Q2 2026 Security & Compliance Report67 incidents, $764M in losses, 88% from operational failures.
Get the report →

Enterprise Assurance Programme

Your security and compliance, on retainer

A single annual programme covering security and compliance across your current products, entities, and future launches.

Enterprise Assurance Programme
2,161
Security assessments delivered
$182B+
Market capitalisation secured
16,659
Vulnerabilities identified
1,600+
Clients since 2017

Outsource the security and compliance function and get:

All Hacken service lines and platforms

Access security audits, testing, monitoring, compliance and assurance services under one programme.

A dedicated senior team

A dedicated team works with you across engagements, with defined capacity and ~24h priority scheduling.

One agreement, one fixed annual fee

All current and upcoming service lines are covered under one master agreement and annual fee.

Your organisation can grow within the programme

Bring future products, and subsidiaries into scope without a new commercial agreement or additional fees.

12-month minimum term

Get continuous coverage and pre-approved capacity, with a minimum commitment of 12 months.

Designed for organisations like yours

Four shapes of organisation where a single fixed-scope engagement never matches what is actually being operated.

  • Banks and financial institutions

    Multi-entity tokenised products, custody or stablecoin infrastructure under regulatory supervision

  • Exchanges, custodians, and CASPs

    Recurring proof of reserves, continuous monitoring and licence-grade pentesting

  • RWA issuers and tokenisation platforms

    Contracts, vaults, oracles and off-chain systems

  • Multi-entity digital asset groups

    Subsidiaries and a roadmap of new entities, with no appetite for a procurement cycle per entity.

Why retain?

38 days → 1 day before the assessment can start

Project-based engagement:

Intros · Scoping · Procurement · Backlog queue
Day 38
Assessment starts
In latest engagement with a global bank, the first audit took 38 days from code being ready to kickoff.

Retainer:

Request day
Day 0
Preliminary report delivered
✓ Another client received a preliminary audit report in 1 day under an Enterprise Assurance at no additional cost.

Intros, scoping, procurement and onboarding happen once, at the start of the term, and there is no backlog queue because capacity is pre-approved and scheduling is prioritised. The assessment itself is identical work on either row — it simply starts thirty-seven days earlier.

How your operations work under the retainer model

Hacken assurance cubes

One negotiation, one legal review, one set of terms. Every service line below is already inside it.

Not just every entity — every cybersecurity and compliance need of every entity. Entities that do not exist yet come online under the same agreement, no new contract, no new fee.

A request enters the standing queue rather than a procurement cycle.

A dedicated account director, a delivery manager and lead auditors per discipline, who stay on your programme for the life of the retainer. Your architecture is learned once and the knowledge compounds.

Because the same team audits every asset you own — contracts, protocol, off-chain systems, cloud, the AI stack — what they know about your architecture compounds across the term. By the second year they are reviewing changes against a model of your systems, not building one from scratch. That is the part a procurement cycle can never buy.

Reports, attestations and remediation history build into a file a supervisor or certification body can be shown.

Work inside the agreement raises no invoice. Assessment work draws on agreed capacity; the always-on services do not.

Services in scope

Smart contract audit

Manual line-by-line review by senior auditors, plus fuzzing and invariant testing. Re-audits of code already reviewed included.

Blockchain and protocol audit

L1 and L2 architecture: consensus assumptions, cryptographic implementations, node behaviour under adversarial conditions.

AI system security audit

White-box review of AI and agentic systems: prompt injection, inter-agent isolation, RBAC, data segregation, API surface.

Off-chain application code review

Front-end and back-end source — the systems around the contracts, attacked just as often.

Penetration testing and red teaming

Web, mobile, API, cloud and CI/CD. Controlled exploitation and lateral-movement assessment.

Cryptography audit

ZK, PQC, ECC, FHE, key management and protocol-level assumptions.

Deployment audit

Ensure deployed code behaves as intended in production systems.

Tokenomics and yield audit

Economic-model review and independent yield-risk assessment.

Compliance and regulatory advisory

Advisory across the frameworks and mandates that apply to you, and the licensing work around them

MiCA · DORA · ISO 27001 · SOC 2 · SEAL · CCSS · Licensing advisory · vCISO
No impact on capacityBug bounty and DualDefenseProof of Reserves VerificationExtractor 24/7 monitoringRisk intelligenceEmergency RoomAI Auditor and consultancy

How capacity works

Capacity is agreed once, in auditor-weeks, and drawn against for the whole term.

Pre-approved capacity

Capacity is sized against your roadmap. You draw against it with no re-negotiation per engagement.

A ramp-up buffer

Onboarding and integration happen before the paid term begins, which includes scoping and setup.

Group-wide by default

Parent/Affiliates covered by Hacken assurance. New subsidiaries are also served under the same agreement.

Fungible across services

A quarter of three contract audits and no pentesting costs exactly the same as the reverse.

Four steps

1

Scope

One call to define your operations, entities in scope and roadmap for the term.

2

Proposal

Offering for service lines, capacity, team and scope documented before signing.

3

Ramp up

Onboarding, access and context building completed before the paid term begins.

4

First workstreams

Assessments and assurance activities scheduled according to your roadmap.

Request a scoping call

One call to size it: what you operate, which entities are in scope, and what your roadmap needs over the term.

FAQ — What you should know before?

Yes. The value comes from continuity and pre-approved capacity, and neither is available with a shorter commitment. If you need a single assessment, we will point you to a standard engagement.
The ramp-up buffer sits before the paid period, terms can extend to absorb delays, and monthly utilisation reporting makes drift visible months before renewal. Capacity you have not used does not die with the term either. Any remaining balance carries over as a courtesy — three months past a 12-month term, six months past 24 months, nine months past 36 — so a slipped roadmap does not cost you the capacity you paid for.
Yes, and they are in writing before you sign. Assessment work draws on agreed capacity; monitoring, PoR, bounty hosting, incident standby and consultancy do not. Third-party licences and bespoke R&D are quoted separately.
Yes, including entities that do not exist yet — no new contract, no additional fee.
Yes, and partners frequently ask us to. It is one of the highest-yield uses of the programme before a launch or a licence application.
Within days rather than after a procurement cycle. With a global bank, a first audit took 38 days from code-ready to kickoff; under a continuous agreement the follow-up produced a preliminary report in a day.
Yes. A dedicated account director, a delivery manager and lead auditors per discipline, with at least two senior auditors on every assessment. The same people stay with your programme for its whole term, so the knowledge base of your systems builds rather than resets.
Only with your written approval, and we ask the same. Where you want visibility: joint case studies, security badges, portfolio publication and amplification.