Telegram
Audit sourcing for protocols

Your audit is the last thing between your code and an attacker. Choose it well.

What decides whether a bug gets caught — depth of review, who reads your code, whether they’ve seen your kind of protocol, what happens after the report — never shows up in a quote. Valyn runs a real competitive process across firms and lays it all side by side, so you can pick the audit most likely to catch what matters.

Example comparison · $10–15k engagement
Line itemFirm AFirm BFirm C
Quoted price$13,500$10,000$15,000
Calendar duration4 days1 week1 week
Auditor-days on your code121015
Team composition2 senior, 1 associate2 associates3 senior
Lead's relevant history2 prior AMM auditsNone on record6 prior AMM audits
Auditor profilesimmunefi/abc,hackenproof/def,immunefi/ghiNot sharedhackenproof/xyz,immunefi/uvw,hackenproof/rst
Methodology providedHigh-level onlyNone givenFull, in writing
Audit typeManual + AIManual + AIManual + fuzzing + AI
Coverage beyond contractsContracts onlyContracts onlyIncl. infra & keys
Re-testing after fixesOne roundBilled separatelyUnlimited
Earliest startIn 2 daysNext weekIn 1 day
Firm A
Quoted price
$13,500
Calendar duration
4 days
Auditor-days on your code
12
Team composition
2 senior, 1 associate
Lead's relevant history
2 prior AMM audits
Methodology provided
High-level only
Audit type
Manual + AI
Coverage beyond contracts
Contracts only
Re-testing after fixes
One round
Earliest start
In 2 days
Firm B
Quoted price
$10,000
Calendar duration
1 week
Auditor-days on your code
10
Team composition
2 associates
Lead's relevant history
None on record
Auditor profiles
Not shared
Methodology provided
None given
Audit type
Manual + AI
Coverage beyond contracts
Contracts only
Re-testing after fixes
Billed separately
Earliest start
Next week
Firm C
Quoted price
$15,000
Calendar duration
1 week
Auditor-days on your code
15
Team composition
3 senior
Lead's relevant history
6 prior AMM audits
Methodology provided
Full, in writing
Audit type
Manual + fuzzing + AI
Coverage beyond contracts
Incl. infra & keys
Re-testing after fixes
Unlimited
Earliest start
In 1 day
Firm B is the cheapest quote — and the worst audit on the sheet. No methodology, no shared auditor profiles, mostly AI with no senior on the logic, and fix re-testing billed on top. Firm C looks like the expensive option and is the one most likely to catch what matters.

Illustrative example built from a typical bid spread. Real comparisons use your scope and live quotes.

And this costs you nothing. Every quote, the full comparison sheet, and our honest read on which one to take. Book none of them and you still owe us nothing.

Request quotes
The problem

Right now, protocols buy audits from their DMs.

No benchmark, no leverage

You'll buy a few audits. Firms price them every week. Without the market rate for your code, you can't spot a padded quote — or negotiate one down.

Quotes that can't be compared

Same code, but every firm includes different work and means something different by "three weeks." Line them up and price is the only thing you can see — the worst thing to choose on.

The best firm isn't the best team

Firms sell the brand; you get whoever's free that sprint. An auditor who's broken code like yours and one who's never seen it cost the same — and find very different things.

How it works

One intake. A real competitive process. A decision you can defend.

01

Send us the scope once

Repo, line count, architecture, target date, budget. One form — not eight sales threads.

02

We pressure-test it

A loose scope means loose quotes. We tighten it first, so every firm prices the same work.

03

We run the bid

The same scope goes to every firm that fits your code and timeline. Same inputs — so the numbers actually mean something.

04

We normalize every quote

Price, auditor-days, seniority, track record, what's included, real start date. One sheet, one format.

05

You choose — or mix

Take the best fit, or split scope across two firms. We tell you where the extra money buys something and where it doesn't.

06

We stay until you're booked

Timelines, terms, start dates. Done when you're on the calendar with the right team — not at the intro.

How the audit is run

Price is the easy part. How the audit is actually run is what matters.

Founders compare price, turnaround, and brand — and skip the things that actually decide whether a bug gets caught. We put these next to every quote.

Methodology, in writing

A real plan — scoping, threat modelling, manual review, testing, fix verification. If they can't describe how before starting, the quality is a guess.

Who's actually on your code

The named auditors, their seniority, and whether they've seen protocols like yours. The individuals matter more than the brand.

Proof of work

Recent public reports, read for depth: findings beyond tool output, justified severities, root-cause fixes. How they explain a bug says the most.

What's actually covered

Many attacks start outside the contracts. We check whether frontend, infra, and key management are in scope — or a gap you didn't budget for.

Depth of testing

Manual logic review and fuzzing on the risky parts, plus how much re-testing after fixes is included — versus mostly automated output.

What happens after

Fix verification, re-checks, and support when you ship an update. A good engagement ends when the issues are resolved, not when the PDF lands.

Start here

Send us your scope and we’ll come back with normalized quotes from firms