Most DeFi protocols are not purely onchain. They depend on backends for coordination, on APIs for pricing and quoting, on custody systems for keys, and on frontends users actually touch. Smart contract auditors stop at the contract boundary; backend engineers assume the chain enforces correctness. The seam between them is rarely anyone's responsibility.
We treat that seam as in scope. It is a distinct discipline from contract review, and it is where a substantial share of our findings for exchanges, payment providers and custodians have been.
Tell us what you're building. Web2.5 Security Audits is an area we work in constantly.