> For the complete documentation index, see [llms.txt](https://docs.sherlock.xyz/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.sherlock.xyz/readme.md).

# Introduction to Sherlock

An overview of Sherlock, our security programs, and how these docs are organized so that teams can quickly find the right guidance for institutional security, AI, audits, bounties. Updated Oct 2026.

Sherlock provides lifecycle security for financial institutions and leading Web3 teams. We audit crypto codebases across languages and execution environments, with services spanning protocols, applications, and infrastructure.

Teams work with Sherlock on individual engagements or security program spanning development, launch, and live operation.

### How we approach security

Sherlock works with leading teams to secure the software and infrastructure powering the onchain economy. Our work supports organizations building new systems, operating established protocols, and bringing institutional capital onchain.

Since 2021, we have assembled a network of 11,000 independent security researchers, bringing together expertise across crypto ecosystems, programming languages, and system architectures. This collective knowledge forms the foundation of Sherlock’s security work.

We combine independent research, AI-powered auditing, and ongoing security programs to help organizations address security throughout the life of their systems. Our role extends from supporting developers as they build to working alongside institutions as they launch and operate onchain financial products.

Our goal is to make strong security a foundation for crypto’s growth, helping protect the infrastructure, users, and capital that depend on it.

### Complete Lifecycle Security

A system’s security requirements change as it moves from development to deployment and ongoing operation. Sherlock’s lifecycle security model connects work across these stages.

#### Development

Examine architecture, implementation choices, dependencies, and trust assumptions while the system is being built. Identify potential failure modes early enough to inform design and engineering decisions.

#### Pre-launch review

Review the code and its interactions before deployment or a major upgrade. Investigate vulnerabilities, assess their impact, and review proposed fixes within the agreed scope.

#### Live operation

Support ongoing vulnerability discovery through bug bounties and review changes to code, integrations, and system configuration. Institutional programs can also include custom monitoring and incident preparedness.

Carry prior findings and remediation decisions into subsequent security work as the system changes.

The scope of each engagement determines which services and stages are included.

### How teams work with Sherlock

#### Sherlock for financial institutions

Sherlock works with financial institutions and asset managers building and operating onchain financial products.

Engagements are structured around the institution’s architecture, dependencies, and operating requirements, from initial design through live operation.

#### Sherlock for leading Web3 teams

Sherlock works with teams building crypto protocols, applications, and infrastructure.

Engagements can cover new codebases, major releases, integrations, or changes to deployed systems. Teams can use individual services or combine them into a security program aligned with their development and release process.

### Core services

#### Collaborative Audits

Sherlock’s private audit service. A selected team of researchers reviews the codebase collaboratively, investigates potential vulnerabilities, documents validated findings, and reviews submitted fixes before final reporting.

The Collaborative Audits section explains scoping, preparation requirements, the review process, and reporting.

#### Audit Engine

Sherlock’s audit orchestration platform, bringing AI auditors, frontier models, and human security researchers into a coordinated review.

The engagement type determines the participant mix. Sherlock handles validation, deduplication, judging, and reporting. The Audit Engine section explains engagement types, workflows, and participation requirements.

#### Bug Bounties

Programs that give independent researchers a defined route to report vulnerabilities and receive rewards for eligible findings.

Each program establishes its scope, submission requirements, and reward rules. The Bug Bounties section explains program setup and participation.

#### Blackthorn

Sherlock’s premier privateaudit track, delivered by its elite research team for high-stakes infrastructure.

See the Blackthorn overview within Collaborative Audits for more information.

#### Institutional Security

Security programs for financial institutions and asset managers designing, launching, and operating onchain financial products.

Engagements combine threat modeling, architecture guidance, auditing, custom monitoring, and incident preparedness. The scope considers the wider system, including protocol dependencies, collateral, oracles, permissions, and operational processes.

Sherlock works alongside the institution across development and live operations, with services defined around its infrastructure and the ways capital could be put at risk.
