Capability statement
deebug — security engineering & assurance
Security assessment for exchange and trading infrastructure.
Issued 19 September 2026 · deebug.io · research@deebug.io
Capabilities
Exchange & trading systems
Trading engine & API assessment
Order lifecycle and state machine legality, balance locking and release, partial-fill accounting, fee and rebate arithmetic, settlement rounding, endpoint concurrency.
Wallet & custody review
HSM and MPC configuration, quorum and signing policy, key ceremony procedure, withdrawal approval flows, custodian integration code.
Proof of reserves
Merkle commitment design, user-verifiable inclusion proofs, liability completeness, attestation cadence and operating controls.
Smart contract review
Solidity and EVM review with executable invariants. Every finding ships with a proof of concept that fails before the fix and passes after.
Offensive security
Penetration testing
Web, API, internal network and admin interfaces. Business-logic led, not scanner output. Retest included.
Red team & adversary simulation
Objective-based, assumed-breach exercises against real detection and response capability.
Secure code review
Manual source review in .NET, Node, Java, Rust and Python — concurrency, state machines, money handling, trust boundaries.
Threat modelling & architecture
Design-stage review before code exists. Trust boundaries, failure modes, and the invariants the system must hold.
Cloud & platform
Cloud security assessment
AWS and GCP. IAM and privilege-escalation paths, network exposure, secrets handling, logging coverage, workload posture.
DevSecOps & supply chain
CI/CD privilege and artefact integrity, IaC review, base image and dependency exposure, SBOM and signing.
Node & RPC infrastructure
RPC surface and rate limiting, management interface reachability, signing host key storage, lateral movement.
Detect & respond
Deception & detection engineering
Honeypots, canary tokens and tripwires placed where an intruder would step, wired into alerting that is read.
Incident investigation
Timeline reconstruction from logs and on-chain data, scope of compromise, containment, defensible root-cause reporting.
IR readiness & tabletop
Runbooks, escalation paths and decision authority agreed in advance, then exercised against a realistic scenario.
Assurance & governance
IT audit & general controls
ITGC across access management, change control, segregation of duties and operational monitoring.
ISO 27001 & SOC 2 readiness
Control design, gap analysis and evidence preparation. Certification is issued by accredited bodies, not by us.
vCISO & programme leadership
Fractional leadership on retainer: roadmap, risk register, vendor review, board reporting.
Bug bounty programme
Scope and policy drafting, safe-harbour terms, severity and reward tables, and day-to-day triage of inbound.
Method
We write down what the system claims to guarantee, turn each claim into an executable invariant, and drive the assessment by attempting to violate them. A fuzzer breaking an invariant is evidence; everything else is a hypothesis until reproduced. Concurrency and time are treated as inputs, because the highest-severity defects in trading systems are only reachable under interleaving.
Engagements run in five stages: scope and rules of engagement, threat model, testing, reporting, retest. Critical findings are reported the moment they are confirmed rather than held for the report.
Frameworks
OWASP ASVSOWASP WSTGOWASP API Top 10PTESNIST CSFNIST SP 800-115ISO/IEC 27001SOC 2CIS BenchmarksMITRE ATT&CKCCSSSCSVS
Engagement & commitments
- retainer
- Continuous review across releases with agreed response times and a monthly allocation of days. The default for teams shipping regularly.
- fixed scope
- A defined assessment with report and retest.
- incident response
- Engaged during or immediately after an incident. Containment first.
- advisory
- Design review and threat modelling before code is written.
- lead time
- Engagements start in days. We do not operate a multi-week queue.
- named delivery
- The person who scopes the work does the work. No handover to an unnamed researcher pool.
- retest
- Included and repeated until the finding is closed. Not billed as a second engagement.
- after the report
- We stay reachable. Fixes and follow-up questions are part of the engagement.
Delivery
- report
- Each finding carries root cause, reproduction steps, a proof of concept, impact in your terms, a remediation diff, and the invariant it violates. A worked example is published at deebug.io/sample-report.
- invariant suite
- The invariants extracted during the engagement are handed over so regressions fail your build rather than waiting for the next assessment.
- debrief
- Walkthrough with the engineers who own the code, not only with management.
Principal
Prasanta Sahoo — builds and operates the systems this practice assesses. Work spans centralised exchange infrastructure (matching engine, order management, ledger and settlement) across a large microservice estate; institutional FX market-making systems in Rust, including FIX and ITCH protocol handling and colocated execution; custody integration over MPC and HSM-backed signing; token issuance and vesting contracts; brokerage and copy-trading platforms; and an ISO 27001 programme across a multi-service production estate.
Terms
- authorisation
- Testing is carried out only under written authorisation within agreed scope. We do not accept work against systems a client does not own or control.
- nda
- Signed on request, before scoping.
- sensitive material
- An encrypted channel is agreed at scoping. Findings and evidence are encrypted at rest and never shared with third parties.
- data retention
- Client data is held only as long as the engagement requires, then destroyed on request.
- confidentiality
- Client names are not published and engagements are not referenced publicly without written permission.
- references
- Available under NDA for qualified engagements.
Contact
- enquiries
- research@deebug.io
- disclosure
- security@deebug.io
- web
- deebug.io
Print or save as PDF with Cmd/Ctrl-P — this page is formatted for A4.