C

CertiK

CertiK is a blockchain security and on chain risk intelligence firm running three connected businesses. Its audit practice combines manual review by security engineers with formal verification and proprietary tooling that automates vulnerability detection, with more than 5,500 audits completed. Skynet is a continuous scoring system covering more than 17,000 projects, exchanges and wallets, publishing a security score built from six named categories spanning code security, fundamental health, operational resilience, governance strength, market stability and community trust, with sub methods that include audit coverage measured by source lines of code, token behaviour scanning for privilege misuse and mint or burn risk, repository activity metrics and website vulnerability scanning.

SkyInsights is its on chain intelligence and risk analytics platform, providing entity attribution, behavioural classification and address and transaction risk scoring through a real time application programming interface, sold to exchanges, financial institutions and crypto custodians for anti money laundering and counter terrorist financing screening and integration with transaction monitoring engines.

Founded in 2017 by professors from Yale University and Columbia University, the firm holds ISO 27001 and SOC 2 Type 1 and Type 2 examinations scoped to the platform hosting its services, and publishes both its scoring methodology and that methodology's stated limitations.

Last VerifiedAugust 19, 2026
Compare CertiK with other vendors
Founded
2017
Headquarters
New York, New York, United States
Website
www.certik.com
Categories
crypto-and-digital-assets, compliance-and-surveillance
Assessment

Capability Axes

Capability grades

15 of 15 axes rated · 7 graded A or B

AI Capability
AI Centrality
BB on AI CentralityThe models are the engine of a core capability, layered on a product that would still function without them as a rules or workflow system.
Vendor Published

Three businesses sit at different distances from the models and the blend lands in the middle. The audit practice, which independent reporting places at roughly half of revenue, is led by security engineers performing manual review, with formal verification supplying mathematical proof rather than learned inference and proprietary tooling automating vulnerability detection and prioritising findings.

Skynet scores more than 17,000 projects continuously, and its published methodology describes weighted aggregation across named on chain and off chain indicators, with algorithms, machine learning and artificial intelligence stated as incorporated to reduce error rather than as the engine itself.

SkyInsights is the part that would not survive removal, since entity attribution and behavioural classification across wallets and transactions is model work of the same kind this index has already recognised in blockchain intelligence. Strip the models and an audit firm and a weighted scoreboard remain.

Autonomy and Oversight Model
BB on Autonomy and Oversight ModelA written commitment that the models work alongside human judgment, with real review surfaces, short of the full control structure: commonly the threshold at which the system stops or what happens after it is wrong.
Vendor Published

A human layer is named and placed in the audit path and no equivalent exists on the scoring path. Every audit is stated to include a thorough manual assessment by security professionals alongside the automated engines, which is a described position in the workflow rather than an assurance.

Skynet runs continuously and publishes scores without any described review step, threshold or approval before a score changes, and those scores are consumed by wallets, exchanges and listing decisions at the point where they affect whether a project reaches users.

The mitigating fact, and it is a real one, is that the methodology page states its own limitations plainly, including that the assessment is external, cannot see private internal security practices or closed source components, and represents a point in time.

Model Risk Management and Transparency
BB on Model Risk Management and TransparencyReal transparency mechanisms are published, such as per alert explainability, confidence scoring or split testing, without the validation package or supervisory mapping behind them.
Vendor Published

Methodology disclosure is genuinely detailed and evidence about the method's quality is absent. The scoring framework is published down to component level across six named categories, with sub methods enumerated: audit coverage measured through source lines of code and similarity mapping, findings parsed into structured severity and remediation data, audit history weighted by the credibility and frequency of the originating auditor, token behaviour scanning, repository activity metrics and website vulnerability scanning.

The published limitations section is a further act of transparency. What is missing is the one thing this firm is uniquely positioned to supply: no back test showing whether high scores were followed by fewer exploits than low scores, no accuracy or calibration figure, no description of the machine learning components asserted in a single sentence, and no artificial intelligence management system certification.

Operational and Outcome Evidence
AA on Operational and Outcome EvidenceNamed customers with hard performance figures and enough method to test them.
Vendor Published

The strongest single piece of evidence in this pocket, because a third party paid out on it. CertiK was awarded Sui's top bug bounty of six hundred thousand dollars for uncovering a critical vulnerability with the potential to shut down the network, which is a customer confirming a finding with its own money rather than a vendor describing its own value.

Around it sits substantial named work: formal verification of the TON network's consensus module, critical issues identified and resolved for SEI Protocol before mainnet launch, and monitoring for Bitget Wallet across more than 130 blockchains. Published scale is consistent across sources at more than 5,500 audits and more than 17,000 projects under continuous scoring. What is missing is any evidence about the scoring product's predictive quality, which is a different question from the audit record and is addressed on the model risk axis.

AI Safety and Data Stewardship
CC on AI Safety and Data StewardshipGeneral assurances that do not answer the question this axis asks, which is whether one customer’s data trains models serving its competitors. Unbounded cross client learning stated with no boundary grades here too.
Vendor Published

The dual position appears here in its most commercially explicit form found in this index. The firm audits projects, scores those same projects on a public leaderboard, and sells the scored projects promotional placement on the scoring surface, described as helping qualified projects showcase verified security and transparency signals across those surfaces and in selected co marketing moments.

Alongside that sits the published assertion that the assessment is independent and unaffected by project relationships. A second overlap runs in parallel: the score aggregates audit reports produced by other firms and assigns them weightings based on the originating auditor's credibility, so a competitor's work is graded by a competitor.

Nothing describes any separation between the audit business, the scoring business and the placement business, whether a paying project's score is computed by people insulated from that relationship, or what a project forfeits by declining to buy placement.

Regulatory and Compliance
GLBA and Data Privacy Posture
CC on GLBA and Data Privacy PostureA standard privacy policy that covers the website rather than the service, or silence on a product that touches limited consumer data.
Vendor Published

No data processing agreement, subprocessor list or retention schedule was located, and a privacy policy is referenced only through the site's cookie notice. The gap matters more here than the product description suggests, because SkyInsights aggregates, classifies and scores wallet addresses and transactions and performs entity attribution, which under most data protection regimes is processing that can identify a person even though the underlying ledger is public.

A financial institution buying this for screening would need to know what is retained, for how long, and whether attribution outputs about an individual are shared across customers, and none of that is addressed.

Security Certifications and Trust Center
BB on Security Certifications and Trust CenterA recognised certification named in the vendor’s own material without the artefact, or with a scope or renewal question the buyer has to raise.
Vendor Published

Real certifications, a dedicated trust and security page, and two scoping limits the firm discloses itself. ISO 27001 and SOC 2 Type 1 and Type 2 examinations are held, and a public bug bounty programme invites external researchers, which is a working security practice rather than a document.

The limits are that the examinations are stated as covering the platform hosting the services rather than the organisation as a whole, and that the report and certificate are available on request rather than published, so a buyer cannot see the scope, the controls or the exceptions without entering a sales process. Measured against the index benchmark, which publishes group wide scope and the implemented proportion of each control set, this is a grade below. The candour about scope is itself worth crediting, since a badge row that hid the boundary would read stronger and mean less.

Regulatory Status and Licensure
CC on Regulatory Status and LicensureThe regulatory position is unstated. Most vendors in this index are technology suppliers and being unlicensed is the correct posture, so this grade records silence about the posture, not a missing licence.
Vendor Published

The firm holds no financial licence, which is the correct posture for a technology supplier and carries no penalty here. Under the standing index rule its ISO 27001 and SOC 2 examinations are technical conformity assessments rather than regulatory standing and are credited on the security axis instead. No sandbox participation, supervised programme or regulator engagement was located.

One detail is worth recording without drawing a conclusion from it: the firm publishes guidance for other companies on obtaining SOC 2 and ISO 27001 credentials to satisfy banks and enterprise procurement, while its own examinations are scoped to its hosting platform rather than the organisation.

AI Governance and Bias Disclosure
CC on AI Governance and Bias DisclosureResponsible artificial intelligence committed to in policy language with no evaluation behind it, on a product whose bias surface is modest.
Vendor Published

No fairness testing or differential outcome analysis is published, and the published methodology contains a structural tilt that is visible without any testing. Among the inputs to what is presented as a security score are a funding profile rated on capital raised, funding rounds and investor reputation, and a team identity component assessed through open source intelligence and third party verification.

A well funded project with recognisable investors therefore scores higher on security than an equally secure project without them, and the score is consumed by exchanges, wallets and users deciding whether to engage. Nothing states the weighting these components carry or whether the score has been examined for that effect.

AI Liability and Recourse
CC on AI Liability and RecourseMechanisms that enable challenge, such as audit trails and source traceability, with nothing standing behind the output and no route for the person affected.
Vendor Published

The disclaimers are unusually clear and there is still no route for anyone harmed. The scoring methodology states that the assessment is not financial or investment advice, is limited to externally observable information, and represents a point in time, which is more candour than most of this index offers. None of that is recourse.

A project scored poorly on components it disputes has no stated appeal or correction path, a user who relied on a high score before an exploit has nothing, and no error rate, remediation commitment or liability position is published for either the scoring product or the audit engagements. For a firm whose entire proposition is that its assessment can be relied upon, the absence of a stated position on being wrong is conspicuous.

Integration and Deployment
Model Supply Chain Disclosure
CC on Model Supply Chain DisclosureThe architecture is described and no provider is named.
Vendor Published

No model provider, family, version or hosting arrangement is disclosed. The published material states that algorithms, machine learning and artificial intelligence are incorporated into the scoring processes and that proprietary artificial intelligence tooling assists vulnerability detection during audits, and identifies none of it further. The hosting platform behind the services is named, which is more infrastructure disclosure than most vendors give, and it does not extend to the models.

Core Systems and Integration Depth
BB on Core Systems and Integration DepthNamed systems or a documented public API, with the depth or the production evidence left open.
Vendor Published

The integration story is described by category rather than by counterparty. SkyInsights runs on a real time application programming interface framework and is presented as integrating with anti money laundering and counter terrorist financing systems, transaction monitoring engines and security infrastructures, which is the correct set of destinations for the product.

Skynet offers API integrations and its risk feeds are consumed by wallets, dashboards and exchanges, and a public partner API portal carries the scoring methodology documentation, which is more than most vendors expose. Held off the top grade because no specific transaction monitoring platform, case management system or core system is named as a supported integration and no integration count is published.

Deployment Model and Data Residency
CC on Deployment Model and Data ResidencyCloud only with nothing stated, which is the category norm.
Vendor Published

No hosting regions, residency commitments or tenancy model are published. Delivery is through real time application programming interfaces and public leaderboards, and the platform hosting the services is named in the certification statement, which is unusual disclosure and stops short of saying where that platform runs. An institution using the screening product inside a jurisdiction with data localisation requirements would find nothing to rely on.

Commercial
Commercial Transparency
CC on Commercial TransparencyNo price is published and engagement runs through a demo form, which is the norm in this index.
Vendor Published

No pricing is published by the vendor for any of the three product lines. One genuine disclosure sits against that: core Skynet analysis tools, leaderboards and dashboards are stated to be freely accessible, which tells a buyer something real about how the scoring product is distributed.

Third party reporting places audit engagements between roughly ten thousand and over three hundred thousand dollars depending on complexity, and that is treated here as a lead rather than a finding because it does not appear in the vendor's own material. The promotional placement product carries no published price either, which matters more than usual given what it is; see the stewardship axis.

Institution and Segment Coverage
BB on Institution and Segment CoverageNamed segments with dedicated material behind part of the coverage.
Vendor Published

Buyer types are named explicitly and the evidenced customers sit on one side of them. SkyInsights is stated as serving exchanges, decentralised finance protocols, financial institutions and crypto custodians for regulatory compliance and risk control, which is genuine institutional breadth on paper.

The customers actually named and described are crypto native rather than institutional: the TON network, whose consensus module was formally verified, SEI Protocol before its mainnet launch, Sui, and Bitget Wallet across more than 130 blockchains. Scale is substantial on both sides, with more than 5,500 audits completed and more than 17,000 projects covered by continuous scoring, and no bank, custodian or asset manager is named as a customer anywhere in the material reviewed.

Alternatives to CertiK

The closest documented capability profiles to CertiK in the same categories, ordered by similarity across the same fifteen axes the index grades every vendor on. Closest documented profile, not a claim that either product does the same job. No vendor pays for placement.

A lighter documented profile than CertiK

Stronger documented coverage on AI Centrality and Autonomy and Oversight Model

Stronger documented coverage on AI Centrality and Institution and Segment Coverage

Stronger documented coverage on AI Centrality and Core Systems and Integration Depth

Documents Regulatory Status and Licensure and Model Supply Chain Disclosure where CertiK does not

Documents GLBA and Data Privacy Posture and Regulatory Status and Licensure, among others where CertiK does not

Similarity is computed axis by axis from published grades, not from a composite score. The index does not aggregate grades into a total. See the fifteen axes and the methodology.

Commercial

Pricing

Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.

No pricing data has been verified for this vendor. Pricing information will be published here once confirmed through vendor disclosure or third-party estimation.

Contact us

Found a vendor we missed? Have feedback on the index? We’d love to hear from you.

AI FinTech Index

The AI FinTech Index is an independent index that tracks changes to AI vendors in financial services. It holds 489 vendors across banking, lending, insurance, wealth, capital markets and financial crime compliance, each graded on the same 15 capability axes from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
September 5, 2026
The AI FinTech Index is an editorial reference, not a regulatory body. Vendor data is verified against published sources and public regulatory filings. Figures labeled “Estimated” have not been confirmed by the vendor. See the Methodology page for evaluation standards and limitations.
© 2026 AI FinTech Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746