Authority Assurance for smart contracts and protocol control planes.

We verify the code that moves value and the authority that can change it. Manual smart-contract review, governance and upgrade analysis, and continuous monitoring of who can change your protocol and how fast, delivered as engineering evidence.

Baseline Control Snapshot

See who controls any protocol, in 30 seconds

Enter a proxy contract address. Themis resolves the authority chain, detects upgrade constraints, and surfaces control-plane risk. No account required.

Architecture classificationController typeTimelock presenceSurfaced risk findings
Run a free scan now!

Free · No account · Ethereum, Arbitrum, Optimism, Base, Polygon

themislabs.ai/scan/trial/…
HIGH RISK: Upgrade path lacks timelock protection
ArchitectureUpgradeable (UUPS)
ControllerEOA (direct)
TimelockNot detected
HIGHCritical upgrade authority appears unconstrained
🔒 Effective Delay · Bypass Paths · Evidence Pack

The same Authority Assurance, applied to a smart contract.

The code that moves value matters, but the authority that can change the code matters just as much. We verify both: the smart contract itself and the control plane around it, governance, upgradeability, the delegation paths that decide how the protocol can change, and the timelocks and multisigs that gate that authority. The same discipline we bring to AI agents.

Most DeFi risk is not in a single line of code. It is in who can change the code, and how fast.

How a security review works.

A structured engagement with a fixed scope, clear checkpoints, and post-fix verification.

01
Scoping
Architecture review, invariant identification, and governance-model analysis. Quote within 48 hours.
02
Kickoff
Repository access, documentation review, communication setup, and priority alignment.
03
Review
Manual analysis, static-analysis tooling, and fuzz testing across the defined scope.
04
Draft Report
Preliminary findings delivered to the protocol team for internal review and triage.
05
Remediation
Support during the fix phase: clarifications, patch guidance, and re-analysis.
06
Final Report
Post-fix verification. Delivered publicly or privately per disclosure agreement.

Code, and the control plane around it.

Protocol logic & invariants
Whether accounting, state transitions, and economic assumptions hold under adversarial conditions.
Governance & timelock
Whether delays, proposer/executor roles, cancellation, and emergency permissions can be bypassed.
Upgrade authority & admin risk
Who can upgrade contracts, how fast, and whether privileged paths rely on EOAs or weak multisigs.
AMM & asset accounting
Rounding, fee-on-transfer and rebasing assets, slippage assumptions, and value-conservation failures.
Edge-case execution paths
Failures from zero amounts, empty sets, boundary values, and unexpected composability paths.
Proxy topology & storage
Storage-layout safety and the upgrade topology behind every implementation swap.

34 major DeFi protocols analyzed.

Authority graphs, upgrade timelines, and risk classifications mapped across the most widely deployed DeFi protocols. Browse the public Control-Plane Index or scan any proxy contract yourself.

Continuous control-plane visibility for protocol teams

Use Themis before audit, before deployment, and after launch to track governance, upgrade, and authority risks for your own protocol.

Each subscription is a workspace for one protocol: a transaction-validated reconstruction of upgrade authority, governance surfaces, and bypass paths, kept up to date as the protocol evolves.

This is not a substitute for a full audit.

Snapshot: Single Proxy System
Best for early-stage protocols with a simple ownership or proxy structure.
$350
  • One protocol workspace included
  • Pre-audit authority-path review
  • Authority chain reconstruction
  • Effective upgrade latency
  • Governance actor mapping
  • Saved protocol snapshots
Recommended
Snapshot: Multi-Proxy / Diamond Systems
$690
  • One protocol workspace included
  • Pre-audit and post-deployment review
  • Cross-contract authority mapping
  • Bypass path detection
  • Parameter drift analysis
  • Upgrade / admin change detection
  • Saved protocol snapshots and exportable reports
Snapshot: Full Protocol Surface
Pre-audit structural assessment for full protocol coverage.
$1,800
  • One protocol workspace included
  • Cross-contract authority graph
  • Governance surface diff
  • Post-deployment monitoring
  • Alerts for authority-path changes
  • Executive summary and exportable reports
  • Additional protocol workspaces available as add-ons

Each subscription covers one protocol workspace. Additional protocols require a separate subscription, add-on, or enterprise agreement. Public scanner usage remains subject to rate limits and supported-chain coverage.

Themis scan results are automated security intelligence based on public onchain data and supported metadata sources. They are not a full smart contract audit, legal opinion, investment advice, or endorsement of any protocol.

Themis provides security analysis, audit, and control-plane risk intelligence services only. Themis does not provide crypto exchange, custody, brokerage, payment, investment, or financial services. Service availability and supported-chain coverage may vary by jurisdiction.

Snapshot requests may be queued depending on system load.

When Should You Run a Snapshot?

  • Before mainnet launch
  • Before token generation event
  • Before fundraise or investor due diligence
  • After major governance refactor
  • Before engaging a full smart contract audit

Continue to Full Governance & Privilege Audit

The Snapshot identifies structural control-plane risks. The Full Audit validates logic-level privilege controls, upgrade safeguards, and escalation paths in depth.

The Snapshot frequently uncovers governance concentration, timelock bypass paths, or upgrade latency inconsistencies not visible in standard reviews.

  • Manual contract review
  • Privilege logic verification
  • Governance simulation
  • Upgrade abuse modeling
  • Formal report suitable for investors
Request Full Audit

Operating or investing in a protocol?

Share your repository and protocol overview for an audit, or run a control-plane scan in seconds. We’ll take it from there.