# QuillAudits > Security audits for serious Web3 teams QuillAudits is a blockchain security company. It provides smart contract audits, penetration testing, and continuous monitoring to help Web3 projects find and fix vulnerabilities before and after launch. QuillAudits is a blockchain security company that helps Web3 projects identify and remediate vulnerabilities across the protocol lifecycle. Its core offering is smart contract auditing, in which a team of researchers reviews code for logic errors, access control flaws, and other exploitable issues before a project goes live. The company works with projects across multiple blockchains and covers a range of protocol architectures. Beyond code review, QuillAudits addresses operational security, since compromised signers, weak multisig configurations, and phished private keys have caused losses in decentralized finance independent of code quality. Its operational security review examines signer setups and supporting infrastructure for weaknesses. The company also offers architecture and threat-modeling advisory before development begins, positioning security review as a continuous process rather than a single event. QuillAudits' broader toolset includes automated vulnerability scanning, penetration testing for decentralized applications, and monitoring that flags unusual onchain activity after deployment. It also maintains a public database of past blockchain exploits and publishes research on topics such as tokenization and decentralized exchange design. Clients span decentralized finance, real-world asset tokenization, gaming, and blockchain infrastructure projects seeking independent security review. - Type: Company - Sector: Security - Status: Active - Founded: 2018-01-01 - Profile: https://thegrid.id/profiles/quillaudits ## Products - [Multisig Inspector ](https://thegrid.id/profiles/quillaudits): Multisig Inspector is a free, read-only tool for reviewing Safe multisig wallets before a transaction is signed. It reads owner lists, signer thresholds, active modules, guards, and the fallback handler directly from the blockchain, and decodes pending transactions to recompute their transaction hash for comparison against a hardware wallet display. Protocol teams and security researchers use it to verify multisig configuration and transaction intent without connecting a wallet or exposing any keys. (Blockchain Development Security Tools, Live) - [Smart Contract Audits ](https://thegrid.id/profiles/quillaudits): Smart Contract Audits is a security auditing service that reviews blockchain codebases for vulnerabilities before and after deployment. Independent researchers perform manual and automated code review, examine attack surfaces such as access control, economic logic, and oracle integrations, and test proposed fixes in a simulated adversarial environment. The service is used by decentralized finance, real-world asset, cross-chain, and NFT projects that need a documented vulnerability report and remediation guidance ahead of launch. (Smart Contract Audits, Live, Main Product) - [RWA Security Score](https://thegrid.id/profiles/quillaudits): RWA Security Score is a self-assessment platform that rates the security posture of tokenized real-world asset protocols. Users answer structured questions across risk categories including smart contract security, oracle integrity, custody, and governance, and a weighted model calculates an overall score and letter grade. Submissions that are reviewed and approved can appear on a public leaderboard that benchmarks protocols against their peers. (Rating & Safety Scoring, Live) - [QuillGuard](https://thegrid.id/profiles/quillaudits): QuillGuard is a security layer for autonomous AI agents that detects vulnerabilities across known attack surfaces and applies behavioral guardrails. It wraps an agent's underlying model to screen incoming prompts for jailbreak attempts and to block outputs that violate defined policies, such as unauthorized financial actions. The guardrails are tailored to an agent's specific logic and update as new attack patterns are identified, and the product is used by developers building agents that execute on-chain actions. (Blockchain Development Security Tools, Live) - [Aegis](https://thegrid.id/profiles/quillaudits): Aegis is a self-assessment platform that helps blockchain project teams identify security gaps before undergoing a formal smart contract audit. It structures review into checkpoints spanning code-level security, access controls, and operational security practices such as team infrastructure and social engineering exposure. Teams use it to track their security posture over time and to identify gaps prior to engaging formal audit services. (Risk Assessment, Live) - [Web3 Hacks Database](https://thegrid.id/profiles/quillaudits): Web3 Hacks Database is a searchable database that catalogs historical cryptocurrency hacks and exploits, including funds lost, affected blockchain, and attack category. Users can filter incidents by blockchain, year, and attack type, and view aggregated statistics on losses across the industry. A companion alert channel notifies subscribers when new incidents are identified, along with details of affected contracts and mitigation notes. (Data Terminal, Live) - [QuillShield](https://thegrid.id/profiles/quillaudits): QuillShield is a scanning tool that detects vulnerabilities in smart contract code before a formal audit is performed. It analyzes contract logic for edge cases and known flaw patterns using automated, AI-assisted detection, and can be run continuously as code changes during development. Developers use it to identify issues early and to start the formal audit process from a cleaner code baseline. (Skills, Live) ## Links - [Main](https://quillaudits.com) - [Blog](https://www.quillaudits.com/blog) - [Privacy policy](https://www.quillaudits.com/privacy-policy) - [Media Kit/branding](https://www.quillaudits.com/brandkit) - [Documentation](https://www.quillaudits.com/leaderboard) - [LinkedIn](https://linkedin.com/company/QuillAudits) - [Telegram](https://t.me/QuillAudits) - [GitHub](https://github.com/Quillhash) - [Reddit](https://reddit.com/r/quillaudits) - [Discord](https://discord.com/invite/C6M2eQZagw) - [YouTube](https://www.youtube.com/channel/UC5Yt_8qEaAr-PiTMmGBuPCQ) - [Twitter / X](https://x.com/quillaudits_ai) - [Medium](https://quillaudits.medium.com) ## Legal This data is provided under two licensing models. Model 1 - open data. The open data core is licensed under the Open Database License (ODbL) — a copyleft/share-alike license allowing free use, modification, and sharing for any purpose. Attribution is required: include "Powered by The Grid" linking to https://thegrid.id wherever the data is used. Derivative databases must be shared under ODbL terms. Trademarks, logos, and brand names (marked "Special TPIP") are not covered by the ODbL. For ML/AI use: training datasets that substantially extract ODbL data are Derivative Databases and must be shared under ODbL if publicly used; models must be attributed in documentation. Model 2 - commercial licenses. The Grid Data Service (TGDS) is also available as a commercial license. See [Web Services Terms](https://about.thegrid.id/legal/web-services-terms) for commercial use that is not covered by the open data service. The following applies to both licensing models. - All data is provided AS IS with no guarantees of accuracy. - The Grid does not provide investment, legal, or tax advice, and - a project's presence in The Grid's data does not imply endorsement. - [Data Licensing & Disclaimers](https://about.thegrid.id/legal/data-licensing-and-disclaimers): Licensing models and disclaimers - [Open Data (ODbL)](https://about.thegrid.id/legal/open-data): Open Database License terms and scope for The Grid's open data service. - [Attribution Guidelines](https://about.thegrid.id/legal/open-data-attribution-guidelines): How to attribute The Grid's data when using the open data service. - [Web Services Terms](https://about.thegrid.id/legal/web-services-terms): commercial Terms for using data services. - [All Legal Documents](https://about.thegrid.id/legal): Full index of terms, policies, and disclosures ## Optional - [TGS Field Descriptions](https://github.com/The-Grid-Data/workspace-public/blob/main/references/tgs-field-descriptions.md): Schema field definitions for The Grid's data model - [TGS JSON Structure](https://github.com/The-Grid-Data/workspace-public/blob/main/references/tgs-json-structure.md): Data model structure and relationships - [Product Type Definitions](https://github.com/The-Grid-Data/workspace-public/blob/main/references/product-type-definitions.md): Definitions for each product type - [Product Type Classification](https://github.com/The-Grid-Data/workspace-public/blob/main/references/product-type-classification.md): Guide for classifying products into types - [Grid MCP Guide](https://github.com/The-Grid-Data/workspace-public/blob/main/grid-search/skills/grid-query/references/grid-mcp-guide.md): How to query The Grid programmatically via MCP