Skip to content
Representative engagements · Examples

How we approach high-stakes systems.

The examples below illustrate the shape of work AN3 can deliver across enterprise and onchain environments.

They are engagement patterns, not claims about named clients, measured results, or completed certifications. Scope and deliverables are tailored to each brief. Redacted sample findings can be shared under NDA during procurement.

Enterprise
Cloud · Identity · Applications

Cloud and application exposure review

Challenge

A growing organisation needs a clear view of attack paths across cloud accounts, identity controls, APIs, and internet-facing services.

Scope

Architecture review, authenticated testing, IAM analysis, API and application testing, and validation of high-risk paths.

Approach

Map the environment, form attack hypotheses, test them manually, and review findings with the engineering owners who will remediate them.

Typical deliverables

Prioritised findings, reproducible evidence, remediation guidance, an executive risk brief, and focused retesting.

Onchain
Contracts · Protocol · Governance

Pre-launch protocol security assessment

Challenge

A protocol team needs independent scrutiny of contract logic, privileged roles, economic assumptions, and operational launch controls.

Scope

Manual contract review, invariant and threat modelling, test-suite review, governance analysis, and deployment-process review.

Approach

Trace value and authority through the system, model adversarial behaviours, reproduce meaningful issues, and work directly with the builders on fixes.

Typical deliverables

Severity-ranked report, proof-of-concept tests where appropriate, fix guidance, remediation review, and a launch-risk summary.

Onchain
Token · Vesting · Launch ops

Pre-token launch security review

Challenge

A team preparing a token generation event needs the supply path, unlock schedule, liquidity setup, and privileged mint or pause roles checked before mainnet distribution.

Scope

Token and vesting contract review, emission and unlock modelling, liquidity and incentive attack paths, admin and rescue roles, and signer or deployment ceremony checks.

Approach

Map every path that can change supply, transferability, or voting power, pressure-test the schedule under adversarial capital, and walk the launch runbook with the operators who will execute it.

Typical deliverables

Severity-ranked findings, unlock and admin risk map, launch-day checklist, fix guidance, and a go / no-go summary for the generation event.

Enterprise
Enterprise operating context

Security and compliance readiness programme

Challenge

A regional or international team preparing for customer assurance or a formal audit needs controls that work in practice, not a paperwork-only exercise.

Scope

Gap assessment against the chosen framework, evidence mapping, technical control review, policy support, and remediation planning.

Approach

Start from the target requirements and current environment, identify material gaps, assign owners, and build an evidence rhythm the team can sustain.

Typical deliverables

Readiness assessment, control matrix, prioritised roadmap, evidence plan, and audit-support materials. Certification remains the auditor’s decision.

Enterprise + Onchain
Incident preparedness · Recovery

Cross-stack incident readiness

Challenge

A team operating cloud infrastructure and onchain assets needs one response model for identity compromise, application abuse, key risk, and protocol events.

Scope

Asset and dependency mapping, scenario design, communications paths, evidence handling, containment options, and tabletop exercises.

Approach

Build scenarios around the organisation’s actual architecture, rehearse decisions with technical and business owners, then close the highest-impact readiness gaps.

Typical deliverables

Response playbooks, escalation matrix, tabletop findings, containment checklists, evidence guidance, and a sequenced hardening plan.

Your environment is the brief

Tell us what is changing, exposed, or keeping your team awake.

We will shape the scope around your architecture, risk, and decision timeline.

Start a security brief ↗