Your models are missing half the data.
More than 50% of open-source security fixes are never publicly disclosed. Your decisions rely on databases built from the other half.
You price risk from databases that are systematically incomplete.
Public CVE databases, audit reports, and disclosed incident histories account for less than half of actual security fixes. According to Chainguard’s 2024 analysis, more than 50% of open-source security fixes are never disclosed publicly. No CVE. No advisory. No changelog entry. The fix ships as a routine update and the vulnerability record never enters your data.
This means every premium priced, every risk assessed, every coverage decision made, every investment thesis validated, and every audit delivered is built on an incomplete foundation.
The problem is structural, not accidental. Protocols have a direct financial incentive to hide vulnerabilities. A known CVE causes risk assessors to reprice. Silence keeps costs low. The entire market subsidizes the silence.
Same bug, four exploits, thirteen months, $31.6 million.
Compound V2’s exchange rate manipulation bug was exploited across four different protocol forks over a thirteen-month window. Total losses: $31.6 million. The vulnerability was known after the first exploit. Three more protocols were hit because no CVE was filed and no downstream notification was issued.
One piece of upstream intelligence would have prevented three of those incidents. Whether you are the underwriter paying claims, the auditor who cleared the protocol, the investor holding the token, or the maintainer running the fork — the missing data cost you.
Get out your calculator.
Every rate is published. Type your number. The math is instant.
Dependency Scan
- Full upstream dependency map
- Silent patch exposure report
- Severity breakdown per finding
- Downstream fork impact analysis
Upstream Watch
- Everything in Dependency Scan
- Continuous silent patch feed
- 48-hour detection SLA
- API integration for CI/CD
- Concealment pattern histories
Full Advisory
- Everything in Upstream Watch
- Dedicated analyst
- Remediation guidance
- Quarterly security reviews
- Investor-ready reporting
Annual — volume locked at signing. If you grow $100M mid-contract, your rate stays the same until renewal.
Silent Patch Access
- Full silent patch database
- Search by project, ecosystem, CWE
- Supplement audit findings
- Historical concealment data
Audit Overlay
- Targeted scan for audit target
- Upstream dependency exposure
- Client-ready findings appendix
- Silent patch delta report
Integrated Feed
- Everything in Dataset Access
- API for workflow integration
- White-label capability
- Dedicated analyst
- Priority SLA
Annual — billings locked at signing. Growth during the contract doesn’t change your rate until renewal.
Pre-Launch Scan
- Dependency exposure report
- Silent patches in your stack
- Risk profile before launch
- Board-ready summary
Continuous Monitor
- Everything in Pre-Launch Scan
- Ongoing silent patch alerts
- 48-hour detection SLA
- API access
- Concealment pattern data
Full Advisory
- Everything in Continuous Monitor
- Quarterly security reviews
- Investor-ready risk reports
- Dedicated analyst
- Insurance-readiness assessment
Annual — round size locked at signing. Raise a bigger round mid-contract? Same rate until renewal.
Portfolio Screen
- Exposure scan across holdings
- Per-protocol risk breakdown
- Silent patch count per position
- LP-ready summary
Due Diligence Feed
- Everything in Portfolio Screen
- Continuous monitoring of holdings
- Pre-investment protocol scans
- Real-time exposure alerts
- API access
Full Intelligence
- Everything in Due Diligence Feed
- Quarterly portfolio briefings
- IC-ready risk reports
- Dedicated analyst
- Custom coverage by thesis
Annual — AUM locked at signing. Portfolio growth mid-contract doesn’t change your rate until renewal.
Risk Intelligence Feed
- Continuous silent patch detections
- Protocol-level exposure mapping
- Severity ratings per finding
- Concealment pattern histories
- API access for model integration
- 48-hour detection SLA
Portfolio Assessment
- Full portfolio exposure analysis
- Per-protocol risk report
- Public posture vs. actual patch status
- Upstream dependency mapping
- Premium repricing recommendations
- Structured data appendix
Underwriting Intelligence
- Everything in Risk Intelligence Feed
- Pre-binding coverage assessments
- Real-time exposure change alerts
- Quarterly underwriting briefings
- Custom SLAs and reporting
- Dedicated analyst
Annual — coverage volume locked at signing. Book growth mid-contract doesn’t change your rate until renewal.
Public interest. No charge.
Investigative support. No charge.
- Concealment timelines with commit-level precision
- Evidence of knowledge prior to exploit events
- Downstream exposure mapping for affected parties
- Expert consultation on technical findings
- Chain-of-custody-ready documentation
What the feed covers.
We Monitor
- Consensus engines (CometBFT, go-ethereum, forks)
- Smart contract frameworks and their forks
- DeFi protocol dependencies and upstream libraries
- Authentication and secrets management platforms
- Cross-chain bridge infrastructure
- Layer-1 and Layer-2 blockchain codebases
We Do Not
- Perform penetration testing or active exploitation
- Provide legal advice or regulatory representation
- Guarantee specific coverage or pricing outcomes
- Disclose raw vulnerability details to non-subscribers
- Operate as a bug bounty platform or triage service
- Accept vendor payment to suppress findings
Price risk from complete data.
Pick your tab. Type your number. If the math makes sense, reach out. If it doesn’t, you weren’t the customer.
Initial consultation free · All prices published · No sales theater
