Sayfer
Sayfer is a Tel Aviv-based Web3-native cybersecurity firm delivering penetration testing, smart contract audits, cloud infrastructure assessments, and crypto scam recovery services to blockchain protocols, DeFi platforms, exchanges, and Web3 projects globally.
- Company typePrivate
- Founded2019
- HeadquartersTel Aviv, Israel
- Headcount11–50
- GTM typeB2B
- OfferingServices
What Sayfer does
Sayfer is a Tel Aviv-based, privately held cybersecurity firm founded in 2019 by Nir Duan (CEO) and Or Duan (CTO) that delivers offensive-security services purpose-built for the Web3 and blockchain market. Its service portfolio spans AI-assisted penetration testing (using its proprietary OffensiveVector AI platform), line-by-line smart contract audits against the SCSVS standard, cloud infrastructure audits across AWS, GCP, and Azure, private key and wallet protection engagements, security consulting, and a specialized crypto scam recovery/forensics line (Sayfer Forensics). The company is Web3-native by design — covering smart contracts, blockchain architecture, DeFi protocols, and key management — rather than a traditional IT security firm extending into crypto. Publicly available audit reports for named protocols (1inch, Tezos, Polkadot, Sei Network, DIMO, Dusa, Leap Wallet, Bolide Finance) and client logos (MetaMask, Binance, StarkWare, eToro, Tenderly, ActiveFence) function as proof-of-work assets in the ecosystem.
The company monetizes through project-based professional services with quote-based pricing scoped after consultation calls, structured around tiered pen test offerings (Lite, Premium, Elite). Sayfer also derives a contingency-fee revenue stream from crypto scam recovery, charging approximately 50% of recovered assets on cases of at least $500,000. Go-to-market combines direct enterprise sales with a community-led channel via partnerships with five Web3 launchpads (Seedify, Gagarin, SamuraiStarter, SuperLauncher, BSCLaunch), supported by content marketing, public audit reports, conference presence, and Google remarketing. The firm is bootstrapped and founder-owned, with no disclosed venture or institutional investment, and operates globally from Tel Aviv with a headcount in the 11–50 range.
Sayfer firmographics
Firmographics- Name
- Sayfer
- Legal name
- Sayfer
- Website
- https://sayfer.io
- Company type
- Private
- Founded year
- 2019
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- Sayfer is a Tel Aviv-based Web3-native cybersecurity firm delivering penetration testing, smart contract audits, cloud infrastructure assessments, and crypto scam recovery services to blockchain protocols, DeFi platforms, exchanges, and Web3 projects globally.
- Ownership category
- akta.pro rank
Sayfer industry classification
Industry- Product category
- Web3 Cybersecurity Services
- NAICS
- Software Publishers (5132)
- SIC
- Telegraph & Other Message Communications (4822)
- akta.pro primary industry
- Digital Asset Risk, Security & Audit Tooling (Smart Contract Audit, Threat Monitoring) (FSAGAMAJ)
- akta.pro secondary industries
- Blockchain Analytics & Transaction Monitoring (FSADALAB), Risk Scoring, Credit & Fraud Analytics (counterparty/wallet risk) (FSAPAJAF), Verification & Risk Signals (Device Fingerprinting, Behavioral Biometrics) (HDADALAJ)
Keywords
Where Sayfer is headquartered
LocationHeadquarters
- HQ city
- Tel Aviv
- HQ country
- Israel
- HQ region
- Middle East
Offices1 record
Markets served
Sayfer business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations
Revenue model
- Professional Security Auditing Services: Sayfer generates revenue through project-based professional services including penetration testing (Lite, Premium, Elite tiers), smart contract audits, cloud infrastructure audits, and private key protection. Engagement scoping is done via consultation calls and pricing is quote-based per project.
- Crypto Scam Recovery / Forensics: Sayfer offers cryptocurrency scam recovery services on a 'no win, no fee' basis, charging approximately 50% of recovered assets upon successful recovery. Handles cases with stolen assets worth at least $500,000.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Other | Multi-year contract | Lite Pen Test – 2 to 4 weeks, targeting critical and low-hanging fruit issues using OWASP Top 10 and standard certifications (ISO 27001, SOC2). Includes retest, marketing package, and is approved by Binance, Metamask, and 1Inch. |
| Other | Multi-year contract | Premium Pen Test – 4 weeks, targeting complex and hidden risks using OWASP WSTG v4.2 and OWASP MSTG v1.1.4, with extended certifications including HIPAA and PCI DSS. |
| Other | Multi-year contract | Elite Pen Test – Monthly, fully customized plan and pricing. |
Go-to-market motion2 records
Distribution channels1 record
Marketing channels5 records
Sayfer product offering
Product offeringCore offering
Sayfer is a Web3-native cybersecurity firm delivering offensive security services to blockchain and crypto projects. Its core offerings include AI-assisted penetration testing (via the proprietary OffensiveVector AI platform), line-by-line smart contract audits, cloud infrastructure audits across AWS/GCP/Azure, private key and wallet protection, and end-to-end security consulting. The firm additionally provides a crypto scam recovery/forensics service on a contingent fee basis for victims of crypto fraud.
Product overview
Sayfer is a Web3-native cybersecurity company offering a comprehensive portfolio of security services. The core offerings include penetration testing using their OffensiveVector AI technology, cloud infrastructure audits (AWS, GCP, Azure), smart contracts audits, private key protection, and security consulting. Additional specialized services include crypto scam recovery/forensics and a Litepaper methodology providing holistic 360-degree cybersecurity roadmaps. The company serves blockchain/Web3 companies with services ranging from one-time audits to ongoing security partnerships.
Differentiator
Problem solved
Functional benefit
Brands
- OffensiveVector AI: AI-based penetration testing service that detects vulnerabilities through customized and controlled simulated cyber attacks.
Products and services
- Penetration Testing AI-assisted penetration testing delivered through Sayfer's proprietary OffensiveVector AI platform, which detects vulnerabilities in web, mobile, and API-based systems via customized and controlled simulated cyber attacks. Offered in three tiers — Lite (2–4 weeks, OWASP Top 10, ISO 27001/SOC2), Premium (4 weeks, OWASP WSTG v4.2, OWASP MSTG v1.1.4, ISO 27001/SOC2/HIPAA/PCI DSS), and Elite (monthly, fully customized). Includes retest, marketing package, and ecosystem approvals (Binance, MetaMask, 1Inch for Lite tier). Targets Web3 and technology companies seeking offensive security validation.
- Cloud Infrastructure Audit Security audits for cloud environments across AWS, GCP, and Azure, assessing configurations, IAM policies, storage permissions, networking, logging, and monitoring against industry standards. Designed to secure the infrastructure backbone of client systems beyond the application layer, with alignment to compliance frameworks such as SOC2, ISO 27001, HIPAA, GDPR, MiCA, and DORA.
- Smart Contracts Audit Comprehensive line-by-line source code analysis of smart contracts performed by expert auditors against the SCSVS standard. Identifies vulnerabilities in blockchain-based applications, with named engagements including 1inch Layer 2 calldata compression, Tezos and Polkadot MetaMask Snap audits, Sei Network MetaMask Snap, DIMO Reward.sol (14 vulnerabilities found), and Dusa DEX/AMM (17 vulnerabilities found). Targets DeFi protocols, Web3 dApps, and blockchain infrastructure projects.
- Private Key Protection Security services focused on protecting private keys and cryptocurrency wallets from theft and unauthorized access through comprehensive wallet security solutions and audits. Targets Web3 projects, crypto custodians, and individual or organizational holders of significant digital assets.
- Security Consulting Expert security advisory services covering all layers of Web3 projects from ideation to deployment, including cybersecurity roadmap development, implementation guidance, and continuous support. Includes the Sayfer Litepaper methodology providing holistic 360-degree cybersecurity roadmaps, historical hack analysis, and passive and active assessment.
- Crypto Scam Recovery and Forensics Cryptocurrency forensics and asset recovery services for victims of crypto scams, combining forensic analysis, open-source intelligence, and legal case preparation to help recover stolen funds. Offered on a 'no win, no fee' basis, charging approximately 50% of recovered assets upon successful recovery, with minimum case size of $500,000. Handles over $1B in assets secured through the Sayfer Forensics service line.
Quantifiable outcome
- $1.1B+ in assets secured through security audits
- +3 more outcomes
Companies that use Sayfer
Customer profileNamed customers12 records
Segments2 records
Ideal customer profiles2 records
Sayfer technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature2 records
Sayfer partnerships and signals
Strategic signalPartnerships
Six partnerships are on record, tiered core and supporting.
- SeedifycoreSeedify is a blockchain gaming-focused incubator and launchpad. Sayfer partners with Seedify to provide security services to new gaming and Web3 projects launching through the platform, enhancing user safety and platform credibility.
- GagarincoreGagarin is a comprehensive platform for project promotion, fundraising, development, and subsequent support. Sayfer partners with Gagarin to offer security auditing services to projects using the platform's launch and fundraising infrastructure.
- SamuraiStartercoreSamuraiStarter is a full-suite crypto startup accelerator and launchpad supporting innovative Web3 projects. Sayfer provides security services to SamuraiStarter portfolio companies as part of the partnership.
- SuperLaunchercoreSuperLauncher is an investment DAO for mass participation in early-stage and listed ventures. Sayfer partners with SuperLauncher to deliver security expertise to projects within its investment ecosystem.
- BSCLaunchcoreBSCLaunch is an all-in-one DeFi platform with its own launchpad serving both low-raise gems and ambitious projects on BNB Chain. Sayfer partners with BSCLaunch to provide security audits and penetration testing for projects launching on the platform.
- Litigation Firms and Law EnforcementsupportingSayfer Forensics partners with litigation firms and law enforcement agencies to support crypto fraud recovery cases, including asset freezes and other legal actions necessary for recovering stolen funds.
Scale indicators7 records
Recent moves6 records
Expansion highlights6 records
Sayfer competitors and assessment
Company assessmentDirect peers
- Nethermind: Blockchain engineering and security firm offering audits and formal verification across Ethereum and Starkware ecosystems — a partial peer with overlap in audit and security consulting.
- Trail of Bits: US-based cybersecurity firm offering smart contract audits, penetration testing, and security research for blockchain and Web3 projects — directly overlapping Sayfer's core services and target buyer profile.
- OpenZeppelin: Provides smart contract audits and security tooling for Ethereum and broader Web3 ecosystems; one of the most established names in the same niche Sayfer operates in.
- CertiK: Web3 security leader offering smart contract audits, formal verification, and on-chain monitoring — a well-funded direct competitor serving many of the same L1/L2 and DeFi clients as Sayfer.
- Quantstamp: Smart contract security and audit firm with a focus on Ethereum and DeFi protocols; competes with Sayfer for audit engagements across Web3 protocols.
- Hacken: Web3 cybersecurity company providing smart contract audits, bug bounties, and blockchain analytics — overlapping Sayfer's audit and forensics offerings for crypto-native clients.
- SlowMist: Blockchain security firm focused on smart contract audits, pen testing, and stolen-asset investigation — closely comparable in scope and similar scale to Sayfer.
- ChainSecurity: Smart contract audit firm with strong formal verification capabilities serving DeFi and infrastructure protocols; competes with Sayfer for higher-end audit engagements.
- Spearbit: Boutique smart contract security firm connecting projects with senior independent auditors; competes with Sayfer in the smart contract audit segment, especially for DeFi and L1 clients.
Broad incumbents
- HackerOne: Bug bounty and crowdsourced security platform serving enterprises including Web3 firms; not a direct audit peer but operates in the adjacent offensive-security market with broader enterprise reach.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat4 records
Key risks5 records
Key highlights6 records
Customer concentration
Sayfer social profiles
Digital presenceSayfer compliance and trust
Trust signalCompliance6 records
Sayfer financial estimates
Financial estimateRevenue estimate
Valuation estimate
Sayfer leadership team
Management profileNumber of profiles
Profiles3 records
Sayfer funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Sayfer M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Sayfer
What does Sayfer do?
Sayfer is a Web3-native cybersecurity firm delivering offensive security services to blockchain and crypto projects. Its core offerings include AI-assisted penetration testing (via the proprietary OffensiveVector AI platform), line-by-line smart contract audits, cloud infrastructure audits across AWS/GCP/Azure, private key and wallet protection, and end-to-end security consulting. The firm additionally provides a crypto scam recovery/forensics service on a contingent fee basis for victims of crypto fraud.
Is Sayfer a public or private company?
Sayfer is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was Sayfer founded?
Sayfer was founded in 2019. It employs 11 to 50 people.
Where is Sayfer based?
Sayfer is headquartered in Tel Aviv, Israel, in the Middle East region.
How does Sayfer make money?
Two revenue lines are on record. Professional Security Auditing Services are the primary driver. The others are crypto Scam Recovery / Forensics.
Who are Sayfer's main competitors?
Direct peers on record are Nethermind, Trail of Bits, OpenZeppelin, CertiK, Quantstamp, Hacken, SlowMist, ChainSecurity and Spearbit. HackerOne is listed as a broad incumbent.
Does Sayfer have an API?
No public API is recorded for Sayfer.
What industry is Sayfer in?
Sayfer's product category is Web3 Cybersecurity Services. Its primary akta.pro industry code is FSAGAMAJ, Digital Asset Risk, Security & Audit Tooling (Smart Contract Audit, Threat Monitoring), with a secondary code of FSADALAB, Blockchain Analytics & Transaction Monitoring. Its NAICS code is 5132 and its SIC code is 4822.