Skip to content
Client Focus

Client Focus solution

Smart Contract Guard 360

Smart contract analysis and continuous compliance monitoring for organizations operating on public chains. Smart Contract Guard 360 (SCG360) is designed to run inside the client's environment, bringing contract findings, control evidence and change monitoring into one governed workflow.

Four capabilities, one controlled process

SCG360 brings analysis, monitoring, threat modeling and enterprise integration into a single service. The analysis engines are open source; Client Focus builds and operates the layers that orchestrate them and connect their results to client controls.

01

Automated contract analysis

SCG360 orchestrates Slither, Mythril, Foundry and Echidna in isolated, parallel runs. Analysis covers contract vulnerabilities, upgradeable proxy patterns (UUPS, transparent and beacon) with storage-layout diffing across versions, economic dependencies, and governance attack paths. Oracle and price manipulation exposure is tested through fuzzing and AI-proposed hypotheses confirmed against on-chain state. Formal verification tools can be integrated for critical invariants.

02

Continuous compliance monitoring

A four-step loop triggers, scans, maps findings to controls and reports results on commit, on release and on defined on-chain events. Findings map out of the box to NIST CSF, ISO 27001 annex controls, DORA ICT risk requirements, MiCA and the OWASP Smart Contract Top 10, alongside the client's own control framework. Changes to implementations, proxy administrators, ownership or guardians invalidate the existing certificate and trigger reassessment.

03

AI-assisted threat modeling

Models running inside the client environment propose business-logic, economic and access-control hypotheses. A finding counts only after deterministic confirmation. AI can draft exploit scenarios and remediation guidance from confirmed findings, with outputs fixed to the analyzed bytecode hash.

04

Enterprise integration

REST APIs and CI/CD hooks connect analysis to the release process. Role-based access, an audit trail, portfolio views and exportable reports support engineering, risk and audit teams.

From change to evidence

Analysis is part of the release and monitoring cycle, not a one-time report.

  1. 01

    Trigger

    A code commit, release or defined on-chain event starts a review.

  2. 02

    Scan

    Multiple engines analyze the contract in sandboxed runs.

  3. 03

    Map

    Confirmed results are mapped to the client's control framework.

  4. 04

    Report

    Versioned evidence is issued for engineering, risk and audit.

A verdict that can be reproduced

Rules determine the conformance verdict. AI helps explain and investigate; it does not decide whether a contract conforms.

Certificates bind a result to a bytecode hash and pinned engine and ruleset versions. A status registry distinguishes valid, superseded and withdrawn results. Where a client requires public verifiability, the certificate hash is anchored to an on-chain attestation registry, so any party can confirm a verdict without access to the contract source.

The certificate reports the automated basis of its conclusion. It is not a manual audit and does not certify network configuration or settlement governance. The client retains authorship of its internal control framework.

Colleagues reviewing security controls and assessment evidence together

Designed for the client environment

SCG360 is designed for deployment in a client VPC or on-premises environment. Contract source, bytecode and model inference remain inside that boundary.

Inside the client boundary

Analysis engines, self-hosted open-weight models, contract code and the client control overlay operate within the client environment.

Metadata-only control plane

The Client Focus control plane processes hashes, verdicts and version identifiers, not contract source or bytecode.

Implementation before continuous service

Client Focus provisions the environment, calibrates the engines and models, connects the compliance loop, and validates the workflow against an agreed benchmark corpus before go-live acceptance. Continuous service begins after acceptance.

The initial scope, supported chains, contract languages, acceptance criteria and service levels are agreed with each client. The reference scope starts with EVM and Solidity, with a staged expansion path to Rust-based chains such as Solana and to Move-based chains as engine support matures.

Client Focus operates the control plane, calibrates and updates the engines and rulesets, and runs the compliance loop under agreed service levels. The client's engineers retain ownership of contract code, release decisions and remediation; SCG360 supplies the evidence, and named Client Focus operators remain accountable for its accuracy.

Analysis connected to operations

SCG360 supports the contract assurance workflow. C'ROC watches live on-chain activity and manages security events through a separate operational process.

Continue reading

Build

Engineering and integration for systems that will run on public chains.

Discuss contract assurance with Client Focus.

Review your contract portfolio, control requirements and deployment boundary with a principal of the firm.