Adversarial review · deterministic gates
Most AI dev shops prompt a model, eyeball the output, and hand you code you don't trust. I run every change through an adversarial multi-agent loop and deterministic safety gates — the same paranoid process I use on my own security tooling. You get software you can actually put in front of users.
The problem
The problem is the second half:
Speed without a safety net isn't a deal. It's a liability you haven't noticed yet.
How this works differently
Every unit of work runs a loop: an architect writes the design and the test spec → a coder implements it → a sandbox actually compiles, lints, and tests it → an independent reviewer tries to break it → it goes back until it passes. Nothing ships on "looks good to me."
Known-bad patterns are refused mechanically, not spotted by hand.
For application & backend code (Python, JavaScript/TypeScript, Go, Java): a deterministic crypto-misuse gate — 40 rules across 13 CWE categories, with thresholds drawn from NIST and OWASP. Hardcoded secrets, ECB/weak ciphers, disabled TLS verification, JWT alg=none, undersized RSA keys, IV reuse, and more — caught before they reach you.
For smart contracts: secure-by-design review against five structural red-lines — access control on every value transfer, declared reentrancy surface, a complete revert taxonomy, upgrade safety, and asset conservation — before you pay for a formal audit.
One of these safety gates passed 44 green tests. An independent reviewer still found it silently letting unsafe code through. I fixed it, then re-tested — 51 tests now. If that's the bar I hold my own quality checks to, imagine the bar for your code.
A second one, more recent. I keep a free tool that fills official PDF forms entirely on the user's own machine — nothing uploaded, stored, or logged. That promise is one careless import away from being false, so it isn't a promise: it's a gate that walks the real code path and fails on any network or shell-out capability. Its first green was wrong. I had written “you can't split the product path by directory” in the checker's own docstring — then used a directory pattern to pick the starting set, quietly excluding the file that writes the final output. The check was right; the set it ran over was not. That is the failure mode I look for in client work, and I found it in mine.
Proof · anatomy of a build
I designed a revocable token-vesting vault as a reference build — cliff + linear release, multiple beneficiaries, revocable unvested tokens, emergency pause.
Before a single line of implementation was written, the adversarial review caught a defect that would have made every call that touched that schedule revert until its start date arrived — a subtraction underflow hiding inside an otherwise-correct formula. It also flagged a missing pre-deploy audit requirement and an undefined return at the time boundary. All three were fixed and re-reviewed before handoff.
Or read the deep technical teardown → — the Solidity that shows the trap, the fail-open bug an independent review found in my own gate, and what this does not prove.
What this is, honestly
A design-and-specification engagement, hardened through two rounds of adversarial review. This does not replace a formal third-party audit before mainnet — it's the work that makes that audit cheaper and faster by getting the design right first. (This was a reference build, self-delivered — shown so you can see the process on real, safety-critical work.)
Who this is for
Not a fit if: you want the cheapest possible throwaway MVP and don't care about correctness, or you need a formal smart-contract audit — I feed one; I don't replace one.
Start small
Not ready to commit to a build? Start here. Send an existing codebase (Python / JS / Go / Java) or a smart-contract design. I run the deterministic gate that fits — a 40-rule crypto-misuse & secrets scan on app code, or the five structural design red-lines on a contract — plus one round of adversarial review, and hand you a prioritized findings report.
How engagements work
Gate Pass or scoping call. I look at what you have and tell you, plainly, what's solid and what isn't.
Fixed-scope build or retainer. I deliver through the adversarial loop + gates. You get the code, the tests, and the review trail.
You own everything. A human signs off on every delivery. The AI does the typing; the process makes it trustworthy.
FAQ
The model does the heavy lifting. The value is the adversarial process and deterministic gates around it that make the output trustworthy — and a human who owns every delivery. Anyone can prompt a model. The discipline is the product.
No. The contract work is secure-by-design and adversarial review at the design and spec level, meant to feed a professional audit before mainnet — and make it cheaper because the design is already right. I'll never tell you you're audit-free.
For app/backend code: 40 deterministic rules across 13 CWE categories (hardcoded secrets, weak crypto, TLS/JWT misuse, weak keys, and more), with thresholds from NIST and OWASP. For contracts: five structural design red-lines plus independent adversarial review.
Yes — read the build anatomy. I'm unusually transparent about my own process, including where it has limits.
Start with a fixed-price Security Gate Pass. Send code or a contract design; get back a prioritized findings report.
Book a Security Gate Pass →