Discuss the project

AI & Web3 Security

AI, LLM and Web3 security: smart contract audits and DeFi pentests in Ternopil, Ukraine

Security audits for AI applications and smart contracts, to OWASP standards, with a working exploit and a clear fix plan.

OWASP Top 10 Working PoC AI + Web3

We build and break the same systems, so we know where they break. Vapan covers the security of AI applications and smart contracts: two areas where the cost of a flaw is highest and few teams hold both at once. We work to international standards (OWASP) and hand over a report with a working exploit and a clear fix plan, not a list of warnings.

AI and LLM Security

AI agent and LLM application security audit

A full red team of your AI product to OWASP standards.

We test your LLM application or AI agent against real attacks, from prompt injection to data leakage and tool abuse. The audit follows OWASP Top 10 for LLM Applications (2025) and OWASP Top 10 for Agentic Applications (2026).

What we check
Prompt injection (direct and indirect), leakage of sensitive data and the system prompt, improper output handling, excessive agent permissions, RAG and embedding poisoning, uncontrolled resource use.
What you get
A report of vulnerabilities ranked by severity, with PoC scenarios and fix recommendations.
Price:
Quoted individually after scoping.

MCP server and agent infrastructure security audit

What ordinary scanners miss: the security of the whole agent system, not just the model's answer.

Most tools only check what the model says. We audit the whole agent stack: MCP servers, the tool chain, agent authentication and permissions, data leakage channels and the supply chain. Narrow expertise that is rare on the market.

What we check
MCP server security and authorization, tool poisoning, agent identity and privilege abuse, unsafe inter-agent communication, memory and context poisoning, integrity of skills and tools.
What you get
A report against the OWASP Agentic Top 10 with a risk map, a working exploit and a hardening plan.
Price:
Per project.

AI system protection (guardrails and hardening)

Not just find the holes, but close them without hurting the product.

We build layered protection: input filtering, hardened system prompts, output guards, and limits on permissions and leakage channels. We find the balance between safe and still convenient for users.

What you get
Controls in place and tuned guardrails, plus regression tests against a repeat break.
Price:
Per project or a support retainer.

Web3 and Smart Contract Security

Smart contract audit (Solana / EVM)

Protection for code where a mistake means an irreversible loss of funds.

A manual smart contract audit focused on the logic and economic flaws that automated scanners miss. We work with Solana (Rust / Anchor) and EVM (Solidity).

What we check
Access control and authorization, signer/owner checks, account confusion, arbitrary CPI, oracle safety (Pyth: confidence interval, staleness), Token-2022 extensions, PDA design, reentrancy and flash-loan or economic vectors (EVM).
What you get
A full audit report with severity ratings, PoC and recommendations, plus a re-audit after fixes if needed.
Price:
Depends on the size of the codebase.

Web3 and DeFi protocol pentest

Testing the protocol as a whole system, not just a single contract.

We test the protocol as a whole: contracts, oracles, integrations with other protocols (composability) and points of failure. The biggest DeFi losses come not from a complex bug but from broken authorization and logic.

What you get
A report with attack scenarios, a business-risk rating and a prioritized fix plan.
Price:
Per project.

Ready to test your AI or Web3 under pressure?

Describe your product or codebase and we will come back with a scope and a quote.

What else we do

Development, security, marketing and automation are often bundled. Browse related services and cases.