 23 years of engineering experience. He also lectures at Igor Sikorsky Kyiv Polytechnic Institute, according to his profile page. The team page names two external academic advisors, Victor Sineglazov for AI and Olena Zaichenko for FinTech, and identifies both as advisors rather than employees.

Not the same company as

  • Pharos Systems, which sells print management software
  • Pharos Energy, an oil and gas company
  • Pharos Media Productions and Pharos Post Production, both film companies
  • Pharos Aerospace

This profile covers Pharos Production Inc. of Las Vegas and Kyiv only.

Position in the DSA directory

Pharos Production is one of 24 profiles in the DeFi Security Alliance member directory. Membership decisions on this site are based on public, checkable evidence of smart contract security work.

Smart contract audit services

The firm's audit page describes a Solidity audit and Rust program review service built around static analysis, manual line-by-line review, gas optimization and formal verification. The page states: "Full static and manual analysis of your Solidity or Rust code."

Scope

The stated scope covers Solidity and Vyper contracts on EVM networks, Rust programs on Solana and CosmWasm, and FunC contracts on TON. Typical audit objects for that scope are DeFi protocols such as lending markets, decentralized exchanges, staking systems and vaults, ERC-20, ERC-721 and ERC-1155 tokens, upgradeable proxies, governance and multisig flows, bridges, wallets and exchange back ends.

Four-stage process

  1. Automated scanning with Slither, Mythril and Echidna
  2. Manual line-by-line review and threat modeling
  3. Gas optimization and profiling with Foundry's forge snapshot and the Hardhat Gas Reporter
  4. Formal verification for high-value contracts, using tools the firm's research names, Certora and Halmos

Deliverables

The audit page lists a severity-ranked report with findings classified Critical, High, Medium, Low or Informational, proof-of-concept exploits for confirmed issues, remediation guidance, a gas profile and a post-remediation re-verification pass.

What the firm reports about its own audits

The audit page's stat block states a median of 27 findings per audit, 71% of audits with at least one critical or high finding, and a median audit cost of $8,000. The firm counts 50 or more formal security engagements since 2018, the figure this profile uses throughout.

Supported networks and languages

Networks listed on the Pharos Production audit page, grouped by execution environment (retrieved )
Environment Networks Audit language
EVM Ethereum, Arbitrum, Optimism, Base, Polygon, BSC, Avalanche, Fantom, Celo Solidity, Vyper
Solana and CosmWasm Solana, Sei, Cosmos Rust
TON TON FunC
Other listed networks Polkadot, NEAR, Aptos, Sui, Hedera, Stellar, Tron, MultiversX, Algorand, Tezos, Flow, Ontology, VeChain, EOS, IOTA, Neo, Hyperledger, Corda, IPFS Not stated as an audit language

The chain list on the site is broader than the audit language scope. Move, the language used on Aptos and Sui, and Bitcoin script are not named as audit languages on the audit page, even though those networks appear in the wider chain list. A team scoping non-EVM, non-Solana and non-TON work should ask the firm directly before assuming coverage. The DSA's cybersecurity company ranking sets this scope next to nine other security firms.

Beyond the contracts: penetration testing, cloud and source code audits

The firm's cybersecurity services page lists work beyond smart contracts.

Web3 penetration testing and application security

Listed services include web, mobile and API penetration testing, threat modeling and secure architecture review. For a Web3 team that maps to the front end, wallet and exchange or custody back ends, off-chain services, relayers and the points where oracles are integrated, which is where a web3 pentest usually starts.

Cloud security audit services

The page lists configuration review on AWS, GCP and Azure, container and Kubernetes security checks, and identity and secrets management review.

Source code audit services

Source code review is listed with Semgrep, CodeQL and Snyk, alongside secure development lifecycle work for teams shipping outside the audit engagement itself.

Frameworks and tooling

The page names the OWASP Top 10, the OWASP Testing Guide and OWASP ASVS, the NIST CSF 2.0, NIST SSDF SP 800-218, MITRE ATT&CK and PTES as reference frameworks, with findings ranked by CVSS 3.1. Listed tools include Burp Suite Pro, OWASP ZAP, Trivy, Prowler, ScoutSuite, Pacu and Metasploit.

Compliance readiness

The page describes a team aligned with ISO 27001:2022, readiness assessments for SOC 2 Type II, HIPAA and PCI DSS, GDPR compliance, and evidence preparation for accredited auditors. The firm states "aligned", not "certified", and publishes no certificate number for these frameworks. The firm recommends threat modeling over a penetration test for greenfield work, and states that it declines compliance theater.

Published pricing and turnaround

Pharos Production is one of the few firms in the directory that prints its price bands before the first call, on the audit page and on the cybersecurity services page.

Price bands and lead times published by Pharos Production (retrieved )
Engagement Published band Lead time
Single smart contract auditFrom $8,0005 to 10 business days
DeFi protocol audit (multi-contract, governance, staking, proxies)$25,000 to $60,0002 to 4 weeks
Gas optimizationFrom $5,000 per contractRuns with the audit
Web or API penetration test
2 to 4 weeks
Cloud configuration review
1 to 2 weeks
Source code audit$30,000 to
4 to 8 weeks with a remediation cycle
Hourly rate$50 to $99Not applicable
Emergency startWithin 48 hoursNot applicable

The published bands move with lines of code, the number of contracts in scope, proxy patterns, external integrations and the number of re-audit rounds a client needs. For a like-for-like comparison, see the DSA's pricing explainer and the Audit Builder for a scoped quote from multiple members.

Track record and evidence you can check

The firm's own delivery counters state: founded in 2013, 110+ apps delivered, 200+ clients, 50 or more formal security engagements since 2018, 484 contracts deployed to mainnet with zero critical vulnerabilities, per its Web3 industry page, over $500M in cumulative TVL across protocols it built, and 30+ blockchain projects. Contracts that Pharos Production builds are audited externally before mainnet, which keeps the build and audit roles separate for that work.

One published case study, the Ludo reputation platform, states over 2 million wallets scored, more than 10,000 blockchain events processed per second, 15 or more networks and 50 or more integrated partners.

The firm states 342 verified reviews across five platforms, and 5.0 on Clutch across 107 reviews counted , with an 87% multi-year client retention figure per Clutch. Awards listed include the Top Blockchain Company 2026 badge shown above, Clutch Global Leader Spring 2025, Top Smart Contract Development Ukraine 2025, a GoodFirms Review Award 2025 and The Manifest Top Blockchain Company Ukraine 2024.

The firm's GitHub organization, pharosproduction, lists 112 repositories, most of them infrastructure tutorials such as Apache Pulsar on Kubernetes, Kafka, MongoDB with Ansible and Elixir examples, rather than audit artifacts. The firm's editorial policy states no ghost-written technical content, no material whose primary author is a large language model, and inline citations on numerical claims.

What is not public

Pharos Production keeps no public archive of audit reports; reports stay under NDA. A team evaluating the firm can ask for a redacted sample report, two references, and the commit hash and scope statement of a past engagement. See the DSA guides on how to read an audit report and how to spot a fake audit report for what to check.

How to request an audit from Pharos Production

  1. Prepare the scope: repository and commit hash, contract list, target networks, external dependencies, deadline, and whether a re-audit round is needed.
  2. Send the request through the DSA's request form, or write to hello@pharosproduction.com. An NDA option is available on the firm's contact form, and the firm lists phone numbers +1 (702) 359-6297 and +380 (99) 776-2791.
  3. Expect a first reply within 4 hours and a detailed estimate within 48 hours, per the firm's stated SLA.
  4. Compare the quote against at least two other DSA members on the same scope before committing.

The DSA request form does not create a contract or guarantee availability.

Compare with other DSA members

The directory holds 24 profiles at /members. The audit company analysis pages and the cybersecurity company ranking, where Pharos Production sits at position 1 for being the only firm of ten that publishes prices for both on-chain and off-chain work, help place this profile next to the rest. The tools hub lists further comparison resources.

Shortlist Pharos Production when a project wants one team for contracts plus cloud, pentest and compliance work, when fixed price bands matter before the first call, or when EU regulatory engineering is in scope, covering MiCA, DORA, NIS2, CRA and PSD3. Pick another member when a public report archive is a requirement, or when the scope is Move or Bitcoin script work that the audit page does not name.

Verification notes

Figures in this profile were retrieved on from pharosproduction.com, Clutch and GitHub. The DeFi Security Alliance does not audit these claims itself, and registry numbers were not checked against the Nevada or Ukrainian company registries. Report outdated information through the request form and choose "Report outdated information".

DeFi Security Alliance member profile

Frequently asked questions

Common questions about Pharos Production's scope, pricing and verification status.

Reviewed

Is Pharos Production a smart contract audit company or a development company?

Both. Pharos Production is a software engineering company founded in 2013 that runs a security practice next to its product teams. It sells audits, penetration tests and other security services on their own, without requiring a separate development contract.

Which languages and networks does Pharos Production audit?

The firm's audit page lists Solidity and Vyper for EVM networks such as Ethereum, Arbitrum, Optimism, Base, Polygon, BSC, Avalanche, Fantom and Celo, Rust for Solana and CosmWasm, and FunC for TON. Move, used on Aptos and Sui, and Bitcoin script are not named as audit languages on that page.

How much does a Pharos Production smart contract audit cost?

The audit page lists a single contract audit from $8,000 and a DeFi protocol audit at $25,000 to $60,000, with a median audit cost of $8,000 across its published stat block. See the pricing explainer for how these bands compare with other DSA members.

How long does a Pharos Production audit take?

A single contract audit takes 5 to 10 business days and a multi-contract DeFi protocol audit takes 2 to 4 weeks, per the firm's published timelines. The firm also lists an emergency start within 48 hours for time-sensitive engagements.

Does Pharos Production publish its audit reports?

No. Reports are delivered to the client under NDA and the firm keeps no public archive of completed audits. A team commissioning an audit can ask for a redacted sample report, two references and the commit hash and scope statement of a past engagement before signing.

Is Pharos Production the same as Pharos Systems or Pharos Energy?

No. This profile covers Pharos Production Inc., a software and security company headquartered in Las Vegas with an engineering office in Kyiv. Pharos Systems sells print management software, Pharos Energy is an oil and gas company, and neither is related to Pharos Production Inc.

Fill out the audit application form
We will contact the auditor and agree on the best audit conditions for you