Pre-Launch Risk Assessment

The operational risk your audit cannot see.

An independent, evidence-based assessment of your protocol's operational maturity, mapped to 106 controls drawn from the NIST Cybersecurity Framework v2.0.

ASSESSMENT REPORT READINESS 94% ASSESSED

The gap

The largest loss domain never touches the contracts.

$16.6 billion has been lost across 556 DeFi exploits. Roughly 56% of it never touched the smart contracts: it came from the off-chain surface, private keys, custody, access controls, frontends, and the way a team actually operates.

A code audit is built to find bugs in the contracts. It is not built to see any of this, and this is the single largest loss domain in the market.

Case in point · July 2026

A perp protocol passed six audits and was drained of $23.7 million anyway. The attacker never touched the contract logic; they compromised a signer key. Every one of those audits scoped off-chain key management out. That is the door the PLRA closes.

What it covers

The full off-chain surface, on the NIST CSF v2.0 spine.

Plus the surfaces specific to onchain teams: multisig and signer hygiene, deployment and upgrade process, frontend and infrastructure security, and third-party dependency exposure.

PLRA coverage: 106 controls scanned into a risk reportThe 106 off-chain controls grouped into six assessment-function rails and scanned in turn; each control resolves to a finding and a Pre-Launch Risk Assessment Report tallies the results.106 CONTROLS // OFF-CHAIN SURFACEGOVERNownership, policy, roles,and accountability.IDENTIFYassets, dependencies, and wherethe risk actually sits.PROTECTkey management, custody, accesscontrol, and privilege.DETECTmonitoring, alerting, andanomaly detection.RESPONDincident response, escalation,and communications.RECOVERcontinuity, backups, andrecovery under pressure.SCANNINGPRE-LAUNCH RISKASSESSMENT REPORTPASS0CRITICAL0HIGH0MEDIUM0LOW0NOT APPLICABLE0

How it works

One session. Report in hand.

The session runs around two hours. There is no multi-week engagement; you leave with the report in hand.

How the PLRA works, one session to a stamped reportFour boxed nodes on one spine: book the assessment, run one session across the 106 controls with evidence supplied, score operational maturity control by control, and receive the report as a stamped PDF when the session ends.CRITICAL FLAGGEDPDF01 BOOKTHE ASSESSMENT02 SESSIONEVIDENCE SUPPLIED03 SCOREOPERATIONAL MATURITYCONTROL BY CONTROL04 REPORTISSUED AS PDFSESSION ENDS~2 HOURS · ONE SITTING

The report

A confidential PDF, built to be read.

A per-control PDF report with maturity scores and prioritised fixes, issued the moment the session ends. It sits in the room before the legal opinion.

EXECUTIVE SUMMARY

A two-minute executive summary: your average maturity tier, the critical and high findings, and the priority actions to close before launch.

MATURITY BY FUNCTION

Your operational maturity scored across the six NIST CSF v2.0 functions, on a defined tier scale.

FINDINGS WITH REMEDIATIONS

Every critical and high finding mapped to the exact control, each paired with a concrete remediation.

ALL 106 CONTROLS

Control-by-control detail across all 106 controls, with tier definitions and a glossary.

Not an audit. Not a vulnerability report.

Who it's for

Approaching launch

Protocols shipping their first deployment that need a structured, evidenced read on operational readiness.

Expanding surface

Teams shipping a new product line or expanding to a new chain, where the prior assessment no longer covers the changed surface.

Raising institutional capital

Teams that need to prove operational maturity before an allocator will deploy.

Book the assessment

A fixed-price assessment of the operational surface your audit cannot see.