CertiK
CertiK is a blockchain security and on chain risk intelligence firm running three connected businesses. Its audit practice combines manual review by security engineers with formal verification and proprietary tooling that automates vulnerability detection, with more than 5,500 audits completed. Skynet is a continuous scoring system covering more than 17,000 projects, exchanges and wallets, publishing a security score built from six named categories spanning code security, fundamental health, operational resilience, governance strength, market stability and community trust, with sub methods that include audit coverage measured by source lines of code, token behaviour scanning for privilege misuse and mint or burn risk, repository activity metrics and website vulnerability scanning.
SkyInsights is its on chain intelligence and risk analytics platform, providing entity attribution, behavioural classification and address and transaction risk scoring through a real time application programming interface, sold to exchanges, financial institutions and crypto custodians for anti money laundering and counter terrorist financing screening and integration with transaction monitoring engines.
Founded in 2017 by professors from Yale University and Columbia University, the firm holds ISO 27001 and SOC 2 Type 1 and Type 2 examinations scoped to the platform hosting its services, and publishes both its scoring methodology and that methodology's stated limitations.
Capability Axes
Capability grades
15 of 15 axes rated · 7 graded A or B
Three businesses sit at different distances from the models and the blend lands in the middle. The audit practice, which independent reporting places at roughly half of revenue, is led by security engineers performing manual review, with formal verification supplying mathematical proof rather than learned inference and proprietary tooling automating vulnerability detection and prioritising findings.
Skynet scores more than 17,000 projects continuously, and its published methodology describes weighted aggregation across named on chain and off chain indicators, with algorithms, machine learning and artificial intelligence stated as incorporated to reduce error rather than as the engine itself.
SkyInsights is the part that would not survive removal, since entity attribution and behavioural classification across wallets and transactions is model work of the same kind this index has already recognised in blockchain intelligence. Strip the models and an audit firm and a weighted scoreboard remain.
A human layer is named and placed in the audit path and no equivalent exists on the scoring path. Every audit is stated to include a thorough manual assessment by security professionals alongside the automated engines, which is a described position in the workflow rather than an assurance.
Skynet runs continuously and publishes scores without any described review step, threshold or approval before a score changes, and those scores are consumed by wallets, exchanges and listing decisions at the point where they affect whether a project reaches users.
The mitigating fact, and it is a real one, is that the methodology page states its own limitations plainly, including that the assessment is external, cannot see private internal security practices or closed source components, and represents a point in time.
Methodology disclosure is genuinely detailed and evidence about the method's quality is absent. The scoring framework is published down to component level across six named categories, with sub methods enumerated: audit coverage measured through source lines of code and similarity mapping, findings parsed into structured severity and remediation data, audit history weighted by the credibility and frequency of the originating auditor, token behaviour scanning, repository activity metrics and website vulnerability scanning.
The published limitations section is a further act of transparency. What is missing is the one thing this firm is uniquely positioned to supply: no back test showing whether high scores were followed by fewer exploits than low scores, no accuracy or calibration figure, no description of the machine learning components asserted in a single sentence, and no artificial intelligence management system certification.
The strongest single piece of evidence in this pocket, because a third party paid out on it. CertiK was awarded Sui's top bug bounty of six hundred thousand dollars for uncovering a critical vulnerability with the potential to shut down the network, which is a customer confirming a finding with its own money rather than a vendor describing its own value.
Around it sits substantial named work: formal verification of the TON network's consensus module, critical issues identified and resolved for SEI Protocol before mainnet launch, and monitoring for Bitget Wallet across more than 130 blockchains. Published scale is consistent across sources at more than 5,500 audits and more than 17,000 projects under continuous scoring. What is missing is any evidence about the scoring product's predictive quality, which is a different question from the audit record and is addressed on the model risk axis.
The dual position appears here in its most commercially explicit form found in this index. The firm audits projects, scores those same projects on a public leaderboard, and sells the scored projects promotional placement on the scoring surface, described as helping qualified projects showcase verified security and transparency signals across those surfaces and in selected co marketing moments.
Alongside that sits the published assertion that the assessment is independent and unaffected by project relationships. A second overlap runs in parallel: the score aggregates audit reports produced by other firms and assigns them weightings based on the originating auditor's credibility, so a competitor's work is graded by a competitor.
Nothing describes any separation between the audit business, the scoring business and the placement business, whether a paying project's score is computed by people insulated from that relationship, or what a project forfeits by declining to buy placement.
No data processing agreement, subprocessor list or retention schedule was located, and a privacy policy is referenced only through the site's cookie notice. The gap matters more here than the product description suggests, because SkyInsights aggregates, classifies and scores wallet addresses and transactions and performs entity attribution, which under most data protection regimes is processing that can identify a person even though the underlying ledger is public.
A financial institution buying this for screening would need to know what is retained, for how long, and whether attribution outputs about an individual are shared across customers, and none of that is addressed.
Real certifications, a dedicated trust and security page, and two scoping limits the firm discloses itself. ISO 27001 and SOC 2 Type 1 and Type 2 examinations are held, and a public bug bounty programme invites external researchers, which is a working security practice rather than a document.
The limits are that the examinations are stated as covering the platform hosting the services rather than the organisation as a whole, and that the report and certificate are available on request rather than published, so a buyer cannot see the scope, the controls or the exceptions without entering a sales process. Measured against the index benchmark, which publishes group wide scope and the implemented proportion of each control set, this is a grade below. The candour about scope is itself worth crediting, since a badge row that hid the boundary would read stronger and mean less.
The firm holds no financial licence, which is the correct posture for a technology supplier and carries no penalty here. Under the standing index rule its ISO 27001 and SOC 2 examinations are technical conformity assessments rather than regulatory standing and are credited on the security axis instead. No sandbox participation, supervised programme or regulator engagement was located.
One detail is worth recording without drawing a conclusion from it: the firm publishes guidance for other companies on obtaining SOC 2 and ISO 27001 credentials to satisfy banks and enterprise procurement, while its own examinations are scoped to its hosting platform rather than the organisation.
No fairness testing or differential outcome analysis is published, and the published methodology contains a structural tilt that is visible without any testing. Among the inputs to what is presented as a security score are a funding profile rated on capital raised, funding rounds and investor reputation, and a team identity component assessed through open source intelligence and third party verification.
A well funded project with recognisable investors therefore scores higher on security than an equally secure project without them, and the score is consumed by exchanges, wallets and users deciding whether to engage. Nothing states the weighting these components carry or whether the score has been examined for that effect.
The disclaimers are unusually clear and there is still no route for anyone harmed. The scoring methodology states that the assessment is not financial or investment advice, is limited to externally observable information, and represents a point in time, which is more candour than most of this index offers. None of that is recourse.
A project scored poorly on components it disputes has no stated appeal or correction path, a user who relied on a high score before an exploit has nothing, and no error rate, remediation commitment or liability position is published for either the scoring product or the audit engagements. For a firm whose entire proposition is that its assessment can be relied upon, the absence of a stated position on being wrong is conspicuous.
No model provider, family, version or hosting arrangement is disclosed. The published material states that algorithms, machine learning and artificial intelligence are incorporated into the scoring processes and that proprietary artificial intelligence tooling assists vulnerability detection during audits, and identifies none of it further. The hosting platform behind the services is named, which is more infrastructure disclosure than most vendors give, and it does not extend to the models.
The integration story is described by category rather than by counterparty. SkyInsights runs on a real time application programming interface framework and is presented as integrating with anti money laundering and counter terrorist financing systems, transaction monitoring engines and security infrastructures, which is the correct set of destinations for the product.
Skynet offers API integrations and its risk feeds are consumed by wallets, dashboards and exchanges, and a public partner API portal carries the scoring methodology documentation, which is more than most vendors expose. Held off the top grade because no specific transaction monitoring platform, case management system or core system is named as a supported integration and no integration count is published.
No hosting regions, residency commitments or tenancy model are published. Delivery is through real time application programming interfaces and public leaderboards, and the platform hosting the services is named in the certification statement, which is unusual disclosure and stops short of saying where that platform runs. An institution using the screening product inside a jurisdiction with data localisation requirements would find nothing to rely on.
No pricing is published by the vendor for any of the three product lines. One genuine disclosure sits against that: core Skynet analysis tools, leaderboards and dashboards are stated to be freely accessible, which tells a buyer something real about how the scoring product is distributed.
Third party reporting places audit engagements between roughly ten thousand and over three hundred thousand dollars depending on complexity, and that is treated here as a lead rather than a finding because it does not appear in the vendor's own material. The promotional placement product carries no published price either, which matters more than usual given what it is; see the stewardship axis.
Buyer types are named explicitly and the evidenced customers sit on one side of them. SkyInsights is stated as serving exchanges, decentralised finance protocols, financial institutions and crypto custodians for regulatory compliance and risk control, which is genuine institutional breadth on paper.
The customers actually named and described are crypto native rather than institutional: the TON network, whose consensus module was formally verified, SEI Protocol before its mainnet launch, Sui, and Bitget Wallet across more than 130 blockchains. Scale is substantial on both sides, with more than 5,500 audits completed and more than 17,000 projects covered by continuous scoring, and no bank, custodian or asset manager is named as a customer anywhere in the material reviewed.
Alternatives to CertiK
The closest documented capability profiles to CertiK in the same categories, ordered by similarity across the same fifteen axes the index grades every vendor on. Closest documented profile, not a claim that either product does the same job. No vendor pays for placement.
A lighter documented profile than CertiK
Stronger documented coverage on AI Centrality and Autonomy and Oversight Model
Stronger documented coverage on AI Centrality and Institution and Segment Coverage
Stronger documented coverage on AI Centrality and Core Systems and Integration Depth
Documents Regulatory Status and Licensure and Model Supply Chain Disclosure where CertiK does not
Documents GLBA and Data Privacy Posture and Regulatory Status and Licensure, among others where CertiK does not
Similarity is computed axis by axis from published grades, not from a composite score. The index does not aggregate grades into a total. See the fifteen axes and the methodology.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
No pricing data has been verified for this vendor. Pricing information will be published here once confirmed through vendor disclosure or third-party estimation.