Your dependencies have secrets.
The libraries you ship contain silently patched vulnerabilities that were never publicly disclosed. Your users inherit the exposure. You inherit the liability.
You are shipping code that contains vulnerabilities you were never told about.
Your protocol depends on upstream libraries maintained by other teams. When those teams find and fix security vulnerabilities, the fix does not always come with a disclosure. According to Chainguard’s 2024 analysis, more than 50% of open-source security fixes are never disclosed publicly. The vulnerability gets fixed. The record of it never reaches you.
This means you are running code with known security defects that the upstream maintainer fixed but never told you about. Your dependency manager shows you are up to date. Your audit shows a clean bill of health. Neither tool checks for fixes that were deliberately hidden from the public record.
The problem compounds with forks. If you forked a codebase eighteen months ago, every silent patch merged upstream since then is a vulnerability in your deployment that you do not know exists. Your users are exposed. Your TVL is at risk. And you have no way to measure the gap using any public data source.
One upstream bug. Four forks. Thirteen months. $31.6 million gone.
██████████‘s exchange rate manipulation bug was exploited across four different forks over a thirteen-month window. Total losses: $31.6 million. The vulnerability was known after the first exploit. Three more forks — ████████, ██████, and ████████████ — running the same upstream code were hit afterward because the fix was never publicly disclosed and no downstream notification was issued.
If you are running a fork, this is your risk profile. The upstream maintainer patches silently. You never pull the fix because you never knew it existed. Months later, a researcher or attacker finds the same vulnerability in your deployment. Your users lose funds. Your protocol loses credibility. And the upstream fix was sitting in a commit history the entire time.
This is not a hypothetical. This is the documented cost of shipping code without upstream visibility.
This is not an isolated pattern. Our pipeline has detected the same concealment behavior across every category of infrastructure we monitor.
detected across
9 ecosystems
Our pipeline continuously monitors upstream repositories for silent security patches. The cases above are representative. The full database is larger. Check if your project is in it.
The Dependency Scan is a one-time analysis of every upstream library in your protocol’s dependency chain. We identify every security fix that was merged without public disclosure and map the exposure back to your deployment.
The output is a complete inventory of what you are actually running versus what the public record says you are running. A protocol that appears fully patched against public databases may be carrying dozens of unpatched vulnerabilities that upstream maintainers fixed silently and never told anyone about.
For forked codebases, the scan includes every silent patch merged to the upstream repository since your fork date. That delta is the gap between what you shipped and what the original maintainers know.
What You Receive
Full upstream dependency map. Silent patch exposure report with severity breakdown. Per-finding vulnerability class and affected code path. Downstream fork impact analysis. Remediation priority list. Delivered as a structured report with raw data appendix.
Upstream Watch is continuous monitoring of every dependency in your stack. When our pipeline detects a silent security patch in any library you depend on, you receive an alert within 48 hours of detection. Not 48 hours after disclosure — there is no disclosure. 48 hours after the fix is merged.
Each alert includes the affected dependency, the commit containing the fix, the vulnerability class, severity rating, and whether the fix is present in your current deployment. Your engineering team can integrate alerts directly into CI/CD via our API, or review them through a web dashboard.
The service also tracks concealment patterns over time. An upstream project that has silently patched 14 critical vulnerabilities in the past year without a single CVE is a different dependency risk than one that discloses consistently. That pattern data informs which dependencies deserve the most scrutiny and which upstream relationships carry hidden risk.
What You Receive
Everything in Dependency Scan, plus: continuous silent patch detection feed. 48-hour detection-to-alert SLA. API integration for CI/CD pipelines. Dashboard with filtering and export. Concealment pattern histories per upstream project. Dependency risk scoring.
Full Advisory is the complete service. It includes everything in Upstream Watch, plus dedicated analyst support, remediation guidance for each finding, quarterly security reviews of your full dependency chain, and investor-ready risk reporting.
When a silent patch is detected in your dependency chain, you do not just get an alert — you get a recommended remediation path, an assessment of whether the vulnerability is exploitable in your specific deployment context, and guidance on disclosure timing if you choose to notify your users.
Quarterly reviews provide a structured assessment of how your upstream risk profile has changed. New dependencies, abandoned projects, maintainers with deteriorating disclosure practices — all of it tracked and reported in a format your board and your investors can understand.
What You Receive
Everything in Upstream Watch, plus: dedicated analyst for your protocol. Remediation guidance per finding. Quarterly dependency chain security reviews. Investor-ready risk reports. Insurance-readiness assessment for DeFi coverage applications. Custom SLAs and reporting cadence.
One exploit costs more than a decade of monitoring.
At 3 basis points on $200M TVL, Upstream Watch costs $60,000 per year. A single exploit on one fork of ██████████ cost an average of $7.9 million per incident. The monitoring cost is 0.76% of the average exploit loss. One prevented exploit pays for the service for over 130 years.
The calculation is not theoretical. Four forks of the same codebase lost a combined $31.6 million to the same bug over 13 months. Three of those exploits were preventable with upstream visibility. If any of those three forks had been running Upstream Watch, they would have known about the vulnerability within 48 hours of the upstream fix — months before the exploit.
This is not a technology purchase. It is a data correction for a blind spot that is structurally guaranteed to exist in your current dependency management.
The maintainers you depend on are financially rewarded for not telling you about vulnerabilities.
Public disclosure costs money. It triggers downstream audit requirements, insurance repricing, risk assessor unstaking, and user concern. Silence costs nothing. The upstream maintainer fixes the bug quietly and moves on. Your protocol continues running vulnerable code. The maintainer’s reputation stays clean.
Our lab has documented this pattern across nine ecosystems with a combined 0.44% disclosure rate. That means for every vulnerability an upstream project tells you about, there are approximately 227 they do not.
Audits do not close this gap. 70% of 2024 exploits hit audited contracts. An audit reviews the code at a point in time. A silent patch happens after the audit, in upstream code the auditor never reviewed and your team never saw. The audit remains valid on paper while the code it reviewed is no longer what you are running.
The only way to close this gap is independent monitoring of upstream commit behavior. That is what we build.
Get out your calculator.
Every rate is published. Type your number. The math is instant.
Dependency Scan
- Full upstream dependency map
- Silent patch exposure report
- Severity breakdown per finding
- Downstream fork impact analysis
Upstream Watch
- Everything in Dependency Scan
- Continuous silent patch feed
- 48-hour detection SLA
- API integration for CI/CD
- Concealment pattern histories
Full Advisory
- Everything in Upstream Watch
- Dedicated analyst
- Remediation guidance
- Quarterly security reviews
- Investor-ready reporting
Annual — TVL locked at signing. If you grow $100M mid-contract, your rate stays the same until renewal.
Silent Patch Access
- Full silent patch database
- Search by project, ecosystem, CWE
- Supplement audit findings
- Historical concealment data
Audit Overlay
- Targeted scan for audit target
- Upstream dependency exposure
- Client-ready findings appendix
- Silent patch delta report
Integrated Feed
- Everything in Dataset Access
- API for workflow integration
- White-label capability
- Dedicated analyst
- Priority SLA
Annual — billings locked at signing. Growth during the contract doesn’t change your rate until renewal.
Pre-Launch Scan
- Dependency exposure report
- Silent patches in your stack
- Risk profile before launch
- Board-ready summary
Continuous Monitor
- Everything in Pre-Launch Scan
- Ongoing silent patch alerts
- 48-hour detection SLA
- API access
- Concealment pattern data
Full Advisory
- Everything in Continuous Monitor
- Quarterly security reviews
- Investor-ready risk reports
- Dedicated analyst
- Insurance-readiness assessment
Annual — round size locked at signing. Raise a bigger round mid-contract? Same rate until renewal.
Portfolio Screen
- Exposure scan across holdings
- Per-protocol risk breakdown
- Silent patch count per position
- LP-ready summary
Due Diligence Feed
- Everything in Portfolio Screen
- Continuous monitoring of holdings
- Pre-investment protocol scans
- Real-time exposure alerts
- API access
Full Intelligence
- Everything in Due Diligence Feed
- Quarterly portfolio briefings
- IC-ready risk reports
- Dedicated analyst
- Custom coverage by thesis
Annual — AUM locked at signing. Portfolio growth mid-contract doesn’t change your rate until renewal.
Risk Intelligence Feed
- Continuous silent patch detections
- Protocol-level exposure mapping
- Severity ratings per finding
- Concealment pattern histories
- API access for model integration
- 48-hour detection SLA
Portfolio Assessment
- Full portfolio exposure analysis
- Per-protocol risk report
- Public posture vs. actual patch status
- Upstream dependency mapping
- Premium repricing recommendations
- Structured data appendix
Underwriting Intelligence
- Everything in Risk Intelligence Feed
- Pre-binding coverage assessments
- Real-time exposure change alerts
- Quarterly underwriting briefings
- Custom SLAs and reporting
- Dedicated analyst
Annual — coverage volume locked at signing. Book growth mid-contract doesn’t change your rate until renewal.
Public interest. No charge.
Investigative support. No charge.
- Concealment timelines with commit-level precision
- Evidence of knowledge prior to exploit events
- Downstream exposure mapping for affected parties
- Expert consultation on technical findings
- Chain-of-custody-ready documentation
What you get. What we don’t do.
What You Get
- Silent patch detections across your full dependency chain
- Severity-rated findings with evidence
- Disclosure behavior scoring per upstream project
- Fork drift reports showing where you’ve fallen behind
- Coverage across 9+ ecosystems and growing
- 48-hour detection-to-delivery SLA
What We Don’t Do
- Perform penetration testing or active exploitation
- Provide legal advice or regulatory representation
- Guarantee specific coverage or pricing outcomes
- Disclose raw vulnerability details to non-subscribers
- Operate as a bug bounty platform or triage service
- Accept vendor payment to suppress findings
Ship code with complete data.
Start with a Dependency Scan to see what your upstream libraries are hiding. Or go straight to continuous monitoring. Either way, you get data that does not exist in any public database.
Initial consultation free · All prices published · No sales theater
