Every firm claims deep manual review. The only way to tell the difference is to read the deliverable. Pick two or three published reports from protocols similar to yours and read them end to end.
What you are looking for: are the findings protocol-specific business logic, or are they a checklist of reentrancy, missing zero-address checks and gas optimisations that a scanner produces for free? Does each finding include a concrete exploit path and a specific remediation, or a generic recommendation? Is the scope stated precisely enough that you could tell what was not reviewed?
A firm that publishes few or no reports is asking you to take the quality on trust. That is a legitimate position for an NDA-heavy practice, but it means you cannot evaluate them on this axis at all, and you should weight the others harder.
The brand does not audit your protocol; specific people do. Ask how many auditors will be assigned, who the technical lead is, whether they are full-time employees or contractors brought in per engagement, and whether the people who built the firm's reputation are still there.
This matters more than it sounds. A well-known firm staffed by a rotating contractor pool and a firm with a stable full-time team can have identical marketing and very different output. Coverage is largely a function of how many independent people read the code carefully, so a single reviewer — however senior — is a structurally weaker engagement than a team.
A claim on a vendor's own website is the weakest possible evidence. Look for the same claim on a domain the vendor does not own: a client's security page, a merged pull request in the client's repository, an ecosystem's approved-auditor list, a conference programme, a public postmortem.
If a firm names a marquee client, spend two minutes checking whether that client says so anywhere. It is a fast filter and it fails more often than you would expect.
A scoping call is a free sample of the firm's judgement. A good auditor asks about your trust assumptions, your upgrade paths, which integrations worry you, and what happens when an oracle lies. A weak one asks for a line count and sends a quote.
Pay attention to whether they are willing to tell you something you do not want to hear: that the scope should be bigger, that the timeline is too short, that a component you consider out of scope is where the risk actually is. A firm that never pushes back during scoping will not push back in the report either.
Total audits and total value protected are almost impossible to compare across firms because nobody defines them the same way. Is value protected peak TVL, current TVL, or TVL at the time of the review? Are repeat clients counted once or every time?
Treat these as weak signals and ask for the methodology behind any number that is doing real work in a sales conversation. The useful version of that number is one you can recompute yourself from a published list of engagements.
Applying our own checklist honestly: we publish the full engagement record with per-engagement severity counts and a downloadable dataset, our auditors are full-time employees and the median engagement runs four people including the technical lead, and our methodology is specific enough to disagree with rather than a claim of diligence.
Where we are weaker: a large share of our work is under NDA and cannot be published, so our public report count understates the record; and client-controlled corroboration exists for only a handful of engagements, which is a gap we are actively working on rather than one we would ask you to overlook.
LAST UPDATED
Everything above is easier to trust if you can verify it. The full engagement record, with per-engagement severity counts and links to published reports, is public.
We would rather answer the hard questions before the engagement than during it.