Deterministic contract scanning with an LLM triage layer.
Static-first detectors sweep for the known vulnerability classes; an LLM triage layer ranks, explains, and filters the noise. Commissioned per scan; findings arrive ranked with impact and remediation.
The gap
Roughly a third of all recorded DeFi loss, about $5.6 billion, came through on-chain contract logic. The audit industry's answer is thorough and slow: a point-in-time review of one commit.
But the code you ship next month is not the code that was audited, and re-auditing every change is priced for treasuries, not for teams mid-build. Between audits, most protocols fly blind on the one surface that is fully machine-checkable.
What it is
A static-first detector ensemble sweeps the codebase for the known vulnerability classes; a directed LLM triage stage then ranks what the detectors surface, explains each finding, and filters the noise before it reaches your team.
The detector taxonomy is versioned, so a scan is reproducible against the framework generation that produced it. Findings arrive ranked and explained, not as a thousand-line dump. It is Pro-gated; you do not need a Verdict rating to use it.
How it works
When your code changes, commission a re-scan. There is no subscription to maintain and no engagement to schedule; the scanner is there when the diff is.
01
Commission a scan from the dashboard, paid per scan in USDC.
02
Point it at your GitHub repository; rating-grade scans pin an exact commit, so the result is tied to the code it actually read.
03
The detector ensemble sweeps, and the LLM triage layer ranks, explains, and de-noises what it finds.
04
Your report lands as a downloadable PDF: every finding with its severity, impact, and a concrete remediation.
The loop
A WhiteHat scan is not a dead-end PDF. Scan results flow into the protocol's security evidence inside the Verdict rating: findings, and clean results where the detectors can genuinely attest them, become cited inputs to the security criteria a protocol is publicly scored on. Security work you pay for once keeps paying inside the grade allocators actually read. The same engine powers Verdict's web-layer penetration testing.
A scanner closes known vulnerability classes; it does not catch tomorrow's bespoke logic bug. WhiteHat is a triage and evidence layer, and human audit remains a necessary complement. It also does not cover the off-chain surface: that is the PLRA's job. Teams commonly run a PLRA before launch, keep their audits, and use WhiteHat as the layer between them.
Who it's for
Mid-build teams
Changing contracts faster than they can re-audit.
Pre-audit teams
Clear the known classes cheaply before the expensive review starts.
Rated protocols
Strengthen the security evidence inside your public grade.
Pro subscribers shipping Solidity
A second set of eyes that never gets tired.
Commission a scan
Pro-gated.