Risk Intelligence · Silent Patch Detection

Who needs the data you’re missing?

Every audience has a different exposure. Every pricing model is published. Pick your role.

Intelligence Feed
Ecosystems9+ Monitored
Disclosure Rate0.44% Observed
Patterns52 Detected
OutputAPI + Reports
All PricingPublished

A vulnerability nobody is forced to disclose is a vulnerability that stays buried.

The people who can find concealed defects rarely have the standing to compel action. The people with enforcement authority rarely have the depth to know what they’re looking at. We sit in that gap — detecting what was quietly patched, proving when the vendor knew, and translating it into language a regulator, an underwriter, or a court can act on.

The underlying intelligence is a continuously updated feed of silent patches detected across open-source infrastructure — security fixes merged without public disclosure. One dataset. Six ways in. What changes is how you use the data and how it’s priced. A protocol maintainer measures risk against TVL. An auditor measures it against billings. An underwriter measures it against coverage volume. The risk surface differs, so the pricing model differs.

Every rate is published below. No sales calls. No “contact us for pricing.” Type your number and the math is instant.

Services · By Audience

Choose your risk surface.

For Maintainers

Your dependencies have secrets.

Upstream libraries you ship contain silently patched vulnerabilities. Your users inherit the exposure. We find what your dependency manager misses.

Priced on TVL · from 1 basis point
View Pricing & Intelligence →
For Attestors

Your audits have blind spots.

Upstream code changes after your audit. Silent patches ship between engagements. Your stamp of approval covers code that no longer matches what you reviewed.

Priced on annual billings · from 50 basis points
Coming Soon
For Founders

Your stack has risks you can’t see.

Before launch, before your next raise — know what your upstream dependencies are hiding. Investor-ready risk reporting built on data that doesn’t exist in any public database.

Priced on last round · from 2 basis points
Coming Soon
For Investors

Your diligence is incomplete.

The protocol’s audit is clean. Their public CVE count is zero. Their upstream dependency chain has 47 undisclosed fixes. Your thesis doesn’t account for what isn’t public.

Priced on crypto AUM · from 2 basis points
Coming Soon
For Underwriters

Your models are missing half the data.

DeFi insurance premiums priced against incomplete risk databases. Protocols are financially rewarded for hiding vulnerabilities from you. We close the gap.

Priced on coverage volume · from 3 basis points
Coming Soon
For Regulators

Full dataset. Unrestricted.

Securities regulators and financial supervisory authorities receive unrestricted access to the silent patch intelligence feed. The entities responsible for market transparency should not be gated from the data that enables it.

Supervisory bodies · unrestricted access
Request Regulatory Access →

Need more than a data feed?

The intelligence products above are continuous monitoring — automated detection, delivered via API and reports. Some situations require direct engagement: a full audit of a codebase’s concealment history, regulatory translation of a confirmed finding, breach forensics linking an exploit to the commit where the vendor knew, or coordinated disclosure management end-to-end.

Those engagements are scoped and priced separately.

View Advisory & Engagements →

The Landscape

The data behind the data.

$2.2BCrypto Losses, 2024Total value lost to exploits and hacks across the crypto ecosystem in a single calendar year. Many traced to upstream dependency failures.
70%Audited Contracts ExploitedOf 2024 crypto exploits targeted contracts that had passed a third-party audit. Audits do not catch upstream silent patches.
0.44%Observed Disclosure RateAcross 4,121 security patches analyzed in 9 ecosystems. For every fix disclosed, roughly 227 are not.
48.4%Market CAGR 2025–2029DeFi insurance market is scaling from $3.5B to $16.94B. As TVL grows, so does the cost of undisclosed upstream exposure.
Start Here

If you suspect something was buried.

Bring us the finding, the ghosted report, or the vendor whose disclosure record doesn’t add up. Tell us what you’re building, auditing, insuring, or investigating. We’ll tell you what the public data is missing.

Threshold review no charge · All prices published · No sales theater