Let's look at
your architecture.

Tell us what you are building and what needs to hold up under attack. We will work with you to define the review, from an early protocol design to a release or post-quantum migration.

300+ engagements. Every engagement is led by a senior cryptographer.

How an engagement works

Scope, schedule, and fee agreed in writing before work begins.

Start the conversation

A few sentences are enough to start.

Tell us about the system and the decision you need to make. If the scope is still uncertain, describe the concern you want the review to address.

[email protected]

The draft opens in your email app with a few prompts you can edit.

  1. The system

    What you are building, who uses it, and what it needs to protect.

  2. The review

    The design, code, library, or migration decision you would like us to examine.

  3. Materials and timing

    What documentation or code is available, and any release date or other deadline.

What you receive

A report your engineers can act on.

Scope, schedule, and fee agreed in writing before work begins.

Read a sample report (PDF)
  1. Scope and assumptions

    The system reviewed, attacker capabilities, security goals, and the limits of the analysis.

  2. Findings with evidence

    What can go wrong, the conditions that make it possible, its severity, and the evidence behind the finding.

  3. Remediation and follow-up

    Recommendations your engineers can work from, discussion of the findings, and retesting where agreed in the scope.

Working with us.

We have been working together with Symbolic Software as auditors for cryptographic software. They are reliable, precise, honest, thorough and think outside the box.
— Mario Heiderich, Director, Cure53.
Symbolic Software is run by an accomplished researcher, with significant contributions in the area of applied cryptography. They're the right team for projects that require rigorous design and engineering.
— Jean-Philippe Aumasson, Chief Security Officer, Taurus Group.
Symbolic Software are a delight to work with. Their reports are incredibly thorough and they maintain an excellent line of communication. We are grateful we got the opportunity to collaborate with someone of such high calibre.
— Vishnu Mohandas, Founder, Ente.io.

Before we begin.

What happens after the first conversation?

We define the target and review method with you. The written proposal sets out the scope, deliverables, schedule, and fee before work begins.

Do we need a finished implementation?

No. A design review can begin with a protocol specification, architecture, or threat model. Implementation review can be included when code is available and it fits the scope.

Can you review a specific component?

Yes. A review can focus on a protocol, cryptographic library, key-management design, or migration decision. The boundaries and relevant dependencies are established during scoping.

How long does a review take, and what does it cost?

Each engagement is quoted individually. Timing and fees depend on the size of the target, the material available, and the review method. Dates and deliverables are agreed during scoping.

Let's define the right review.

Scope, schedule, and fee agreed in writing before work begins.