AI finds bugs faster
than you can
patch them.

Autonomous AI systems now discover zero-day vulnerabilities and write working exploits at machine speed, and implementation-level bug hunting is being automated along with them. The work that does not automate sits upstream: protocol architecture, cryptographic design, threat modeling. That is what we do.

$ symbolic --engagement ~5 WEEKS
[wk 1]scopingrequirements, surfaces, threat model
[wk 2]design_reviewprotocol, primitives, key mgmt
[wk 3]code_reviewimplementation fidelity, side channels
[wk 4]draft_reportfindings, severity, remediation
[wk 5]▶ deliveryfinal report · retest if needed
typical · most engagements 4–6 weeks · custom scope on request

What you get.

5 dimensions · led by a senior cryptography expert · full-source review
01 / Architecture

Protocol architecture review

Key exchange, authentication flows, session management, and state machines, evaluated before the first line of implementation.

02 / Primitives

Cryptographic design audit

Primitive selection, parameter choices, composition of schemes, and whether your threat model matches reality.

03 / Code

Implementation verification

Detailed code review across Go, Rust, TypeScript, Swift, Java, .NET, C, and Solidity, verifying that the design was correctly realized.

04 / Post-quantum

PQ readiness assessment

Migration assessment for systems that need to survive the next decade of cryptanalytic advances.

05 / Verification

Formal verification

Machine-checked proofs of protocol correctness, using the most appropriate verifier for your target.

Trusted by

What clients say.

A few of the people we've worked with
We have been working together with Symbolic Software as auditors for cryptographic software. They are reliable, precise, honest, thorough and think outside the box.
— Mario Heiderich, Director, Cure53.
Symbolic Software is run by an accomplished researcher, with significant contributions in the area of applied cryptography. They're the right team for projects that require rigorous design and engineering.
— Jean-Philippe Aumasson, Chief Security Officer, Taurus Group.
Symbolic Software are a delight to work with. Their reports are incredibly thorough and they maintain an excellent line of communication. We are grateful we got the opportunity to collaborate with someone of such high calibre.
— Vishnu Mohandas, Founder, Ente.io.

Why us.

We are an applied cryptography practice, not a generalist penetration testing firm. A senior cryptography expert leads every engagement.

Engagements 250+ completed engagements spanning password managers, encrypted messaging, digital wallets, VPNs, authentication frameworks, and smart contracts.
Named clients 1Password, Mozilla, Coinbase, Zoom, Bitwarden, Dashlane, NordVPN, ExpressVPN, MetaMask, and the Linux Foundation, among the engagements with public reports.
Open-source tooling Verifpal (formal verification), Crucible (post-quantum conformance testing), hpke-ng (RFC 9180 + hybrid PQ), Kyber-K2SO (ML-KEM in Go), the PQ Migration Playbook.
Published research Peer-reviewed work on cryptographic protocol analysis and formal verification, including the libcrux audit papers and the OSTIF talk on disclosure ethics.

Questions, answered.

Deliverables · timeline · pricing
What the deliverable looks like Every engagement ends in a written report covering findings, severity, and remediation. Several are public: 1Password B5, Thunderbird Enigmail, dWallet 2PC-MPC, and Telegram MTProto.
How long it takes Most engagements run 4–6 weeks from scoping to final report, with a retest pass if needed. Custom scopes on request.
What it costs Every engagement is scoped and quoted individually. Pricing depends on codebase size, protocol complexity, and deliverables. You get a written scope and timeline before any commitment.
Where to start Book a call or send an email. We scope the work together on the call, and we typically respond within one business day.

Ready to start?

We scope the work together, agree on timeline and deliverables, and get going.

We typically respond within one business day.