What is Verdict?
Due diligence as a service, plus the security marketplace that acts on it.
Ratings is a subscription rating service across 7 entity classes (protocols, chains, tokens, oracles, vaults, organisations, and bridges) graded against 300+ testable criteria on a version-controlled rubric.
PLRA (Pre-Launch Risk Assessment) is a fixed-price managed engagement that scores a protocol's launch-readiness against a 106-control NIST CSF v2.0 framework and hands back a citation-grade report.
WhiteHat is a security scanner: static-first analysis with an LLM triage layer, commissioned per scan so new findings reach the team as the code changes.
Verdict Cover is a parametric cover marketplace where each pool's opening premium is seeded directly by the rating composite of the entity it covers. It turns a protocol's security posture into a revenue line rather than a cost line.
The security partner marketplace routes the work Verdict does not do itself: audits, monitoring and pen testing from vetted partner firms, procured through one rail with sealed bids and comparable scopes.
Two of these close a loop the rest of the market leaves open. The rating prices the cover. The cover validates the rating. A pure-data rater publishes a number to a dashboard and waits for someone to notice; Verdict publishes a number that becomes the AMM's opening quote on a live cover pool, and the price moves on every trade. And the number is not shallow: no competitor scores the dependency graph, so a Verdict rating carries Protocol, Chain, Oracle, Token, Org, Bridge, and Vault in one figure. The rating, from the first block onward, is a live position rather than an opinion with a logo. Every dependency the entity has chosen (the chains it runs on, the oracles that price it, the bridges it crosses, the organisations that operate it) drags the grade by 2% per notch below B, scaled by criticality, capped at 30%.
Roughly $3 trillion of stablecoin float is queueing for onchain yield by the end of the decade. "The stablecoin market, meanwhile, is valued around $300 billion and could grow tenfold by the end of the decade thanks to the innovation made possible by the GENIUS Act." US Treasury Secretary Scott Bessent. The institutional yield platforms wrapping that float are the channel it will move through, and they are launching now. None of them can ship into an allocator without an independent rating on the underlying DeFi exposure and parametric cover on the same exposure. Those are the two unticked boxes on every DD pack and every compliance memo. Whoever rates and covers the first cohort of stacks sets the rubric the next cohort is benchmarked against.
Verdict is built by a founding team spanning smart-contract engineering, institutional operations, and DeFi growth, with backgrounds across security auditing, energy markets, and Web3 infrastructure. The methodology is the product of that mix: engineering rigor applied to an analyst's problem.
Priced to map onto where DeFi loss actually originates.
Ratings. Subscription access to the catalogue and API: Free $0, Pro $200 per month, Enterprise $24,000 per year.
Coverage requests. An entity can ask to be covered, or to have coverage expedited. The resulting rating is public either way, and it is scoped case by case rather than read off a rate card, so talk to us.
PLRA (Pre-Launch Risk Assessment). A one-time managed pre-launch assessment against a 106-control NIST CSF v2.0 framework. $500 flat.
WhiteHat. A static-first security scanner with LLM triage, commissioned per scan. $50 per scan, Pro-gated.
Pen testing. Delivered by vetted partner firms through the marketplace, scoped and priced per engagement by the partner. Verdict does not run a rate card for it.
Cover. A parametric cover marketplace seeded by the rating. 0.10% on redemption plus a 0.50% AMM share, a $2,500 one-time pool-creation fee, and a $5,000-plus monthly institutional API tier.
Because the full-stack view is what turns a pile of siloed scores into due diligence.
Risk in DeFi is inherited, not isolated, and no single-surface tool prices it that way. The $16.6B loss record splits across three domains with three different owners: roughly $9.4B (56%) off-chain through keys, custodians, and frontends; $5.6B (33%) on-chain contract logic; and $1.5B (9%) governance, dependencies, and fraud. A product that covers one of those covers at most a third of the problem.
The services map onto those domains: PLRA on off-chain operations, WhiteHat on contract logic, Ratings on the ecosystem and governance surface, and the marketplace on the audit and monitoring work Verdict does not do itself. Cover prices the result.
What no competitor does is model how the domains compound. Verdict scores the dependency graph, Protocol to Chain, Oracle, Token, Org, Bridge, and Vault, and caps a protocol's effective risk by the worst of its dependencies, because an attacker takes the cheapest path in. An externally-owned-account admin key (a PLRA finding) multiplies the blast radius of a contained logic bug (a WhiteHat finding): medium and medium become catastrophic together. A-rated code reading a permissionless oracle inherits that oracle's manipulability and is capped accordingly. The full-stack view is the only place these cross-service effects can be computed.
Ratings
The pipeline is researcher-led, AI-assisted, human-reviewed. A researcher prepares an evidence pack for the entity under review (PLRA, pen testing, code, docs, on-chain history, governance posture, organisation footprint). An upskilled AI agent then scores each domain in turn against a domain-specific prompt, returning a score, a rationale, and a citation back into the evidence for every one of the 300+ criteria. A human reviewer overrides any low-confidence output, flags team-questions for outreach, and confirms cited evidence. The publish flow then runs the 7 mandatory minimum viable criteria gates, computes the composite deterministically, and writes the per-domain breakdown to the ratings API.
Three structural separations. Subscription pricing for the rated entity is structurally separate from the rating itself. A protocol does not buy its score, and the rubric is the same a paying Enterprise subscriber reads on the API. Domain weights, criteria, evidence requirements, and scoring logic all sit in source, and every revision is a reviewable diff. The cover pool then prices what the rating gets wrong: under-priced premiums clear too fast and the AMM re-prices upward; over-priced premiums sit unfilled and the AMM re-prices downward. Every block, the cover pool grades the rating in basis points. And the incentive behind all three is neutral: Verdict's fee is the same whether a hack fires or not (redemption, pool-creation, and AMM-share fees are direction-neutral), the Ratings and Cover teams are separated, and compensation is not tied to Cover volume. Verdict sets only the opening premium; the market sets every price after.
Verdict's model is reader-pays, not issuer-pays: the entities we rate are not the ones paying us, which removes the classic ratings-agency conflict.
The security partner marketplace sits on the same separation. It routes buyers to vendors; the rating function is structurally separate from it; and buying services through it never moves a grade.
Today: our pipeline plus human review on every published change. Where this is going: agents that pay for access can flag stale answers and earn bounties for verified corrections, agent-maintained and human-governed.
Every entity scores on a 0 to 100 composite that rolls up to a 10-tier letter scale: AAA (95-100), AA (88-94), A (80-87), BBB (70-79), BB (60-69), B (50-59), CCC (40-49), CC (30-39), C (20-29), and D (0-19). The same scale applies across all 7 entity classes, calibrated so a grade means the same thing whatever the entity: a AAA chain and a AAA protocol have been measured to the same composite band. The letter is the headline; the per-domain breakdown and the cited evidence behind it sit underneath on the ratings API.
The headline grade prices the whole stack. Every dependency the entity has chosen (the chains it runs on, the oracles that price it, the bridges it crosses, the organisations that operate it) drags the grade by 2% per notch below B, scaled by criticality, capped at 30%. Certain structural failures in a critical dependency cap the grade at CC outright. Dependencies we have not yet rated are flagged, never treated as safe.
Ratings move with the underlying. The data layer is a live pipeline rather than a quarterly snapshot: protocol TVL and flow, uptime and feed integrity, security and exploit signals, plus a wider mesh of contract-level and market-data sources sit behind the scoring for live updates. The composite recomputes on a schedule and on an exploit-monitoring trigger; a published rating that drifts on fresh evidence is re-scored against the same rubric and re-published with the new composite.
The response sequence is automatic. Live exploit monitoring detects the event through three independent inputs: Chainlink Runtime Environment on-chain anomaly detection, audit-firm bulletins routed through the data aggregator, and live data to disambiguate signal from noise. On contact with a probable exploit, the affected cover pool's CLAIM issuance auto-pauses; the rating recalibration request fires through the scoring pipeline instantly, not in weeks; and Coverage Seekers and Providers are notified through on-chain events and Verdict alert infrastructure. Resumption of issuance is gated. Post-incident analysis, recalibrations are republished, and governance approval all close before the mint surface re-opens. The rerate is observable, dated, and citable.
The methodology is the first check. The rubric is published in full to Enterprise users, the calibration corpus (556 incidents and ~$16.6B in losses, sourced from DefiLlama, mapped to 62 canonical defense-requirements) is named, and any sophisticated reader can reproduce the score against the cited evidence. The coverage claim is measured, not asserted: the 62 requirements were stress-tested by an independent skeptic asking whether a protocol could score full marks and still be hacked, and the stack robustly covers around 47, with 15 named as needing strengthening. A reviewer who disagrees can re-run, can challenge, can argue on equal footing because the pipeline is deterministic enough to be testable. The cover pool is the second check, and the more expensive one. The AMM is a continuous, on-chain, basis-point referendum on whether the rating is right, denominated in the same units the rating was meant to predict; a wrong call costs the pool, and a wrong pool costs the rating. The third check is exploit monitoring: detection runs off independent inputs, so the auto-pause and the recalibration trigger are not in the rater's discretionary path. The discipline is the loop, not the logo.
Verdict Pre-Launch Risk Assessment is a fixed-price managed engagement that produces a launch-readiness package for early-stage DeFi protocols. $500 flat per engagement, fully managed, with no Pro subscription required to buy it. The assessment runs as a single working session of around two hours: we take you through the 106 controls mapped to the NIST CSF v2.0 functions, you supply the evidence behind each one, and your maturity is scored control by control. The report is issued as a confidential PDF the moment the session ends: every critical and high finding mapped to its control with a concrete remediation, control-by-control detail with tier definitions, and a two-minute executive summary. It is designed to sit in a DD pack. Continuous contract surveillance is handled separately by WhiteHat, for teams that want findings to keep alerting after launch.
It is not an audit replacement. The audit shop reviews code for vulnerabilities. The PLRA reviews launch-readiness across a broader surface (smart-contract architecture, oracle configuration, governance design, organisational dependencies, bridge exposure, and documented incident-response procedures) evidenced in the same written PDF. The audit does not satisfy the launch-readiness checklist in a risk memo; the PLRA does not satisfy the audit clause in an investor LOI. Buy both; they address different questions.
Three buyer profiles commission a PLRA. Pre-launch protocol teams across any DeFi sector that need a structured, evidenced assessment. Existing Pro or Enterprise customers launching a new product line or a chain expansion where the prior assessment no longer covers the changed surface. Smaller protocols that cannot justify a $50,000 to $200,000 audit retainer but need a launch-readiness signal at a price-point that does not consume runway.
WhiteHat is Verdict's security scanner, sold as a standalone product. Static-first analysis runs across the codebase and an LLM triage layer ranks and explains what it finds, filtering noise before it reaches the team. Scans are commissioned per scan from the dashboard; when a contract changes or a new deployment ships, commission a re-scan and the new findings reach the team the same way.
It is Pro-gated and billed at $50 per scan. PLRA is the one-time pre-launch assessment; WhiteHat is the scan layer that keeps the picture current after launch. Teams commonly run a PLRA before launch and re-scan with WhiteHat as the code changes.
Two paths.
Path A. Public request form at verdict.finance/contact. Open to anyone. Submit the form (protocol name, category, website, deployed chains, contact details). Verdict reviews every submission within three business days and replies with one of three outcomes: approved for organic rating; commission quote; or not a fit at this time.
Path B. Dashboard Commission tab. Customers can commission a rating directly through the dashboard.
Pricing scales with engagement scope across three tiers.
Typical turnaround is two weeks depending on the number of dependencies being rated in parallel.
No. PLRA stands on its own. It is a $500 fixed-price engagement with no Pro subscription and no prior rating required, so a pre-launch team can commission it as a first touch with Verdict.
A rating and a PLRA answer different questions and reinforce each other. The rating scores the entity against the 300+ criteria rubric; the PLRA scores launch-readiness against the 106-control framework and hands back a prioritised remediation list. A team that holds both gets a published score for allocators and a dated, evidenced readiness package for its own DD pack. Neither is a precondition for the other.
Protocols Verdict rates organically as part of its public roadmap are already on the catalogue, so for them a PLRA simply sits alongside a rating that already exists.
It depends on the nature of the change. Two rules govern re-rating.
Same protocol team, same chain set, non-structural updates: the rating auto-recomputes against the latest data. No extra charge. The continuous-surveillance pipeline picks up the change and rescores accordingly.
Major refactor, new product line, new chain deployment with materially different contract logic, or a change to the oracle or bridge configuration that is structurally different from the original scope: a new commission is required at the appropriate tier.
The Pen Test Marketplace routes web and dapp penetration testing to vetted partner firms. The testing reviews the frontend and dapp surface that exposes a protocol's contracts to users, where Ratings, PLRA, and WhiteHat focus on the contracts and the framework around them. It runs in two modes: an invasive mode that actively probes the frontend and may briefly disrupt the running site, and a report-based mode that finds issues through passive scanning with no active probing; the customer picks on risk appetite. Verdict does not operate the tests. They are delivered by vetted partner firms through the marketplace, scoped and priced per engagement by the partner.
Verdict Cover
A cover pool is a CLAIM/NOCLAIM dual-token AMM, seeded by the rating. Three roles populate the pool: a Liquidity Provider deposits USDC and receives CLAIM plus NOCLAIM, holding both to expiry while earning AMM trading fees; a Coverage Provider deposits USDC, sells the CLAIM into the AMM, and holds the NOCLAIM to expiry, keeping the premium and principal if no exploit fires during the coverage period; a Coverage Seeker pays USDC for the CLAIM and redeems if an exploit hits during the coverage window.
Yes. The rating is the system's first-pass estimate of the expected loss the pool is pricing, and the AMM seed is a deterministic function of the composite. As an example, AAA seeds at 98/2, an opening premium around 1%. Lower ratings seed higher; an illustrative BB-rated pool seeds at roughly 80/20, a 12% premium baked into the opening ratio. From there the market is free to disagree by trading: under-priced premiums clear too fast and the AMM re-prices upward; over-priced premiums sit unfilled and the AMM re-prices downward. That is the seam between ratings and cover. The rating becomes a price the moment a pool opens.
A bounded, on-chain claim path runs in roughly 9 days. Chainlink Runtime Environment detects the anomaly and proposes the assertion to UMA Optimistic Oracle, which opens a 48-hour dispute window backed by economic bonds on both sides. If undisputed, the assertion settles automatically; if disputed, UMA's voter set adjudicates. A 7-day governance backstop window then opens as a final safety period for genuinely anomalous edge cases (a manipulated detection, a corrupted feed, a classification ambiguity). At the end of the backstop, the payout fires and CLAIM holders redeem, as an example, 100 CLAIM for $100.
Each component does one job. Chainlink Runtime Environment is the claim execution layer. It watches for on-chain anomalies on covered contracts, proposes the assertion that triggers a payout, and runs the time-based parts of the flow. UMA Optimistic Oracle is the dispute layer: bonded proposers, bonded disputers, and a 48-hour window that settles automatically if undisputed and routes to UMA's voter set if not. Uniswap v4 hooks implement the CLAIM/NOCLAIM trading logic and the pool fee accrual. The AMM is a hook, not a fork. CCIP plus the Cross-Chain Token standard handles cross-chain settlement, so a pool open on Arbitrum can accept activity from any CCIP-supported chain without bridging risk hand-rolled into the cover layer.
Yes. The Coverage Provider role is open to the rated protocol itself. There is no structural constraint requiring the Coverage Provider to be a third party. A protocol treasury that holds a strong conviction about its own security posture can deposit collateral, sell CLAIM into the AMM at the opening seed, and retain NOCLAIM to expiry, earning premium income, AMM swap fees, and principal back on a clean window.
The worked example uses an Arbitrum / Aave v3 wrapped ETH pool, AAA-rated by Verdict (composite >95 on the [0,100] scale). The AAA rating seeds the AMM at an opening CLAIM/NOCLAIM ratio of 0.05/0.95, a 5% premium for $100 of coverage. The protocol treasury elects to act as Coverage Provider on 50% of the pool's total capacity, deploying $500,000 of USDC into the underwriting side. On Day 1 it receives 500,000 CLAIM plus 500,000 NOCLAIM; selling the CLAIM at $0.05 into the AMM realises $25,000 in premium income, in the treasury immediately. Over twelve months, an illustrative $5 million in secondary trading volume on the CLAIM/NOCLAIM pair produces approximately $25,000 in AMM swap fees at the 0.50% protocol share rate. On a clean expiry at Day 365, the 500,000 NOCLAIM tokens redeem at $1.00 each and the $500,000 principal returns. Total Year 1 to the protocol treasury: approximately $50,000 on $500,000 deployed, a 10% gross yield, with the premium realised up front, not at expiry.
The downside is bounded: if an exploit fires during the coverage window, NOCLAIM expires worthless and the principal does not return. The protocol retains the $25,000 day-one premium and any fees accrued before the pause. The $500,000 figure is a treasury decision; the same structure applies at any scale.
Verdict goes from a cost line to a revenue line for every rated protocol that opts in. Numbers are illustrative and an example only.
Discretionary cover relies on a committee or token-holder vote to adjudicate each claim, which means payout timing is unpredictable, payout amounts are negotiable after the fact, and pricing has no live mechanism keeping it honest. Parametric coverage settles claims against on-chain trigger conditions instead: exploit detection by Chainlink Runtime Environment, dispute by UMA Optimistic Oracle, payout by CRE. The path is bounded at roughly 9 days and every step is observable. Pricing is set by the rating-seeded AMM and re-priced by the market in real time. Parametric removes the discretion from claim payout; the rating removes the opinion from premium pricing.
Yes. CLAIM and NOCLAIM are ERC-20 tokens trading on the Uniswap v4 hook AMM for the duration of the coverage period. A Coverage Seeker who buys CLAIM can sell those tokens back into the AMM at any block. A Coverage Provider holding NOCLAIM can sell at any block to close the underwriting position before expiry. A Liquidity Provider holding both can take a directional view at any block by selling one side. Every position is a token, and every token is liquid.
Cross-chain settlement runs on Chainlink CCIP plus the Cross-Chain Token (CCT) standard. A Coverage Seeker on Ethereum can buy CLAIM on a pool whose home chain is Arbitrum; the premium settles back to the pool, and a payout, if it fires, settles back to the seeker, all over the same channel. The pool itself remains on its home chain; the cross-chain capability is in the token transport, not in the pool logic. Chains at launch will be Ethereum, Arbitrum, Base, Optimism, and Polygon. Cover markets open in September.
Business
Yield platforms are the beachhead: vault optimisers, staking aggregators, RWA wrappers and stablecoin-yield products that need institutional capital to trust them. Behind them: RWA and tokenisation, perps DEXes, lending, GambleFi, stablecoins, and pre-launch teams in any sector. The common thread is the same gate: before an allocator commits, someone asks who rates the underlying and who covers the loss.
Three subscription tiers: Free $0, Pro $200 per month, and Enterprise $24,000 per year. An entity can request coverage, or ask for it to be expedited, and that is scoped case by case rather than sold off a rate card. PLRA is a separate $500 managed engagement with no subscription required, and WhiteHat adds contract scanning at $50 per scan for teams that want it.
A $2,500 flat pool-creation fee per new cover pool, paid one-time by the pool initiator to cover methodology review, on-chain deployment, and oracle wiring.
Risk
Three named risks, one mitigation each. Smart-contract risk: the Cover layer is the most exposed surface; mitigation is in the form of multiple audits, formal verification, plus a public bug bounty post-mainnet to keep the surface continuously priced. Oracle dependency: triggers and pay-outs lean on external feeds; mitigation is Chainlink as primary and UMA Optimistic Oracle as the dispute fallback, with multi-source signal corroboration before a trigger fires. Low coverage demand: mitigation is in the form of creating new revenue streams for protocols.
External infrastructure and one corpus. Chainlink Runtime Environment: wired into the pool contract's claim execution and monitoring path. UMA Optimistic Oracle: for disputes, with the bonded proposer/disputer mechanic doing the adversarial work. CCIP/CCT for cross-chain transport. Uniswap v4 hooks for the AMM. LLM for the AI scoring layer, against the rubric inlined into the system prompt.
The methodology is private by design and gated to Enterprise customers only, who must sign an NDA. Copying it is not encouraged because the rubric's value comes from being utilised for DD checks. What is harder to copy is the loop itself. Replicating the 556-incident calibration corpus, the 62 defense-requirements, the 300+ criteria, and the years of revisions on the record is another challenge. Harder still is the dependency graph: no competitor scores it. Verdict rates Protocol to Chain, Oracle, Token, Org, Bridge, and Vault, so one rating carries the risk of everything the protocol stands on. Copying the loop requires both halves at once. A pure-data rater has no AMM seam to wire a rating into, and a pure-cover provider has no rubric to seed the premium with. The defensibility is in the mechanism.
We name them before the critics do. Four hold.
Off-chain controls are largely self-attested. Verdict can ask for evidence and increasingly require it, but cannot externally verify that a team generated its keys with a secure random source. A clean process score shows a team knows what good looks like, not that they do it under pressure.
The novel-exploit tail is open-ended. WhiteHat closes known patterns; it does not catch tomorrow's bespoke logic bug. It is a triage and evidence layer, not a guarantee, and human audit remains a necessary complement.
A rating is point-in-time unless monitored. Continuous re-scanning on upgrades, governance, and oracle changes is the mitigation, and a stale score carries a freshness stamp that degrades its confidence.
The corpus is bounded by what has been observed. Attack classes that have not yet entered the 556-incident record cannot be priced. The corpus and rubric are versioned, so every rating carries a stamp telling you which framework generation it reflects.