← home

Capability statement

deebug — security engineering & assurance

Security assessment for exchange and trading infrastructure.

Issued 19 September 2026 · deebug.io · research@deebug.io

We assess the seam where a trading platform loses funds — the matching engine, the order and settlement APIs, the custody path and the chain — as one connected surface rather than four separate audits. The work is done by engineers who build this infrastructure.

Capabilities

Exchange & trading systems

Trading engine & API assessment

Order lifecycle and state machine legality, balance locking and release, partial-fill accounting, fee and rebate arithmetic, settlement rounding, endpoint concurrency.

Wallet & custody review

HSM and MPC configuration, quorum and signing policy, key ceremony procedure, withdrawal approval flows, custodian integration code.

Proof of reserves

Merkle commitment design, user-verifiable inclusion proofs, liability completeness, attestation cadence and operating controls.

Smart contract review

Solidity and EVM review with executable invariants. Every finding ships with a proof of concept that fails before the fix and passes after.

Offensive security

Penetration testing

Web, API, internal network and admin interfaces. Business-logic led, not scanner output. Retest included.

Red team & adversary simulation

Objective-based, assumed-breach exercises against real detection and response capability.

Secure code review

Manual source review in .NET, Node, Java, Rust and Python — concurrency, state machines, money handling, trust boundaries.

Threat modelling & architecture

Design-stage review before code exists. Trust boundaries, failure modes, and the invariants the system must hold.

Cloud & platform

Cloud security assessment

AWS and GCP. IAM and privilege-escalation paths, network exposure, secrets handling, logging coverage, workload posture.

DevSecOps & supply chain

CI/CD privilege and artefact integrity, IaC review, base image and dependency exposure, SBOM and signing.

Node & RPC infrastructure

RPC surface and rate limiting, management interface reachability, signing host key storage, lateral movement.

Detect & respond

Deception & detection engineering

Honeypots, canary tokens and tripwires placed where an intruder would step, wired into alerting that is read.

Incident investigation

Timeline reconstruction from logs and on-chain data, scope of compromise, containment, defensible root-cause reporting.

IR readiness & tabletop

Runbooks, escalation paths and decision authority agreed in advance, then exercised against a realistic scenario.

Assurance & governance

IT audit & general controls

ITGC across access management, change control, segregation of duties and operational monitoring.

ISO 27001 & SOC 2 readiness

Control design, gap analysis and evidence preparation. Certification is issued by accredited bodies, not by us.

vCISO & programme leadership

Fractional leadership on retainer: roadmap, risk register, vendor review, board reporting.

Bug bounty programme

Scope and policy drafting, safe-harbour terms, severity and reward tables, and day-to-day triage of inbound.

Method

We write down what the system claims to guarantee, turn each claim into an executable invariant, and drive the assessment by attempting to violate them. A fuzzer breaking an invariant is evidence; everything else is a hypothesis until reproduced. Concurrency and time are treated as inputs, because the highest-severity defects in trading systems are only reachable under interleaving.

Engagements run in five stages: scope and rules of engagement, threat model, testing, reporting, retest. Critical findings are reported the moment they are confirmed rather than held for the report.

Frameworks

OWASP ASVSOWASP WSTGOWASP API Top 10PTESNIST CSFNIST SP 800-115ISO/IEC 27001SOC 2CIS BenchmarksMITRE ATT&CKCCSSSCSVS

Engagement & commitments

retainer
Continuous review across releases with agreed response times and a monthly allocation of days. The default for teams shipping regularly.
fixed scope
A defined assessment with report and retest.
incident response
Engaged during or immediately after an incident. Containment first.
advisory
Design review and threat modelling before code is written.
lead time
Engagements start in days. We do not operate a multi-week queue.
named delivery
The person who scopes the work does the work. No handover to an unnamed researcher pool.
retest
Included and repeated until the finding is closed. Not billed as a second engagement.
after the report
We stay reachable. Fixes and follow-up questions are part of the engagement.

Delivery

report
Each finding carries root cause, reproduction steps, a proof of concept, impact in your terms, a remediation diff, and the invariant it violates. A worked example is published at deebug.io/sample-report.
invariant suite
The invariants extracted during the engagement are handed over so regressions fail your build rather than waiting for the next assessment.
debrief
Walkthrough with the engineers who own the code, not only with management.

Principal

Prasanta Sahoo — builds and operates the systems this practice assesses. Work spans centralised exchange infrastructure (matching engine, order management, ledger and settlement) across a large microservice estate; institutional FX market-making systems in Rust, including FIX and ITCH protocol handling and colocated execution; custody integration over MPC and HSM-backed signing; token issuance and vesting contracts; brokerage and copy-trading platforms; and an ISO 27001 programme across a multi-service production estate.

Terms

authorisation
Testing is carried out only under written authorisation within agreed scope. We do not accept work against systems a client does not own or control.
nda
Signed on request, before scoping.
sensitive material
An encrypted channel is agreed at scoping. Findings and evidence are encrypted at rest and never shared with third parties.
data retention
Client data is held only as long as the engagement requires, then destroyed on request.
confidentiality
Client names are not published and engagements are not referenced publicly without written permission.
references
Available under NDA for qualified engagements.

Contact

enquiries
research@deebug.io
disclosure
security@deebug.io
web
deebug.io

Print or save as PDF with Cmd/Ctrl-P — this page is formatted for A4.