Oak Security
Oak Security is a Munich-based, bootstrapped Web3 security firm founded in 2017 that audits smart contracts, protocols, and bridges across EVM, Cosmos, Solana, and Polkadot ecosystems, serving crypto protocols and foundations with audits, operational security, vCISO, and advisory services.
- Company typePrivate
- Founded2017
- HeadquartersMunich, Germany
- Headcount11–50
- GTM typeB2B
- OfferingServices
What Oak Security does
Oak Security GmbH is a Munich-based, founder-led Web3 security firm founded in 2017 that provides security auditing, operational security, and advisory services to crypto protocols, decentralized applications, and blockchain foundations. The company's core offering is security auditing across smart contracts (Solidity/EVM, CosmWasm, Solana, ink!/Substrate, Soroban), consensus protocols, virtual machines, cryptographic primitives, ZK circuits, and cross-chain bridges, delivered in Foundation, Seed, and Signature tiers using a blinded multi-researcher process. Audits are complemented by operational security reviews, continuous audit/PR review subscriptions, a vCISO service, penetration testing, operational security training, security and economic advisory, and technical due diligence for VCs.
The business is anchored by a distributed pool of 50+ vetted senior security researchers with advanced degrees in cryptography, economics, and computer science, organized around Oak's proprietary TRACE threat modelling methodology that covers Protocols, Systems, and Organisations layers. Oak is bootstrapped without venture capital, sells through a consultative enterprise model with custom quote-based pricing, and monetizes thought leadership through the State of Web3 Security research report (produced with rekt.news), the TRACE framework (open-sourced under CC BY 4.0), and a free Op-Sec Academy. The company is expanding into AI tooling, with the Pre-Audit Agent and AI Threat Modeller (AiTM) in private beta as of 2025, alongside a rebrand of Solidified as a standalone brand for ongoing Web3 cybersecurity services.
Oak Security firmographics
Firmographics- Name
- Oak Security
- Legal name
- Oak Security GmbH
- Website
- https://oaksecurity.io
- Company type
- Private
- Founded year
- 2017
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- Oak Security is a Munich-based, bootstrapped Web3 security firm founded in 2017 that audits smart contracts, protocols, and bridges across EVM, Cosmos, Solana, and Polkadot ecosystems, serving crypto protocols and foundations with audits, operational security, vCISO, and advisory services.
- Ownership category
- akta.pro rank
Oak Security industry classification
Industry- Product category
- Web3 Security Auditing and Advisory
- NAICS
- Investigation and Security Services (5616)
- SIC
- Services-Engineering, Accounting, Research, Management (8700)
- akta.pro primary industry
- Smart Contract Security Tooling (static/dynamic analysis, formal verification) (FSAPABAI)
- akta.pro secondary industries
- On-Chain Monitoring, Threat Detection & Incident Response (FSAPAJAB), Bug Bounty, Vulnerability Disclosure & Security Services (FSAPAJAL), Insider Threat Program Design & Risk Assessments (BPAKADAM)
Keywords
Where Oak Security is headquartered
LocationHeadquarters
- HQ city
- Munich
- HQ country
- Germany
- HQ region
- Europe
Offices1 record
Markets served
Oak Security business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Operations, Marketing or Sales, Others
Revenue model
- Security Audits: Foundation, Seed, and Signature audits of smart contracts, consensus algorithms, virtual machines, and bridges. This is the core revenue driver. Conducted with a blinded multi-researcher process for thorough coverage.
- Operational Security Review: Review of multisig design, key management, deployment, governance, and incident response. Addresses the gaps traditional audits leave behind including CI/CD security and cloud posture.
- Continuous Audit / PR Reviews: Ongoing pull-request reviews with guaranteed turnaround time, plus priority scheduling for full audits. Keeps threat models current between major audit cycles.
- vCISO Service: On-demand security leadership for protocols. The vCISO owns the threat model and serves as the person founders and teams consult before architecture decisions or when security issues arise.
- Penetration Testing: Web3-native pentests of wallets, browser extensions, web interfaces, and backends that hold keys. Real testing approach rather than checklist-based.
- Operational Security Training: Security training for technical and non-technical team members, built around attacks actually targeting Web3 teams. Delivered remotely or on-site.
- Security & Economic Advisory: Design reviews of white papers and architectures, plus economic modelling to harden protocol economics and incentive mechanisms.
- Technical Due Diligence: Viability, technical maturity, code quality, and IP risk assessments for VCs and foundations evaluating teams and protocols.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Other | Multi-year contract | Security Audit tiers (Foundation, Seed, Signature) |
| Other | Multi-year contract | Enterprise professional services (vCISO, Training, Advisory) |
Go-to-market motion1 record
Distribution channels1 record
Marketing channels8 records
Oak Security product offering
Product offeringCore offering
Oak Security is a security partner for Web3 protocols, with Security Audits as the core offering. It conducts Foundation, Seed, and Signature tier audits of smart contracts, consensus algorithms, virtual machines, and bridges across EVM (Solidity), Solana, Cosmos (CosmWasm), Polkadot/Substrate (ink!), Stellar (Soroban), Rust, and ZK circuits using a blinded multi-researcher process. Beyond audits, it sells Operational Security Reviews, Continuous Audits, vCISO Service, Penetration Testing, Operational Security Training, Security & Economic Advisory, and Technical Due Diligence, anchored by the proprietary TRACE threat modelling methodology and supported by AI tools (Pre-Audit Agent, AiTM) and research (State of Web3 Security report, OpSec Academy).
Product overview
Oak Security operates as a security partner for Web3 protocols, offering a platform-plus-services model. The core offering is Security Audits (Foundation, Seed, Signature tiers) covering smart contracts and blockchain code across EVM, Cosmos, Solana, Polkadot, and other protocols. This is complemented by operational security services including Operational Security Reviews, Continuous Audits, vCISO Services, Penetration Testing, Operational Security Training, and Technical Due Diligence. The platform layer includes the Pre-Audit Agent (AI-powered repository analysis in private beta), AI Threat Modeller/AiTM (AI-assisted threat modelling in private beta), Op-Sec Academy (free educational resource with 18 guides and an AI OpSec Agent), Web3 Security Dashboard (interactive research visualization), and the TRACE Framework (proprietary threat modelling methodology published under CC BY 4.0). The portfolio is anchored by the State of Web3 Security research report analyzing industry-wide audit findings and exploit incidents.
Differentiator
Problem solved
Functional benefit
Products and services
- Security Audits Foundation, Seed, and Signature tier smart contract and blockchain security audits covering EVM (Solidity), Solana, Cosmos (CosmWasm), Polkadot/Substrate (ink!), Stellar (Soroban), consensus protocols, virtual machines, cryptographic primitives, ZK circuits, and cross-chain bridges. Audits are conducted with a blinded review process in which auditors work independently and simultaneously for redundancy. Designed for DeFi protocols, L1/L2 chains, bridges, and dApp teams.
- Operational Security Review Structured multi-expert audit of a Web3 team's operational practices covering key management, access controls, multisig design, CI/CD pipelines, cloud security posture, and incident response. Deliverable is a prioritized finding report with concrete remediation steps and a re-check upon completion. For Web3 teams, foundations, and protocols whose primary risk sits in operations rather than code.
- Continuous Audit Ongoing security assessment providing pull-request reviews with guaranteed turnaround times and priority scheduling for full audits when needed. Keeps threat models current between periodic formal audits. Subscription-style engagement suited to actively shipping Web3 protocols.
- vCISO Service On-demand virtual Chief Information Security Officer service providing an experienced security leader who owns the client's threat model and serves as the strategic security advisor for architecture decisions and incident response. Subscription-style recurring engagement.
- Penetration Testing Web3-native penetration testing covering wallets, browser extensions, web interfaces, and backends that hold keys. Uses real-world attack simulation rather than checklist-based testing. For Web3 protocols and teams needing offensive security validation of front-ends and key-handling infrastructure.
- Operational Security Training Security training for technical and non-technical team members covering threat modelling, hardware wallet onboarding, multisig operations, and social-engineering defense. Delivered remotely or on-site as interactive workshops.
- Security & Economic Advisory Design reviews of white papers and architectures, plus economic modeling to harden protocol token economies and incentive mechanisms against manipulation and attack. For protocol design teams and foundations.
- Technical Due Diligence Comprehensive assessment of protocol viability, technical maturity, code quality, and IP risk. The same review VCs and foundations request when evaluating teams and protocols for investment.
- Pre-Audit Agent AI-powered tool that analyzes GitHub repositories to generate an audit-readiness score (0-100), identify risk hotspots (oracle, upgrade path, access), assess complexity, and recommend the appropriate Oak Security audit package. Currently in private beta. Integrates with GitHub and uses the firm's accumulated audit heuristics.
- AI Threat Modeller (AiTM) Desktop application for AI-assisted threat modelling built on the TRACE framework. Runs the full TRACE workflow (Actors, Roles, Assets, Critical Invariants, Edges) on user-provided specs and code, supporting OpenAI and Anthropic AI models. Currently in private beta for macOS, Windows, and Linux.
- Op-Sec Academy Free, open library of 18+ operational security guides covering device hardening, wallets, keys, infrastructure, authentication, incident response, communications, and physical security. Includes AI-powered OpSec Agent that answers operational security questions and falls back to the SEAL framework.
- Web3 Security Dashboard Interactive dashboard presenting aggregate audit findings and exploit incident data from the State of Web3 Security report. Covers 23,818 published audit findings from 22 firms and 218 documented exploit incidents worth US$7.76 billion in losses (2022-Q1 2026), updated quarterly.
- TRACE Framework Oak Security's proprietary threat modelling methodology for teams without a clean security perimeter. Comprises five model objects (Threat actors, Roles, Assets, Critical invariants, Edges) applied across three layers (Protocols, Systems, Organisations). Published openly under CC BY 4.0 license and used as the structural backbone for every Oak engagement.
Quantifiable outcome
- 600+ engagements completed since 2017 with 9+/10 average client rating
- +2 more outcomes
Companies that use Oak Security
Customer profileNamed customers11 records
Segments4 records
Ideal customer profiles3 records
Oak Security technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration3 records
AI capability8 records
Feature6 records
Oak Security partnerships and signals
Strategic signalPartnerships
Two partnerships are on record, tiered core.
- Security Alliance (SEAL)coreOak Security is an accredited assessment firm for the Security Alliance (SEAL) operational security certification program. They assess protocols against the SEAL framework and when passed, SEAL issues a verifiable on-chain attestation through the Ethereum Attestation Service. The certification covers operational security areas including Multisig Ops, Treasury Ops, Incident Response, DevOps & Infrastructure, DNS & Registrar, and Identity & Accounts.
- rekt.newscoreData partnership for the State of Web3 Security report. rekt.news provides incident data and leaderboard information for the research report and interactive dashboard. The collaboration analyzed four years of data: 23,818 published audit findings from 22 firms and 218 documented exploit incidents worth US$7.76 billion in losses.
Scale indicators6 records
Recent moves6 records
Expansion highlights6 records
Oak Security competitors and assessment
Company assessmentDirect peers
- Trail of Bits: Trail of Bits is a leading Web3 and software security firm offering smart contract audits, formal verification, and cryptographic reviews. It is a direct peer — same service categories (smart contract audits, security reviews), overlapping target customers (protocols, foundations), and comparable enterprise positioning.
- ChainSecurity: ChainSecurity is a blockchain security firm focused on smart contract audits and formal verification, with strong roots in the Ethereum research community. It is a direct peer in Web3 security audits and formal verification, serving similar DeFi and protocol customers.
- MixBytes: MixBytes is a blockchain security and development firm providing smart contract audits across EVM, Solana, Cosmos, Polkadot, and Substrate. It is a direct peer with overlapping protocol coverage (especially Cosmos/CosmWasm) and comparable services spanning audits, consulting, and protocol development.
- Certora: Certora provides formal verification tooling and security audits for smart contracts, including a commercial prover product. It is a direct peer in the Web3 security audit market with overlapping emphasis on rigorous (formal) verification methodologies and similar enterprise protocol customers.
- OpenZeppelin: OpenZeppelin provides smart contract security audits alongside its widely-used developer libraries and Defender platform. It is a direct peer in Web3 security audits serving the same protocol developer customer base, with comparable enterprise reputation and a similarly broad protocol coverage.
- Zellic: Zellic is a Web3 security firm specializing in smart contract audits, protocol security reviews, and applied cryptography research. It is a direct peer with a comparable premium positioning, PhD-heavy researcher roster, and focus on multi-chain audits (EVM, Solana, Move, Cairo).
- Spearbit: Spearbit operates a curated collective of senior security researchers for smart contract audits and Web3 security reviews. It is a direct peer competing for the same top-tier audit talent pool and same protocol customers, with a distributed-researcher model analogous to Oak's 50+ senior researcher pool.
Broad incumbents
- CertiK: CertiK is a large-scale Web3 security firm offering smart contract audits, formal verification, and on-chain monitoring (Skynet). It is a broad incumbent in the same security market but with a more productized, scale-driven model and broader service portfolio than Oak's specialist positioning.
- Quantstamp: Quantstamp is an established Web3 security firm offering smart contract audits and security tooling across multiple chains. It is a broad incumbent competing for the same protocol audit engagements, with a longer operating history and broader geographic footprint but a less specialized methodology positioning than Oak.
Emerging players
- Cantina: Cantina is a Web3 security platform that runs audit competitions and connects protocols to vetted researchers. It is an emerging player competing for some of the same audit-engagement demand, with a platform model that overlaps with how Oak structures its distributed researcher pool.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks6 records
Key highlights7 records
Customer concentration
Oak Security social profiles
Digital presenceOak Security compliance and trust
Trust signalCompliance1 record
Oak Security financial estimates
Financial estimateRevenue estimate
Valuation estimate
Oak Security leadership team
Management profileNumber of profiles
Profiles15 records
Oak Security funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Oak Security M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Oak Security
What does Oak Security do?
Oak Security is a security partner for Web3 protocols, with Security Audits as the core offering. It conducts Foundation, Seed, and Signature tier audits of smart contracts, consensus algorithms, virtual machines, and bridges across EVM (Solidity), Solana, Cosmos (CosmWasm), Polkadot/Substrate (ink!), Stellar (Soroban), Rust, and ZK circuits using a blinded multi-researcher process. Beyond audits, it sells Operational Security Reviews, Continuous Audits, vCISO Service, Penetration Testing, Operational Security Training, Security & Economic Advisory, and Technical Due Diligence, anchored by the proprietary TRACE threat modelling methodology and supported by AI tools (Pre-Audit Agent, AiTM) and research (State of Web3 Security report, OpSec Academy).
Is Oak Security a public or private company?
Oak Security is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was Oak Security founded?
Oak Security was founded in 2017. It employs 11 to 50 people.
Where is Oak Security based?
Oak Security is headquartered in Munich, Germany, in the Europe region.
How does Oak Security make money?
Eight revenue lines are on record. Security Audits are the primary driver. The others are operational Security Review, continuous Audit / PR Reviews, vCISO Service, penetration Testing, operational Security Training, security & Economic Advisory and technical Due Diligence.
Who are Oak Security's main competitors?
Direct peers on record are Trail of Bits, ChainSecurity, MixBytes, Certora, OpenZeppelin, Zellic and Spearbit. Broad incumbents are CertiK and Quantstamp. Cantina is listed as an emerging player.
Does Oak Security have an API?
No public API is recorded for Oak Security.
What industry is Oak Security in?
Oak Security's product category is Web3 Security Auditing and Advisory. Its primary akta.pro industry code is FSAPABAI, Smart Contract Security Tooling (static/dynamic analysis, formal verification), with a secondary code of FSAPAJAB, On-Chain Monitoring, Threat Detection & Incident Response. Its NAICS code is 5616 and its SIC code is 8700.