# Verdict > Due diligence as a service for DeFi. Verdict runs independent risk ratings > (AAA-D, 300+ testable criteria, 7 entity types), pre-launch risk assessments, > contract scanning, rating-priced cover, and a security partner marketplace for > audits, monitoring and pen testing. Ratings are free to read from a public API > that needs no key and is browser-callable. Positioning: the due-diligence house for DeFi - independent ratings, rating-priced cover, security testing and continuous monitoring, across every entity type. Thesis: risk isn't isolated, it's inherited. Verdict scores the whole dependency stack rather than an entity in isolation, and a weak dependency drags the dependent entity's grade. ## What Verdict rates Seven entity types, each with its own rubric (306 criteria total): Protocol (85 criteria): Security, Code Quality, Compliance, Operations, Technology, Finance, Protocol Team Bridge (62): Governance, Incident History, Transparency, On-Chain Footprint, plus category-specific domains (Messaging Security, Lock and Mint Security, Burn and Mint Security, Atomic Security, Custodial Security, Trustless Assumptions) Token (44): Contract Security, Holder Distribution, Liquidity and Trading, Project Fundamentals, Tokenomics, Market Stability, plus a Stablecoin Stability domain for stablecoins Chain (40): Node Infrastructure, Security, Code Quality, Economic Model, Ecosystem, Governance, Compliance Risk Oracle (34): Data Quality, Security, Decentralization, Integration Ecosystem, Economic Model, Transparency and Governance Vault (26): Admin Powers, Strategy Risk, Receipt Token Mechanics, Oracle Dependency, plus Staking and Slashing for LST/LRT vaults Organisation (15): Team and Track Record, Legal and Regulatory, Transparency and Conflicts Grades run AAA to D off a 0-100 composite: AAA >=95 exceptional - AA >=88 very strong - A >=80 strong - BBB >=70 adequate - BB >=60 elevated risk - B >=50 significant risk - CCC >=40 high risk - CC >=30 critical - C >=20 severe - D >=0 failed/unsafe Bands assign after half-up rounding to 1 decimal (87.98 -> 88.0 -> AA). Live coverage (auto-updated): 34 chains, 11 oracles, 1 protocol, 14 bridges, 4 vaults rated; tokens and organisations not yet published. Machine-readable methodology: https://api.verdict.finance/api/v1/methodology ## Products 1. Ratings - https://www.verdict.finance/products/ratings Objective DeFi risk ratings across the full dependency graph. An independent letter rating (AAA-D) from 300+ testable criteria across 7 entity types. Free to read via API. LIVE. 2. Cover - https://www.verdict.finance/products/cover Rating-priced parametric cover: the rating prices the premium, with the claim path defined in code rather than decided by committee. Indicative rating-seeded anchors: AAA ~1%, A ~4%, BB ~12%, D ~50% of covered value; the AMM discovers the live premium from that seed. 3. Pre-Launch Risk Assessment - https://www.verdict.finance/products/pre-launch-risk-assessment Independent, evidence-based assessment of operational maturity mapped to 106 controls from NIST Cybersecurity Framework v2.0. Targets the off-chain surface - keys, custody, access control, frontends - which Verdict puts at ~56% of the $16.6B lost across 556 DeFi exploits. Booked as an engagement. 4. WhiteHat - https://www.verdict.finance/products/whitehat Deterministic smart-contract scanning with an LLM triage layer: static-first detectors sweep known vulnerability classes, then triage ranks, explains and filters. Commissioned per scan; findings ranked with impact and remediation. Security partner marketplace - audits, monitoring and pen testing procured through one rail from vetted security firms, with the rating function kept structurally separate from what you buy. 5. Audit Marketplace - https://www.verdict.finance/products/audit-marketplace Audit exchange where vetted firms submit sealed blind bids against a comparable scope, so offers can be read side by side. Enquiry only. 6. Monitoring Marketplace - https://www.verdict.finance/products/monitoring-marketplace Continuous monitoring on the entities you hold: watchlist, live alerts and webhooks, tied to the grade. Enquiry only. 7. Pen Test Marketplace - https://www.verdict.finance/products/pen-test-marketplace Web3 frontend and infrastructure penetration testing, delivered by vetted partner firms and scoped per engagement. Enquiry only. 8. Quantum Readiness - https://www.verdict.finance/products/quantum-readiness Post-quantum migration, measured: a live league table of post-quantum readiness across 70+ chains, free to read via API, plus readiness assessments, migration roadmaps and quantum engineering delivered per engagement. LIVE. Direction: Verdict is building toward agent-native access - x402 micropayments for ratings data, and a bounty system where agents are paid to find stale answers, with every change human-reviewed. The methodology is heading toward open source; the data stays the product. ## Who it's for Protocols getting launch-ready, raising, or onboarding institutional capital - via ratings, pre-launch assessment and scanning. Analysts and risk teams consuming ratings data - via the API on Free or Pro. Cover buyers and underwriters pricing off an independent grade. ## Pricing - https://www.verdict.finance/pricing Free - $0 forever Letter grade + composite score per entity; public entity metadata; public dashboard. 300 requests/minute. "Powered by Verdict" attribution required on any user-facing UI. Pro - $200/month Everything in Free, plus per-domain score breakdowns, rating version history, watchlist and grade-change alerts, bulk CSV/JSON export. 1,000 requests/minute. Attribution optional. Enterprise - custom Everything in Pro, plus per-question scores with rationale, full rubric criteria, evidence and reasoning trails, compare endpoint, white-label, custom rate limits, MSA + NDA. Transparency note: per-question criteria, rubric weights and evidence trails are Enterprise-tier. Free and Pro callers receive the grade and score but not the full derivation. ## For developers and agents Full API reference (endpoints, object shapes, errors, rate limits): https://www.verdict.finance/llms-full.txt OpenAPI spec: https://api.verdict.finance/openapi.json Human docs: https://www.verdict.finance/docs/api Base URL: https://api.verdict.finance/api/v1 - public reads need no key, CORS open. Anonymous limit: 120 requests/minute, 20,000/day per IP. Quantum readiness companion data, no key required: GET /quantum-readiness (league table, 72+ chains) and GET /chains/{slug}/quantum-readiness (per chain). QRI + band sourced from LayerQu, served with attribution; never a rating input. MCP server for agent frameworks: npm package verdict-finance-mcp (run: npx verdict-finance-mcp, Node 20+), listed on the official MCP Registry as io.github.charles-verdict/verdict-finance-mcp. Eight tools: search_ratings, get_rating, list_ratings, get_recent_incidents (confirmed hacks by default; min_status: 'corroborated' opts into multi-source early leads), quantum_readiness, get_methodology, get_rating_breakdown, request_coverage. Keyless except get_rating_breakdown, which reads VERDICT_API_KEY from the environment. Discovery file: https://www.verdict.finance/.well-known/mcp.json Hack incident feed, no key required: GET /incidents - confirmed by default, tiered via min_status. Semantics in llms-full.txt. ## Terms for AI and automated access https://www.verdict.finance/legal/terms - agents and automated clients are permitted on the same tiers as any other client. Attribution on free and anonymous use is satisfied by naming Verdict as the source and linking where the medium allows. Redistribution as a substitute or competing data service is not permitted. ## Contact https://www.verdict.finance/contact