(For institutions)
Enterprise blockchain security programs.
Banks, asset managers, payments companies, and regulated fintechs run blockchain workloads in environments where one-off audits are not enough. Sigma Prime builds multi-year security programs against MSA-grade engagement terms — dedicated team, defined SLAs, RFP-ready documentation, and full procurement support.
(Procurement)
Built for procurement teams.
We have responded to formal RFPs from banks, payments processors, and asset managers. Documentation for procurement teams — corporate structure, insurance, data handling, and references — is available on request without going through a sales process.
Selected institutional engagements include the Ethereum Foundation Pectra hard fork review and multi-year programs for Tier 1 protocols. References available under NDA.
Request procurement information
(By the numbers)
Track record and standing.
-
10+ years
Operating
Continuous since 2016
-
>50%
Of Ethereum network on Lighthouse
Production protocol experience
-
AU
Jurisdiction
Sydney-based, Pty Ltd registered
-
140+
Public reports
github.com/sigp/public-audits
(Engagement model)
How institutional engagements run.
Institutional engagements at Sigma Prime are structured for procurement, legal, and security teams who need predictable terms across multi-year programs. The mechanics below are the default starting point — variations are accommodated where institutional policy requires.
-
01
Master Service Agreement
Standard MSA-based engagement structure. Statements of work issued under the MSA per release. Multi-year coverage available.
-
02
Defined response and delivery SLAs
Response-time and delivery-window SLAs documented in the MSA. Escalation paths for security-incident-class events documented separately.
-
03
Dedicated team
Named lead engineer and named secondary engineer per engagement. Continuity across releases. Escalation contact documented.
-
04
Insurance and posture
Professional indemnity insurance in place. Detailed insurance posture, data handling, and security practices are available during vendor review.
-
05
NDA-first engagement
Mutual NDA executed before any code or threat-model material is shared. Standard NDA terms available for review on request.
-
06
No subcontracting
All work performed by Sigma Prime employees. Subcontracting is not part of our model and is not used for engagement delivery.
(Program design)
What a multi-year security program needs to make clear.
A program is not a standing audit slot
The useful part of an enterprise program is continuity. The same Sigma Prime engineers learn the protocol, the release cadence, the threat model, the operational constraints, and the internal approval path. That context means each new review starts with less archaeology and more time spent on the security properties that changed.
This is different from reserving calendar time with no defined responsibility. We still scope work in writing. Each release, feature, incident-readiness exercise, or infrastructure review has an owner, a boundary, a delivery expectation, and a record of what was reviewed.
Scope is written per release
Large teams rarely ship one isolated codebase. They ship protocol upgrades, smart contract changes, frontend changes, governance proposals, infrastructure changes, and emergency patches. A program gives those workstreams a single commercial and legal frame, but the security scope is still written at the level where engineers can be accountable.
For an L2, that may mean separate SOWs for bridge contracts, fault-proof changes, sequencer infrastructure, and governance controls. For a DeFi protocol, it may mean recurring review of governance-driven upgrades, oracle changes, migrations, and frontend transaction flows.
Procurement work happens once; security work repeats
MSA-based programs exist because procurement, legal, vendor-risk, and security teams should not renegotiate the same baseline terms before every release. Insurance posture, data handling, NDA terms, references, and invoicing mechanics are handled up front so later SOWs can focus on the systems being reviewed.
The result is faster engagement without removing discipline. If the scope changes, the SOW changes. If a release introduces a new trust boundary, the program has to name it. Predictability is useful only when it preserves clear review boundaries.
What the program should produce
-
Written scopes for each release or workstream, including exclusions and assumptions.
-
Continuity of reviewer context across protocol upgrades, remediation rounds, and recurring feature audits.
-
Private reports, remediation review, and public reports where the client signs off on publication.
-
A known escalation path for high-severity findings, urgent review needs, or incident-class events.
-
Procurement-ready documentation that security, legal, vendor-risk, and finance teams can reuse.
(Why work with us)
Implementation experience matters at the protocol layer.
Sigma Prime maintains Lighthouse, the Rust Ethereum consensus client running on more than half of the Ethereum network. The same engineers who maintain Lighthouse run protocol-layer audit engagements. For institutional buyers reviewing their own validator infrastructure, Layer 2 deployments, or token-related contracts, this implementation experience is the differentiator.
We are also part of an Identified DVT Cluster on Lido alongside Nethermind, ChainSafe, and Develp, and operate as a sequencer on the Aztec network with a governance voting role. Operating production validator and sequencer infrastructure keeps us close to the systems we audit.
(Selected engagements)
Selected institutional engagements.
-
Ethereum Foundation
Pectra system contracts review (2025)
-
EigenLayer
10 engagements over 3 years across core contracts, slashing, rewards, EigenDA
-
Lido
Continuous coverage since the December 2020 launch
-
Aave
8 engagements through 2023, including Governance v3 and GHO stablecoin
(Get in touch)
Schedule a discovery call.
Discovery calls run 45 to 60 minutes and cover your current security program, the systems in scope, and the engagement model. There is no commitment from a discovery call — they are useful even if our engagement is not the right fit.
Schedule a discovery call
Services
Products
Resources
Company
Social
© Copyright 2026 by Sigma Prime. All Rights Reserved.
