A control-plane review that maps every upgrade path, governance actor, and timelock bypass route across your contracts. We reconstruct the real authority model from on-chain state, not the org chart, so you know who can change what, and how fast.
In-depth · Control-plane analysis
The problem
A perfectly audited contract is still unsafe if one key can upgrade it with no delay. The authority around the code (who can change it and how fast) is where the largest, least-visible risk lives.
Scope
We reconstruct the full authority graph from on-chain state and stress every path that can change the protocol.
Methodology
We combine automated authority-graph reconstruction with manual review of the paths that matter most.
Deliverables
A free control-plane scan gives you a baseline in seconds. A full Governance Audit adds manual review, bypass enumeration, and evidence.
Why Themis
FAQ
A code audit reviews contract logic. A Governance Audit reviews the authority around it, who can change the code, through which paths, and how fast. They complement each other.
Ethereum, Arbitrum, Optimism, Base, and Polygon, with more on request. The free scan covers the same set.
Yes, run a free control-plane scan on any proxy contract. The Governance Audit adds manual bypass analysis, evidence, and a written report.
An authority graph, the effective timelock delay, a ranked list of bypass paths, and on-chain evidence for each finding.
Run a free scan for a baseline, or request a full Governance Audit with manual bypass analysis and evidence.