agentsastLast reviewed 2026-09-13

Firms that run AI-assisted audits

Direct answerA reviewed list of security firms whose audits combine AI tooling with named human validation, with what each firm's AI offering is, whether it targets cryptography and ZK, and public evidence of results. zkSecurity, Trail of Bits, Zellic, Nethermind Security, Sherlock, Cantina, Consensys Diligence and others.

Listing criteria: a public AI tool or documented AI-assisted methodology, named human validation of every reported finding, and public evidence of results on real code. Order reflects the editors' assessment; see methodology.

#2Trail of Bits

New York, United States · AI-native security practice: Buttercup, 201 open-source skills, about 20 percent of reported bugs first surfaced by AI, all human-validated

Trail of Bits built Buttercup, the AIxCC runner-up, and has reorganised its audit practice around AI: it reports 15 to 200 AI-surfaced candidate bugs per week on suitable engagements, about 20 percent of reported findings first surfaced by AI, every one validated by an auditor, and publishes 201 skills and 94 plugins as open source. It has a cryptography and ZK practice.

Profile · Website

#3Zellic

San Francisco, United States · V12 autonomous Solidity auditor alongside human audits; ZK and Rust work

Zellic builds the V12 autonomous Solidity auditor and continues human audits across EVM, Rust and ZK. It owns Code4rena, which announced it is closing.

Profile · Website

#4Nethermind Security

London, United Kingdom · AuditAgent as a second layer after manual audits; published recall data

Nethermind Security runs AuditAgent after every manual audit as a second layer and publishes its recall against its own human findings (30 percent average, 42 percent of criticals). It also has a formal verification team working in Lean and EasyCrypt.

Profile · Website

#5Sherlock

Distributed · Sherlock AI plus audit contests and private audits

Sherlock combines its Sherlock AI product with contest-based and private human audits, and has published a controlled precision study of the AI.

Profile · Website

#6Cantina (Spearbit)

Distributed · AI-native AppSec platform with an enterprise AI code analyzer and a 9,000-researcher network

Cantina, from Spearbit, markets an AI-native application security platform with an enterprise AI code analyzer, combined with human expert review from a network of more than nine thousand researchers. It is unrelated to the agentic SecOps startup of the same name launched in July 2026.

Profile · Website

#7Consensys Diligence

Distributed · Agentic vulnerability mining as a co-audit workflow guided by veteran auditors

Consensys Diligence describes an agentic vulnerability-mining workflow in which swarms of parallel agents act as lead generators and a confirmation layer, guided by veteran auditors, alongside its symbolic-execution tooling.

Profile · Website

#8Cyfrin

Distributed · Aderyn static analyzer, Solodit API for AI agents, CodeHawks contests; an AI formal verification engagement for Lido

Cyfrin maintains the Aderyn static analyzer (not AI), opened its Solodit database of more than fifty thousand audit findings to AI agents via an API, runs CodeHawks contests, and lists an AI formal verification engagement for Lido's Circuit Breaker (April 2026) in its public reports.

Profile · Website

#9OpenZeppelin

Distributed · AI Auditor within Program Security; audited EVMbench

OpenZeppelin markets an AI Auditor within its Program Security offering and published the March 2026 audit of EVMbench that identified invalid high-severity items and contamination risk. Product details are not public.

Profile · Website

#10QuillAudits

India · QuillShield AI plus human audits across 1,400 projects

QuillAudits pairs its QuillShield AI auditor and open-source Claude skills with human audits, reporting more than 1,400 projects audited.

Profile · Website

#11Certora

Tel Aviv, Israel and United States · Formal verification core; AI Composer for prover-checked code generation

Certora's core is the open-sourced Certora Prover; its AI work (AI Composer, Concordance) uses the prover to check model output rather than to scan code. Human audits continue.

Profile · Website

#12Veridise

Austin, Texas, United States · Formal methods and static analysis for ZK (Picus, ZK Vanguard, LLZK); no public LLM tooling

Veridise is a strong ZK audit firm (RISC Zero, Linea, Succinct, Semaphore) whose tooling is formal and static (Picus, Vanguard, ZK Vanguard, OrCa, LLZK) rather than LLM-based. It is listed for teams weighing AI scanners against solver-based alternatives for circuits.

Profile · Website

How to choose