Cantina
Cantina is an AI-native security platform that combines machine intelligence with a network of 9,000+ vetted security researchers to deliver code audits, bug bounties, competitions, and managed detection and response for Web3 and Web2 clients.
- Company typePrivate
- Founded-
- HeadquartersMiami, United States
- Headcount51–100
- GTM typeB2B
- OfferingSoftware
What Cantina does
Cantina is an AI-native security platform that combines machine intelligence with a curated network of human security researchers to deliver code audits, bug bounty programs, security competitions, and managed detection and response services. The company is operated by Spearbit Labs, Inc., a Delaware corporation headquartered in Miami, and was founded in 2023. Its core products include Cantina Code (a collaboration and review platform for researchers and clients), the AI Code Analyzer and Apex AI security engineer (which identify exploitable vulnerabilities and provide fix-ready guidance), Clarion (an agentic Security Operations Control Center), and Web3SOC (a continuous monitoring service for blockchain protocols). The platform is powered by the Spearbit network of 9,020+ tiered researchers and has secured $100B+ in total value locked across 200+ client projects.
The company operates a two-sided marketplace business model: protocols and enterprises pay for audits, bug bounties, competitions, and managed services, while researchers earn payouts through a tiered Fellowship Program (Apprentice, Resident, Fellow). Revenue streams include professional services (audits, competitions, managed detection and response), transaction fees on bug bounty payouts, and a referral program paying 5% of Net Revenue (capped at $50K per individual). Pricing is quote-based and not publicly disclosed. Customer segments span DeFi protocols, L1/L2 chains, DEXes, CEXes and wallets, NFT projects, RWA and tokenized assets, GameFi, financial institutions, and AI agents. Named enterprise clients include Coinbase, Uniswap, Aave, EigenLayer, Polygon, Optimism, MakerDAO, OpenSea, zkSync, SAP, and the Ethereum Foundation. The platform holds SOC 2 Type 2 compliance and processes payments in USDC on Ethereum.
Cantina firmographics
Firmographics- Name
- Cantina
- Legal name
- Spearbit Labs Inc.
- Website
- https://cantina.xyz
- Company type
- Private
- Operating status
- Operating
- Headcount range
- 51–100 employees
- Short description
- Cantina is an AI-native security platform that combines machine intelligence with a network of 9,000+ vetted security researchers to deliver code audits, bug bounties, competitions, and managed detection and response for Web3 and Web2 clients.
- Ownership category
- akta.pro rank
Cantina industry classification
Industry- Product category
- Cybersecurity Services
- NAICS
- Security Systems Services (except Locksmiths) (561621), Other Computer Related Services (541519)
- SIC
- Services-Computer Integrated Systems Design (7373)
- akta.pro primary industry
- Bug Bounty, Vulnerability Disclosure & Security Services (FSAPAJAL)
- akta.pro secondary industries
- Security Analytics & Detection Engineering (HDADAGAE), Vulnerability Assessment & Scanning (HDADAHAA)
Keywords
Where Cantina is headquartered
LocationHeadquarters
- HQ city
- Miami
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
Cantina business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Operations, Marketing or Sales, Infrastructure
Revenue model
- Security Audits / Reviews: Cantina facilitates security reviews and audits performed by security researchers for clients. Fees are charged based on the scope and type of engagement (smart contract audits, web2 security audits, advanced security assessments).
- Bug Bounty Programs: Managed bug bounty programs where organizations host bounties on Cantina's platform. Cantina earns a portion of the engagement as a platform/service fee (Net Revenue = gross amount less payouts to researchers, third-party fees, taxes, refunds).
- Security Competitions: Security competitions where multiple researchers compete to find vulnerabilities. Organizations pay for the competition engagement.
- Managed Detection & Response: Managed security operations services including Clarion (Security Operations Control Center) and Web3SOC services.
- Referral Fees: Cantina pays 5% of Net Revenue to individuals who refer clients for non-bug bounty engagements (competitions, audits) or the first valid bug bounty finding.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Usage-based | Pay-as-you-go | Bug Bounty Programs - payout-based model |
| One time/ perpetual license | Multi-year contract | Security Competitions - engagement-based pricing |
| Subscription | Annual | Managed Detection & Response / Security Audits - quote-based |
| Transaction based/ take rate | Pay-as-you-go | Referral Program compensation |
Go-to-market motion3 records
Distribution channels5 records
Marketing channels9 records
Cantina product offering
Product offeringCore offering
Cantina operates an AI-native security platform that connects organizations with a network of 9,000+ vetted security researchers to deliver smart contract audits, bug bounty programs, security competitions, Web2 audits, and managed detection and response. Its proprietary tooling, including the Apex AI Code Analyzer and Clarion agentic SOC, combines machine intelligence with elite human expertise to identify and remediate exploitable vulnerabilities across Web3 and Web2 systems.
Product overview
Cantina is an AI-native security platform combining machine intelligence with elite human expertise for Web3 and Web2 code audits, bug bounties, competitions, and incident response. The platform operates as a unified system with multiple integrated products: AI Code Analyzer (Apex) and Cantina Code serve as core products for code review; Clarion provides an agentic Security Operations Control Center; Smart Contract Audits, Bug Bounty Programs, and Security Competitions are the primary service offerings; Managed Detection & Response and Web3SOC address ongoing monitoring needs; Spearbit Services offer elite hand-picked researcher reviews; and the Fellowship Program and Referral Program provide researcher development and client acquisition pathways. Cantina Code includes AI-powered Cantina Assistant, reputation scoring, findings dashboards, and communication features (pings, comments, notifications).
Differentiator
Problem solved
Functional benefit
Brands
- Cantina Code: Code review platform designed for efficient security review experience, featuring findings dashboard, reputation scoring, and collaboration tools
- Clarion
- Apex
- Web3SOC
Products and services
- AI Code Analyzer (Apex) Leading AI code security tool that identifies exploitable vulnerabilities in code and ranks findings by impact. The Apex AI security engineer finds real vulnerabilities in mission-critical code and provides fix-ready guidance for engineering teams.
- Cantina Code Dedicated code review platform for conducting security reviews efficiently, with real-time findings dashboard, reputation-based researcher scoring, researcher-to-client communication through comments and pings, structured findings submission, and AI-powered triage assistance.
- Clarion Security Operations Control Center that deploys intelligent security agents, connects tools, and begins monitoring environments in minutes. Provides an agentic SOC that identifies vulnerabilities, neutralizes threats, detects infrastructure threats, secures supply chains, and automates response and remediation.
- Smart Contract Audits World-class smart contract security reviews performed by Cantina's assembled team of top security researchers, including Cantina reports (hand-picked team reviews), Competition reports (open code reviews), and Spearbit reports (elite reviews).
- Bug Bounty Programs Top security researchers find critical bugs through a managed bug bounty platform where researchers submit findings, communicate with clients via pings and comments, and receive payouts based on severity, with triaging by deeply knowledgeable smart contract developers.
- Security Competitions Open code review competitions where security researchers compete to find vulnerabilities across multiple technologies including smart contracts, Cosmos, Geth, and precompiles, featuring competition leaderboards and tiered payouts based on placement and severity.
- Managed Detection & Response Detection, response, and resolution of security incidents at speed through continuous security monitoring and AI-powered threat detection across customer environments.
- Web2 Security Audits Application, API, and penetration testing security reviews for Web2 infrastructure, covering cloud systems, applications, and identities.
- Web3SOC Specialized Security Operations Center for Web3 protocols providing continuous monitoring and incident response for blockchain-based systems.
- Spearbit Services Elite, high-touch security audits by a curated network of top security researchers, including smart contract security reviews, Web2 security reviews, penetration testing, advanced security assessments, and advisory services.
Quantifiable outcome
- $100B+ in TVL secured across the platform
- +4 more outcomes
Companies that use Cantina
Customer profileNamed customers25 records
Segments9 records
Ideal customer profiles4 records
Cantina technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration8 records
AI capability8 records
Feature12 records
Cantina partnerships and signals
Strategic signalPartnerships
Two partnerships are on record, tiered core.
- SpearbitcoreCantina is operated by Spearbit Labs, Inc. Spearbit provides the curated network of elite security researchers (SR, ASR, LSR tiers) that power Cantina's platform. Cantina Code was built integrating Spearbit's methodologies and expertise from the Spearbit network.
- Ethereum FoundationcoreEthereum Foundation partnered with Cantina for the Pectra Competition (Spectra), a major security competition to audit Ethereum's Pectra upgrade (8 EIPs). Cantina provides the platform and coordinates researcher participation for Ethereum's security.
Scale indicators8 records
Recent moves6 records
Expansion highlights6 records
Cantina competitors and assessment
Company assessmentDirect peers
- Hacken: Blockchain security auditor offering smart contract audits, bug bounties, and penetration testing for crypto protocols; competes with Cantina across audit and bounty services.
- Cyfrin: Smart contract auditing firm and security education platform serving DeFi protocols with audit and code-review services; competes directly with Cantina for mid-market and emerging protocol engagements.
- ConsenSys Diligence: Smart contract audit arm of ConsenSys serving Ethereum-aligned protocols; competes directly with Cantina for institutional Ethereum audits, including L1/L2 chain security reviews.
- Trail of Bits: Established security firm providing smart contract audits, penetration testing, and security assessments across Web3 and Web2; a direct competitor for Cantina's audit and advanced security assessment offerings.
- Immunefi: Largest bug bounty platform dedicated to Web3, directly overlapping with Cantina's bug bounty programs and competing for DeFi/DEX client engagements.
- Code4rena: Web3 audit competition platform hosting code contests where security researchers compete to find vulnerabilities; the closest direct analog to Cantina's competition model serving DeFi protocols and L1/L2 chains.
- OpenZeppelin: Tier-one smart contract auditor and security tooling provider serving DeFi protocols and L1/L2 chains, competing with Cantina on audit services and security frameworks across the same Web3 customer base.
- Sherlock: Smart contract audit contests and managed bug bounty program for Web3 protocols, directly competing with Cantina on competition-based code reviews and payout-based researcher engagement.
- Certik: Web3 security firm offering smart contract audits, formal verification, and bug bounty services; significant market share overlap with Cantina across DeFi protocols and L1/L2 chains.
Broad incumbents
- HackerOne: General-purpose bug bounty and vulnerability disclosure platform with broad enterprise customer base; provides the incumbent alternative to Cantina's bug bounty programs as Cantina expands into Web2.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks6 records
Key highlights7 records
Customer concentration
Cantina social profiles
Digital presenceCantina compliance and trust
Trust signalCompliance1 record
Cantina financial estimates
Financial estimateRevenue estimate
Valuation estimate
Cantina leadership team
Management profileNumber of profiles
Cantina funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Cantina M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Cantina
What does Cantina do?
Cantina operates an AI-native security platform that connects organizations with a network of 9,000+ vetted security researchers to deliver smart contract audits, bug bounty programs, security competitions, Web2 audits, and managed detection and response. Its proprietary tooling, including the Apex AI Code Analyzer and Clarion agentic SOC, combines machine intelligence with elite human expertise to identify and remediate exploitable vulnerabilities across Web3 and Web2 systems.
Is Cantina a public or private company?
Cantina is a private company. It is classified as unknown and is currently operating.
When was Cantina founded?
Cantina was founded in -1. It employs 51 to 100 people.
Where is Cantina based?
Cantina is headquartered in Miami, United States, in the North America region.
How does Cantina make money?
Five revenue lines are on record. Security Audits / Reviews are the primary driver. The others are bug Bounty Programs, security Competitions, managed Detection & Response and referral Fees.
Who are Cantina's main competitors?
Direct peers on record are Hacken, Cyfrin, ConsenSys Diligence, Trail of Bits, Immunefi, Code4rena, OpenZeppelin, Sherlock and Certik. HackerOne is listed as a broad incumbent.
Does Cantina have an API?
No public API is recorded for Cantina.
What industry is Cantina in?
Cantina's product category is Cybersecurity Services. Its primary akta.pro industry code is FSAPAJAL, Bug Bounty, Vulnerability Disclosure & Security Services, with a secondary code of HDADAGAE, Security Analytics & Detection Engineering. Its NAICS code is 561621 and its SIC code is 7373.