Fixed Scope · Fixed Price · No Retainer Lock-In

CLEAR PRICING

Every engagement scoped in writing before the first invoice. Smart contracts, cloud, PQC readiness, GEO Wireless, and EU regulatory compliance — one team, transparent rates.

SOC 2 · ISO 27001 NIS2 · DORA MiCA · EU AI Act GEO Wireless Stack PQC · ML-DSA Qiskit VQC Web3 · DeFi Diia.City · UA
📐

Fixed Scope, Fixed Cost

Defined in writing before the first invoice. Price changes only if scope changes — and only with your sign-off.

🔁

Re-test Included

One full re-test of all Criticals and Highs included in every engagement. We verify the fix, not just the intent.

📄

Completion Letter

Signed letter for investors, regulators, or your insurance broker — accepted across EU, US, and UA regulatory contexts.

⚖️

Multi-Framework

Single engagement can map findings to NIS2, DORA, MiCA, EU AI Act, SOC 2, and ISO 27001 simultaneously.

One-Time Engagements

Point-in-Time Audits

Pre-launch audits, compliance assessments, and cloud reviews. Scoped, priced, and delivered.

Starter

Smart Contract Audit

$4,500

Fixed price · Up to 500 LoC

Focused manual and automated review for single contracts or small protocol components. Covers Solidity, Rust, and Vyper.

  • Manual review up to 500 lines (Solidity / Rust / Vyper)
  • Slither static analysis — 20+ detectors
  • AI-assisted vulnerability classification (LLM-Bridge)
  • Severity-rated findings report — PDF + HTML
  • Plain-language executive summary
  • Impact, likelihood, and blast-radius scores
  • Re-test of all Critical and High findings
  • Signed completion letter
  • Fuzzing / formal verification
  • Mainnet fork simulation
Get a Quote

Cloud & Compliance

Cloud Security Review

$8,000

Fixed price · Up to 4 AWS/GCP/Azure accounts

IAM, network, secrets, and logging mapped to SOC 2, ISO 27001, or NIS2 controls where relevant.

  • IAM privilege analysis and RBAC control matrix
  • Network exposure review — SGs, NACLs, firewall rules
  • Secrets and key management assessment
  • Logging and monitoring coverage check
  • Blast-radius scores for every finding
  • SOC 2 / ISO 27001 / NIS2 control mapping
  • Evidence export templates for your compliance platform
  • Re-test of Critical and High findings
  • Fuzzing / blockchain analysis
  • Continuous monitoring
Get a Quote

Advanced & Emerging Technology

Specialist Security Tracks

Beyond standard audits — deep-expertise engagements for post-quantum cryptography, GEO wireless, anti-gambling intelligence, and national defense-grade architecture.

PQC · Quantum Lab

Post-Quantum Cryptography Readiness Audit

$9,500 + scope

Fixed price baseline · Hardware add-ons scoped separately

NIST PQC migration readiness for cloud, IoT, and embedded systems. Covers ML-DSA-65 (CRYSTALS-Dilithium), ML-KEM (Kyber), SLH-DSA, and hybrid classical/PQC transition paths. Includes Qiskit Aer CUDA VQC validation for cryptographic strength under quantum adversary assumptions. Aligned to EU AI Act Annex III and ENISA PQC guidelines.

  • Current cryptographic inventory — TLS, JWT, at-rest encryption
  • ML-DSA-65 / ML-KEM migration gap analysis
  • Qiskit VQC+PSO meta-optimizer evaluation (shadow mode)
  • ESP32 / RP2040 embedded PQC feasibility assessment
  • Hybrid classical/PQC transition roadmap with ADR framework
  • ENISA PQC readiness report — accepted by EU financial regulators
  • Merkle tree audit trail for cryptographic state evidence
  • EU AI Act + NIS2 dual-mapping of findings
GEO Wireless Stack

Physical RF Security & OSINT Geolocation Audit

$6,800 + per-site

Baseline engagement · On-site survey add-ons quoted separately

WiFi/BLE triangulation, SDR-based spectrum analysis, and legal OSINT geolocation (Wigle + OpenCellID) for physical perimeter security. Identifies rogue APs, unauthorized transmitters, RF leakage across security zones, and wireless blind spots in your monitoring coverage. Evidence maps to ISO 27001 Annex A.7 physical controls and SOC 2 CC6.4.

  • WiFi 802.11 / BLE 5.x passive beacon survey
  • SDR wideband RF spectrum analysis — GNU Radio / HackRF
  • RSSI trilateration + RF fingerprinting (kNN model)
  • Legal OSINT geolocation via Wigle API + OpenCellID
  • Rogue AP and unauthorized transmitter identification
  • Geo-tagged findings as GeoJSON + PDF evidence artefacts
  • DBSCAN spatial clustering and heat-map risk overlay
  • ISO 27001 A.7 / SOC 2 CC6.4 evidence package
AML / Anti-Gambling

Anti-Gambling Intelligence Hub & AML Architecture Review

$14,000 + data scope

MVP sprint 1–2 · Full OMNIVERSAL stack quoted on engagement

The OMNIVERSAL 5-layer architecture review for AML/CFT and anti-gambling platforms — from OSINT ingestion and Neo4j graph correlation through Kafka/Flink AML Risk Engine to Merkle-anchored audit trails on Hyperledger Fabric. Aligned to MiCA, 6th AML Directive, and FATF Travel Rule requirements for token issuers and DeFi operators.

  • 5-layer architecture review — Sensing → Cognition → Decisioning → Evidence → Action
  • Neo4j graph correlation model and entity resolution logic
  • Kafka/Flink AML Risk Engine pipeline audit
  • Merkle Tree + Hyperledger Fabric audit trail integrity verification
  • OSINT ingestion security and source validation
  • MiCA / 6AMLD / FATF Travel Rule control mapping
  • On-chain AML/CFT controls — wallet screening, sanctions list
  • GitHub RFC structure review and Kafka topic boundary analysis
Defense · NIS2 · DORA

National Infrastructure & Defense Architecture Security

Custom

12-month engagements · Ukraine Diia.City eligible · EU grant-fundable

Defense-grade security architecture review for national critical infrastructure, multi-bearer connectivity stacks (fiber + SATCOM + fallback), and space-system threat modelling (5-domain: space, launch, ground, terminals, governance). Includes Starshield / SATCOM supplier due diligence, hosted payload trust boundaries, and NIS2 incident notification workflow design. Directly applicable to UA defense contractors, EU public sector, and Diia.City registered entities.

  • Multi-bearer stack security — fiber + SATCOM + Starshield fallback
  • Space threat model — 5 domains per ENISA Space Threat Landscape
  • Hosted payload trust boundary analysis and payload-to-bus isolation
  • NIS2 Article 21 security measure implementation review
  • DORA ICT risk management and TLPT readiness
  • Supplier due diligence — non-EU private provider risk assessment
  • Incident notification workflow — 24h / 72h / 1-month NIS2 tiers
  • EU strategic autonomy risk register with dependency mapping

EU & International Regulatory

Compliance Framework Audits

Standalone compliance readiness assessments. Each engagement ends with a gap report, control mapping, and an evidence package your auditor or regulator can act on.

NIS2 Readiness Assessment

$7,200

Fixed · Article 21 + 23 coverage · Essential & Important entities

Gap assessment against all Article 21 security measures. Incident notification workflow design (24 h / 72 h / 1-month tiers). ICT supply chain due diligence checklist. Remediation roadmap with deadline mapping to enforcement dates.

DORA ICT Risk Review

$9,400

Fixed · Financial entities · Jan 2025 enforcement

ICT risk management framework assessment. Resilience testing (TLPT) scoping and preparation. Incident classification and reporting workflow. Third-party ICT provider register and contractual gap analysis.

MiCA Compliance Assessment

$8,100

Fixed · Token issuers & CASPs · White paper review

MiCA Title II–V control mapping for asset-referenced tokens, e-money tokens, and crypto-asset services. White paper review against Article 19 disclosure requirements. On-chain AML/CFT control inventory and FATF Travel Rule gap analysis.

EU AI Act Conformity Review

$6,800

Fixed · High-risk AI systems · Annex III coverage

Risk classification under Annex III. Technical documentation requirements (Article 11). Conformity assessment preparation. Bias, explainability, and robustness evaluation framework. Applicable to AI-assisted security tools, LLM-based audit platforms, and autonomous agent systems.

SOC 2 Type II Readiness

$7,500

Fixed · All 5 TSC · 90-day observation window prep

Automated evidence collection pipeline setup. Control testing and sampling design. Auditor-ready artefact repository. Gap assessment with prioritised remediation before the observation window opens. Reduces fieldwork time and auditor fees significantly.

ISO 27001 Gap Assessment

$5,900

Fixed · Annex A · Certification path report

Full Annex A control gap analysis. Risk register population. ISMS documentation review and policy templates. Certification auditor selection guidance. Remediation roadmap prioritised by likelihood-of-auditor-flagging.

Ongoing Services

Continuous Compliance & DevSecOps Retainers

Security and compliance wired into your pipeline — not a once-a-year fire drill.

DevSecOps Pipeline Retainer

$2,500 /month

3-month minimum · Cancel with 30 days notice

SAST, DAST, dependency scanning, and secret detection on every pull request. Critical/High findings block merge. Mediums auto-filed as issues. Includes LLM-Bridge integration for AI-assisted finding triage.

  • Slither / Semgrep SAST on every PR
  • Dependency scanning and secret detection on every commit
  • Critical + High block merge; mediums auto-filed
  • LLM-Bridge AI triage and classification
  • Monthly pipeline health report
  • On-call Slack channel — next business day SLA

Continuous Compliance Retainer

$3,800 /month

6-month minimum · Includes annual audit support

Automated evidence collection, daily control monitoring, and auditor-ready artefact repository. Covers SOC 2, ISO 27001, NIS2, DORA, or a custom framework. Your next audit starts with a clean evidence base, not a manual scramble.

  • Automated evidence collection wired to cloud environment
  • Daily control monitoring with drift alerts
  • Auditor-ready repository — Vanta, Drata, or raw storage
  • Quarterly gap assessment and remediation roadmap update
  • Annual audit support — we liaise with your auditor
  • RBAC review quarterly + policy document maintenance

Web3 On-Chain Monitoring

$1,800 /month

1-month minimum · Per protocol

Post-deployment on-chain monitoring for DeFi protocols. Real-time transaction analysis, anomalous fund flow detection, flash loan / MEV pattern recognition, and AML/CFT-aligned thresholds via the Kafka/Flink Risk Engine. Alert escalation to your team via PagerDuty, Slack, or Discord.

  • Real-time monitoring via Tenderly / custom Kafka indexer
  • Flash loan, MEV, and sandwich pattern detection
  • Unusual fund flow alerts — AML/CFT thresholds
  • PagerDuty / Slack / Discord alert integration
  • Monthly on-chain activity summary report
  • 4 hours incident response support per incident

Enterprise Security Partnership

Custom

12-month agreements · Volume discounts · Diia.City eligible

Dedicated engagement for large protocols, regulated financial institutions, EU public sector entities, or government digital services. Covers audits, continuous compliance, monitoring, threat modelling, PQC migration, and executive reporting under a single agreement. Structured for Diia.City–registered entities and UA defense contractors.

  • Dedicated lead security engineer
  • Unlimited point-in-time audits within agreed scope
  • Board-level quarterly risk briefing + regulatory dashboard
  • PQC transition roadmap included
  • 4-hour incident response SLA
  • Priority scheduling for new product launches and regulatory filings

What's Covered Where

Service × Regulatory Framework Matrix

Every audit engagement can be mapped to one or more frameworks simultaneously — no separate re-engagement required.

Service Base Price NIS2 DORA MiCA EU AI Act SOC 2 PQC
Smart Contract Audit (Starter) $4,500 — — ✓ Add-on — — —
Full Protocol Audit (Professional) $12,000 ✓ ✓ ✓ ✓ Add-on — + PQC
Cloud Security Review $8,000 ✓ ✓ — — ✓ —
PQC Readiness Audit $9,500 ✓ ✓ — ✓ — Native
GEO Wireless Stack Audit $6,800 ✓ — — — ✓ CC6.4 —
AML / Anti-Gambling Audit $14,000 ✓ ✓ ✓ — — + PQC
Defense / National Infrastructure Custom ✓ Art. 21 ✓ TLPT — ✓ — ✓ PQC
Continuous Compliance Retainer $3,800/mo ✓ ✓ ✓ ✓ ✓ Coming

Common Questions

Pricing FAQ

What if my codebase is larger than the tier covers?

We scope it properly before you sign. For contracts above the listed LoC, we provide a custom quote — typically $80–$120 per additional 100 LoC for smart contracts, or a flat add-on for additional cloud accounts. You see the number before we start.

Do you charge hourly for anything?

No. All engagements are fixed-price based on an agreed scope. If scope changes mid-engagement we issue a change order with the additional cost before doing the work.

How does the PQC audit work with existing infrastructure?

We start with a full cryptographic inventory — every algorithm, key exchange, signing scheme, and protocol in scope. We then apply the NIST PQC migration framework (NIST IR 8547) against your current posture, use Qiskit Aer simulation to evaluate quantum adversary assumptions, and deliver a prioritised migration roadmap covering ML-DSA-65, ML-KEM, and hybrid transition strategies. For embedded targets (ESP32, RP2040), we include hardware feasibility benchmarks.

Can a single engagement cover NIS2 and DORA simultaneously?

Yes. Many controls overlap — ICT risk management, incident notification, and third-party supplier assessment appear in both frameworks. We map findings once and generate dual-framework evidence artefacts, saving you from running two separate engagements. Our framework matrix above shows exactly which services cover which frameworks out of the box.

We're a Diia.City entity in Ukraine. How does that affect scope?

Diia.City registered entities operating in the defense, fintech, or public sector space often have obligations that intersect with EU NIS2 (as supply chain partners to EU entities) and Ukrainian cybersecurity law. We're familiar with both the regulatory context and the multi-bearer connectivity architecture (fiber + SATCOM + Starshield fallback) relevant to UA defense infrastructure. Contact us with your specific regulatory obligations and we'll scope appropriately.

What's in the completion letter?

A signed PDF confirming scope, finding summary by severity, re-test outcome, and our professional assessment of the system's security posture. Accepted by VCs, EU and UA regulators, and insurance brokers as proof of audit. For NIS2/DORA engagements the letter includes a statement on Article 21 measure coverage.

How does the AML / Anti-Gambling Hub engagement work?

We review your OMNIVERSAL-style architecture layer by layer: OSINT ingestion security, Neo4j graph model logic, Kafka/Flink pipeline integrity, and the Merkle Tree + Hyperledger Fabric audit trail. The output is a MiCA and 6AMLD-aligned control report plus a prioritised remediation backlog structured as GitHub-ready RFCs your team can act on immediately.

Custom Scope

Get an Exact Quote

Not sure which track fits? Tell us what you're securing and we'll return a scoped proposal — usually within 24 hours.

Useful things to include:

  • System type — cloud, Web3, PQC/IoT, GEO Wireless, AML, or defense
  • Rough size — LoC for contracts, number of cloud accounts, or site count
  • Target chain(s) and deployment status
  • Regulatory deadline — NIS2, DORA, MiCA, SOC 2, or other
  • Diia.City registration status if applicable
  • Prior audit reports or known risk areas

Request a Proposal