Kerne Logo

Kerne Security

Audit introductions

If your protocol needs a security audit, we will introduce you to Hexens, the firm that audits Kerne. If that introduction turns into a paying engagement, Hexens pays us a commission for it. We have put that in the first paragraph rather than a footnote, because a recommendation you find out later was paid for is worth less than no recommendation at all.

You pay nothing for the introduction. The commission is a share of what Hexens receives, so it comes out of their fee rather than being added to yours. What we cannot publish is the rate: the agreement lets either side disclose that it exists, and keeps the commercial terms confidential, so the number stays between us and them.

The disclosure, in one place

  • Kerne has a signed referral agreement with Hexens Cyber Security Ltd. It is non-exclusive, and it does not stop us introducing you to anyone else or stop them working with anyone else.
  • If an introduction we make becomes a paying engagement, Hexens pays Kerne a commission on it.
  • The commission is calculated on what Hexens receives from you, which means it comes out of their fee. You are not charged for the introduction and there is no line item for it.
  • We cannot publish the rate. The agreement keeps its commercial terms confidential and permits us to disclose that it exists, which is what this page does.
  • Hexens is also the firm auditing Kerne. We are their client and their referrer at the same time, and you should read our opinion of them knowing both of those things.
  • We do not perform the audit, price it, scope it, or see the findings unless you show them to us.

Why we would introduce you at all

Kerne bought this audit with its own money and went through the whole process: scoping, the engagement, an initial report, and remediation that is still in progress. That is the entire basis of what we can tell you. We know how they scope, what their reports actually look like, how they handle a finding you disagree with, and what the calendar really was rather than what the proposal said.

A full audit is a real budget item, generally $40,000 to $100,000 for a DeFi protocol, plus weeks of calendar. Most of the useful information about a firm before you commit that is held by people who already paid it. We are one of those people and we will answer specific questions about the experience, including the parts that were annoying.

Kerne is not an audited protocol yet, and we do not describe ourselves as one until the final report is published. Our own audit status, findings and remediation are at kerne.fi/security, so you can judge the recommendation against how we handled our own findings.

When we will tell you not to

We are paid only if you engage them, so the incentive runs one way. The only useful answer to that is a specific list of the cases where we say no, written down before the situation comes up.

  • Your contracts are still changing week to week. An audit of a moving target is an expensive snapshot of code you are about to replace.
  • What you actually need is cheaper. If the question is whether a single mechanism holds up, a focused adversarial pass costs a fraction of an audit and answers it sooner.
  • You are pre-product and the budget would be better spent getting to a design worth auditing.
  • Another firm is a better fit for your stack. We know one firm well. That is a limit of ours, not a ranking, and if your system is a Solana program or a zk circuit we will say so rather than route you anyway.
  • You want the audit for a marketing line rather than for the findings. Every firm can tell, and it wastes your money.

What actually happens

1. You tell us what needs auditing

The form below asks for the things the firm needs in order to say yes or no: what the contracts do, roughly what you can spend, who signs off, and when you want it done. If you cannot answer some of those yet, send it anyway and say so.

2. We tell you whether we think an audit is the right spend

Sometimes it is not, and we would rather say that than pass you on. If your design is still moving, or the thing you actually want is a cheaper adversarial pass first, we will say that instead.

3. We make the introduction, with the fee disclosed in it

If it is a fit, we send the firm your context and introduce you directly. The introduction email states that we are paid if you engage them, so you and they are reading the same disclosure at the same time.

4. You deal with them directly

Scope, price, timeline and contract are between you and the firm. We do not sit in the middle of it, we do not mark anything up, and we do not get a say in what they charge you. We ask them for a yes or a no in writing and we pass their answer on either way, including a no.

If you are the one making the introduction

Researchers and other people in this corner of the industry run into teams that need an audit more often than we do. If you send us one and it converts, Kerne splits its commission with you fifty fifty. That split is ours to state and it is not conditional on anything except the introduction actually converting.

One condition, and it is not negotiable. If you approach a team on our behalf you disclose the arrangement to them up front, before anything else, in writing. We would rather lose the lead than have somebody find out afterwards that a recommendation was paid for. If you are not willing to say it in the first message, do not make the introduction.

Researchers who have disclosed to Kerne can also take paid work through the Whitehat Desk, which is a separate arrangement with its own terms.

An audit may cost less than you expect

Hexens takes part in the Ethereum Foundation and Areta Audit Subsidy Program, which can cover up to 30 percent of an audit for teams it accepts into a cohort. We will point you at the application when we make the introduction. It lowers your cost rather than ours, and it does not change your terms with them.

Limits, in plain language

  • Kerne is not an auditor and does not audit anything on this page. We make an introduction and nothing else.
  • We do not warrant the firm's work, their findings, their timelines, or their availability. An audit is not a guarantee that code is safe, and no clean report from anyone should be presented as one.
  • We have no say in what they charge you, what they scope, or whether they accept you at all. They decline introductions and we pass that on unchanged.
  • Your contract is with them. We are not a party to it, we do not hold your money, and we have no authority to agree anything on their behalf.
  • Nothing you send through the form below obliges you to anything. No introduction is made until you tell us to make it.
  • We know one firm well and say so. This page is not a survey of the audit market and it is not a claim that they are the best option for you.

Ask for an introduction

The fields below are the ones the firm needs in order to answer. An introduction without them tends to sit unanswered, which helps nobody, so it is worth two minutes.

I am

0 / 1024 characters.

Before you send this: if an introduction we make becomes a paying engagement, the firm pays Kerne a commission. You pay us nothing, and the commission comes out of their fee rather than being added to it. We tell you the same thing again in the introduction itself.

We reply from [email protected]. Submitting this commits you to nothing and does not put you in touch with anyone until you say so. Prefer email? Write [email protected] directly.