Terms of Service
Last updated: 31 August 2026
These terms apply to ongoing smart contract review retainers and one-time audits provided by Adomas Venslovas, trading as Alex Cipher. Anything agreed in writing for a specific engagement takes precedence over what is written here.
The two parts of an engagement
The Onboarding Review is a one-time engagement priced between $300 and $600, and it is required before ongoing review begins. It establishes a baseline understanding of the codebase you already have live: trust boundaries, privileged roles, value flows, and severity-rated findings in the current code. The exact fee inside that range, and your monthly Ongoing Review fee, are both determined during it, based on the actual size and complexity of the codebase.
Ongoing Review is a monthly retainer starting at $300 per month. It covers the codebase established during the Onboarding Review in two ways: each submitted diff is reviewed for security and exploitability, covering the changed code and the code paths that reach it; and, where contracts are unchanged, the deployed code is periodically re-checked against attack patterns that have become publicly known since the previous review. Both are covered by the same fee.
The monthly fee, the cadence and scope of review, and the turnaround on each diff are agreed in writing after the Onboarding Review, based on how often you ship and how much attention your existing contracts need. A minimum deploy frequency is not required. Turnaround is typically 3 to 5 business days per diff. Unused reviews do not roll over into the following month.
Teams deploying more frequently, or requiring a faster turnaround than the agreed cadence, can agree a higher-volume or expedited arrangement directly. Such arrangements are priced individually and agreed in writing before they take effect.
Scope is security and exploitability only
Reviews cover security and exploitability. They do not cover gas optimisation, code style, naming, architectural preference, or general code quality, and no finding of those kinds will be reported as part of a review.
This is a deliberate limit rather than an oversight: keeping the scope narrow is what makes the turnaround short enough to sit inside your deploy cycle.
A review is not a substitute for a full audit
Ongoing review covers what changes between deploys. It is not a substitute for a full audit before a major version release or a public launch, and it is intended to be paired with one.
You are expected to commission a full audit — from me or from another auditor — at those milestones. Nothing in a retainer should be represented to your users, investors, or exchanges as a full audit of your protocol.
Submitting diffs
You are expected to submit each diff at least 3 business days before the intended deploy, regardless of the turnaround agreed for your engagement. Turnaround is counted in business days from the point the complete diff and any required context are provided.
Submitting a diff later than that does not shorten the turnaround. Where a diff arrives too late to be reviewed before your deploy, the review is delivered on the normal turnaround and the deploy proceeds at your own risk.
Changes above the retainer threshold
New modules, new external protocol integrations, and major logic rewrites fall outside Ongoing Review and are quoted separately as their own scoped engagement, agreed in writing before that work begins.
Parameter changes, bug fixes, and incremental feature work on existing contracts are covered by the monthly fee. Where a submitted diff crosses the threshold, you are told when it is received, before any additional work or cost is incurred.
Minimum term and cancellation
Ongoing Review carries a minimum term of 3 months from the start of the first billed month. After the minimum term it continues month to month. The Onboarding Review is a one-time engagement and carries no minimum term.
Either party may end a month-to-month retainer with 30 days' written notice. Notice given during the minimum term takes effect at the end of it. Fees for months already begun are not refundable.
The monthly fee agreed at the start of the term is fixed for that term. Any change to it is agreed in writing before it takes effect.
One-time audits
One-time Full Audits are priced per project on the size and complexity of the agreed scope, fixed in writing before the work starts. Each covers a defined set of contracts at a defined commit or deployed address; code outside that scope is not reviewed.
If the scope changes after work has begun — new contracts, significant rewrites, or a materially larger codebase than described — the price and delivery date are re-agreed before the additional work is carried out.
Payment
Ongoing Review fees are payable monthly in advance. The Onboarding Review and one-time audits are payable before the work begins.
The agreed price is the total price for the agreed scope. There are no hourly overruns and no scope-creep invoices.
What a review is, and is not
A security review is a best-effort expert assessment carried out within an agreed time and scope. It is not a guarantee that the code is free of vulnerabilities, and it is not insurance, a warranty, or financial advice.
No review — from any auditor or firm — can prove the absence of bugs. Findings and recommendations are advisory: you remain responsible for deciding what to implement and for the security and operation of anything you deploy.
Liability arising from an engagement is limited to the fees paid for that engagement in the three months preceding the claim, to the extent permitted by law.
Confidentiality
Your code, diffs, findings, and correspondence are treated as confidential and are not published or shared without your written permission. A mutual NDA can be signed on request, before you send anything.
Reports are published on this site only where the client has agreed to it.
Intellectual property
You own your code. You receive the report and full rights to use it internally and to publish it, provided it is published unaltered and in full.
Reports and other material published on this site remain my copyright and may be quoted with attribution.
Contact
Questions about these terms can be sent to hello@alexcipher.xyz.