A security pilot for regulated digital asset programs.
We work with your organization to assess your architecture and design against secure best practices and regulated standards. We bring the hands-on experience and lessons from hundreds of prior engagements to your digital assets program.
The Pilot Supports Architecture assessment Standards alignment Assurance engineering Smart contract audit Offchain pentests
A pilot structured to your needs.
Each module is self contained and pilot ready. Your pilot is designed with the modules most impactful for your roadmap.
For example A stablecoin issuer eight weeks from launch 3 of 5
A wholistic architecture & design assessment.
A digital asset system is mostly not onchain. It is a custody arrangement, an issuance path, a reserve ledger and the operators around it. The security model is concerned with every piece of the architecture.
- Custody and key ceremony Where the keys live, who holds what share, what a quorum actually requires in practice, and what happens the day somebody leaves or a device is lost.
- Privileged control surface Who can upgrade, pause, mint, set parameters or move funds, whether that authority sits behind a threshold or a single key, and how long it takes to use it.
- Every route value can take Issuance, redemption, reserve movement, and the oracles and bridges you inherit risk from. Most designs have more routes than originally intended, and the extra ones are rarely guarded.
- The operational security model How the organization actually runs the system: who approves what, how joiners and leavers are handled, and what single points of failure need to be diversified.
- Threat modeling A wholistic attack surface map, with every way that funds can be moved or the system can fail.
Review for standards and regulatory alignment.
MiCA, DORA and their equivalents make specific demands of custody, resilience, incident handling and third-party risk, and almost all of them are architectural rather than administrative.
Put into practice your legal and regulatory requirements at an engineering level.
- MiCA Safeguarding and segregation of client assets, the custody arrangement you have to be able to evidence, and the obligations that land on issuers of asset-referenced and e-money tokens. Most of it is decided by how the system holds keys.
- DORA ICT risk management, incident classification and the reporting window you are committing to, and the critical third parties you depend on. A reporting deadline you cannot meet is a design problem found at the worst moment.
- Control standards, mapped to the system CCSS levels, ISO 27001 and NIST CSF mapped onto the actual key ceremony and change control, plus NYDFS Part 500, the FCA regime, MAS and VARA where they apply and where two of them disagree.
Assurance built into how you ship.
A design is only as good as what holds it up between releases. We build the suites that prove your properties still hold, the gates that stop a change that breaks them, and the checks that confirm what reached the chain is what you staged.
- Invariant suites and fuzzing The properties the system must never violate, written as executable suites and driven by fuzz campaigns that look for the sequence nobody thought to write a test for.
- Engineering processes and review gates What has to be true before a change can merge: who approves, what is signed, which suites must pass, and what happens to the branch when one of them does not.
- Deployment operations and validation practices Storage layout, initialisers and roles checked against what was staged, then the onchain state read back and compared to what you intended to deploy.
A scoped Smart Contract audit.
Guardian performs a full audit of the contracts in scope, on the approach every Guardian engagement runs on: two competing teams over the same code in parallel, one driving expert manual analysis and one leveraging frontier AI, with an exhaustive invariant suite fuzzing underneath both.
- Read against the invariants State transitions, access control, accounting, upgrade paths, and the assumptions the contracts make about every protocol and oracle they touch.
- Findings with severity and remediation Each one written with the impact, the conditions needed to reach it, and the fix, then re-reviewed against your change before the report closes.
- The same bar as any Guardian audit Same reviewers, same methodology, same report. The pilot decides how much goes in scope, not how carefully it is read.
Offchain pentests for critical surfaces.
Most of what can move value in a digital asset program is ordinary infrastructure: consoles, APIs, signing services and the cloud account holding them. We test it the way somebody trying to reach your keys would, and every finding is reproduced by an engineer before it reaches you.
- Infrastructure pentest Hosts, ports, edge and cloud configuration, and the privilege paths between them, tested from outside and again from the position of a first foothold.
- WebApp pentest The console and the customer-facing app: authentication, session handling, authorization between roles, and the logic behind the buttons that move money.
- API pentest Authorization between accounts, injection, rate and replay handling, and everything the documented endpoints do not say they also do.
- Browser extension pentest Wallet and signing extensions: message passing, permissions, the content script boundary, and what a malicious page reaches through it.
- SDK audit The libraries you hand to integrators, read for the assumptions they make and the ones they quietly let a caller break.
- Offchain automation pentest Keepers, bots, sequencers and anything else holding a key on a schedule, reviewed at source and tested for what it does under conditions nobody planned for.
Guardian has already pressure tested hundreds of digital asset systems, let's see what we'll find in yours.
Book your pilot overview callDesigned around your digital asset program's roadmap.
The pilot is deliberately structured to be low commitment and easy for your vendor process to accept. This is a bounded way to work with Guardian and see what digital asset security services look like for your organization. You choose the modules within the pilot which are most applicable to your digital asset program roadmap.
Pick the modules that accelerate your roadmap.
The custody model, issuance path and operator roles are still being decided.
Contracts, services and the engineering process that ships them are being written.
The code is finished and the infrastructure that will hold client assets is standing up.
Client assets are onchain, regimes phase in, and new chains keep arriving.
An example roadmap. Your pilot is scoped to where your program actually sits.
Get Guardian involved in a low risk engagement with maximal upside.
Start with the overview call. By the end of it you will know whether the pilot is the right next step, and what it should cover for you.