What decides whether a bug gets caught — depth of review, who reads your code, whether they’ve seen your kind of protocol, what happens after the report — never shows up in a quote. Valyn runs a real competitive process across firms and lays it all side by side, so you can pick the audit most likely to catch what matters.
| Line item | Firm A | Firm B | Firm C |
|---|---|---|---|
| Quoted price | $13,500 | $10,000 | $15,000 |
| Calendar duration | 4 days | 1 week | 1 week |
| Auditor-days on your code | 12 | 10 | 15 |
| Team composition | 2 senior, 1 associate | 2 associates | 3 senior |
| Lead's relevant history | 2 prior AMM audits | None on record | 6 prior AMM audits |
| Auditor profiles | immunefi/abc,hackenproof/def,immunefi/ghi | Not shared | hackenproof/xyz,immunefi/uvw,hackenproof/rst |
| Methodology provided | High-level only | None given | Full, in writing |
| Audit type | Manual + AI | Manual + AI | Manual + fuzzing + AI |
| Coverage beyond contracts | Contracts only | Contracts only | Incl. infra & keys |
| Re-testing after fixes | One round | Billed separately | Unlimited |
| Earliest start | In 2 days | Next week | In 1 day |
Illustrative example built from a typical bid spread. Real comparisons use your scope and live quotes.
And this costs you nothing. Every quote, the full comparison sheet, and our honest read on which one to take. Book none of them and you still owe us nothing.
Request quotesYou'll buy a few audits. Firms price them every week. Without the market rate for your code, you can't spot a padded quote — or negotiate one down.
Same code, but every firm includes different work and means something different by "three weeks." Line them up and price is the only thing you can see — the worst thing to choose on.
Firms sell the brand; you get whoever's free that sprint. An auditor who's broken code like yours and one who's never seen it cost the same — and find very different things.
Repo, line count, architecture, target date, budget. One form — not eight sales threads.
A loose scope means loose quotes. We tighten it first, so every firm prices the same work.
The same scope goes to every firm that fits your code and timeline. Same inputs — so the numbers actually mean something.
Price, auditor-days, seniority, track record, what's included, real start date. One sheet, one format.
Take the best fit, or split scope across two firms. We tell you where the extra money buys something and where it doesn't.
Timelines, terms, start dates. Done when you're on the calendar with the right team — not at the intro.
Founders compare price, turnaround, and brand — and skip the things that actually decide whether a bug gets caught. We put these next to every quote.
A real plan — scoping, threat modelling, manual review, testing, fix verification. If they can't describe how before starting, the quality is a guess.
The named auditors, their seniority, and whether they've seen protocols like yours. The individuals matter more than the brand.
Recent public reports, read for depth: findings beyond tool output, justified severities, root-cause fixes. How they explain a bug says the most.
Many attacks start outside the contracts. We check whether frontend, infra, and key management are in scope — or a gap you didn't budget for.
Manual logic review and fuzzing on the risky parts, plus how much re-testing after fixes is included — versus mostly automated output.
Fix verification, re-checks, and support when you ship an update. A good engagement ends when the issues are resolved, not when the PDF lands.
Send us your scope and we’ll come back with normalized quotes from firms