Skip to content

Once published, it cannot be recalled. So we test first.

We run attack tests and simulations on a test network until behaviour is proven, and only then move to the main network.

What you get

  • Contracts tested and reviewed before they touch real funds
  • Revenue-share and fee rules readable by anyone, in the open
  • Wallets, payments, and bookkeeping wired into your existing systems
  • Keys and authority stay with you, not with us

Capabilities

What this covers

Yield & Automated Exchange

Locking, distribution, and swapping that run on their own.

  • Fee and revenue-share rules readable by anyone, in the open
  • Brakes that stop value being dumped all at once
  • Worst-case scenarios simulated before real funds go in
  • Emergency pause switch if something goes wrong
  • Keys and authority stay in your hands

Typical scope

  • Yield & staking platform

    Time-locked deposits, scheduled distributions, and brakes that stop the value being dumped all at once.

    • Brakes simulated before launch
    • Yield calculations anyone can verify
    • An emergency pause switch

    Typical duration: 6–10 weeks

  • Automated exchange & lending

    Intermediary-free asset swapping and collateralised lending, with monitoring and a collateral-recovery mechanism.

    • Price references resistant to manipulation
    • Risk limits and isolation between assets
    • Adverse market conditions simulated before launch

    Typical duration: 8–14 weeks

  • Decentralised exchange build

    Liquidity pools, swap routing, fee logic, and an interface an ordinary person can use — plus an admin panel to change fees without touching code.

    • Liquidity pools and swap routing
    • Fees configurable from a panel
    • An interface that demands no technical knowledge

    Typical duration: 8–14 weeks

  • Lending protocol build

    Isolated per-asset markets, collateral thresholds, a liquidation engine, and interest curves — with risk separated so one collapsing asset cannot drag the whole protocol down.

    • Isolated markets: one asset failing does not spread
    • A liquidation engine with stress testing
    • Interest curves adjustable without redeployment

    Typical duration: 10–16 weeks

Request consultation

Talk to us about scope and pricing.

Real-World Asset Tokenisation

Assets that genuinely exist, opened to a wider pool of investors.

  • Proof the asset exists, open for anyone to verify at any time
  • Rules on who may buy enforced by the system itself, country by country
  • Ownership register and profit distribution calculated automatically
  • Built compliance-ready from the first line of code
  • All code, documentation, and control handed over to you in full

Typical scope

  • Discovery & token design

    Two weeks to lock the token structure, holder rights, jurisdiction map, and technical specification — before code is written.

    • A chosen structure out of four options, with the reasoning
    • Holder rights and the distribution scheme spelled out
    • A jurisdiction map with its list of legal requirements

    Typical duration: 2 weeks

  • Real-world asset tokenisation platform

    A four-layer platform — asset, verification, token, and application — built compliance-ready from the start, with an investor portal and issuer console.

    • Rules on who may buy enforced country by country
    • Proof the asset exists, open for anyone to check
    • Ownership register and distributions calculated automatically

    Typical duration: 4–12 weeks

  • Compliance layer

    Identity checks, rules on who may hold and transfer, screening, and periodic reporting — per jurisdiction.

    • Adding a country is configuration, not a rebuild
    • Transfer rules enforced by the system itself
    • Periodic reports assembled automatically

    Typical duration: 4–8 weeks

  • Platform operations

    Maintenance, infrastructure, data providers, and compliance updates for a platform already running.

    • Maintenance with a written response time
    • Infrastructure, data providers, and network nodes
    • Compliance updates when the rules change

    Typical duration: Annual

  • Real-world asset tokenisation

    Issuing fractional ownership of a physical asset or receivable: issuance contracts, evidence storage, distribution rails, and transfer restrictions where required.

    • Issuance contracts and fractional ownership
    • Asset evidence storage anyone can verify
    • Automated distribution to holders

    Typical duration: 10–16 weeks

Request consultation

Talk to us about scope and pricing.

Smart Contract Development

Rules enforced by the network, not by trust.

  • Layered testing and review before real funds are involved
  • Fee and revenue-share rules readable by anyone, in the open
  • Keys and authority stay in your hands
  • Connected to the bookkeeping and payments you already run
  • Full test reports handed over, including the failures

Typical scope

  • Contract audit — up to 500 lines

    A layered security review with reproducible attack paths, plus one retest after fixes.

    • Findings ranked by real danger, not by count
    • Every finding carries a reproducible attack path
    • One retest after fixes is included

    Typical duration: 2 weeks

  • Contract audit — 500 to 1,500 lines

    A larger scope with per-dimension review: arithmetic, access control, external calls, price feeds, and economic resilience.

    • Review dimension by dimension, not a single sweep
    • Resilience tested with randomised input, not just the happy path
    • Core properties proven to hold, not assumed

    Typical duration: 3–4 weeks

  • Contract monitoring

    Watching a live contract: alerts on unusual behaviour, and an emergency pause switch ready to use.

    • Alerts when behaviour falls outside the norm
    • An emergency pause switch that has been tested, not merely present
    • A monthly report on what happened and what did not

    Typical duration: Monthly

  • Contract recovery & upgrade

    Handling the aftermath of an exploit or a needed upgrade: recovering remaining funds, patching, and migration.

    • Recovering remaining funds comes first
    • The cause is traced, not merely patched over
    • Migration of holders to a new contract

    Typical duration: Diagnosis first

  • Smart contract audit

    Line-by-line review by several auditors working from different angles, plus invariant and fuzz testing — not a scanner run pasted into a report template.

    • Several auditors working from different angles, not one person
    • Invariant and fuzz testing, not just the happy path
    • Every finding carries a concrete exploit path

    Typical duration: 2–5 weeks

  • Token economics audit

    Testing whether the economic design holds under pressure: where the yield is actually paid from, what happens if the price halves, and who benefits most if everyone exits at once.

    • The true source of every promised yield
    • Stress simulation: price drop, thin liquidity, simultaneous exit
    • Unlock schedule and its effect on price

    Typical duration: 2–3 weeks

Request consultation

Talk to us about scope and pricing.

Blockchain & Digital Assets

Contracts and tokens anyone can audit.

Typical scope

  • Tamper-proof certificates

    Diplomas, quality certificates, and export documents whose authenticity anyone can verify in seconds.

    • Verifiable by anyone without contacting the issuer
    • Document contents are not published — only the proof
    • Revocable if the document is cancelled

    Typical duration: 3 weeks

  • Cross-border payments & settlement

    On- and off-ramps plus cross-border settlement that completes in minutes rather than days.

    • Settlement in minutes
    • Identity checks and screening as required
    • Automatic reconciliation with your existing bookkeeping

    Typical duration: 8–12 weeks

  • Protocol operational security audit

    Reviewing the layer a contract audit does not touch: who holds the keys, who can change parameters, how deployments happen, where prices come from, and whether abuse would be visible before the money is gone.

    • Who holds the keys, and what they can do alone
    • Real multisig authority and signing thresholds
    • Deployment path: who can swap a contract unobserved

    Typical duration: 3–4 weeks

  • Milestone escrow

    Funds locked in a contract and released per milestone when both sides agree, with a dispute route for when they do not.

    • Milestone-based release
    • A dispute route with an arbiter
    • A trail both sides can inspect

    Typical duration: 6–10 weeks

  • Token launch & vesting portal

    Allocation design, vesting contracts, a claim portal for holders, and an issuer panel — so the promised schedule is enforced by code rather than promised in a document.

    • Vesting enforced by contract
    • A claim portal ordinary people can use
    • An issuer panel to monitor distribution

    Typical duration: 6–10 weeks

  • Protocol monitoring & early alerts

    Continuous watch over protocol invariants: solvency, unusual movement, privileged calls, and parameter changes — alerting the person who can act, not a dashboard nobody watches.

    • Solvency invariants checked continuously
    • An alert on every privileged call
    • Detection of out-of-hours parameter changes

    Typical duration: Ongoing

  • Key management & multisig authority design

    Setting who holds what, how many signatures each class of action needs, how keys rotate when someone leaves, and what happens if one holder is lost.

    • A map of who can do what alone, today
    • Signing thresholds per class of action
    • Key rotation when someone leaves

    Typical duration: 2–3 weeks

  • Price oracle integration & hardening

    Wiring price sources with fallbacks, time-weighted averaging, and movement bounds — so one briefly manipulated price cannot drain the protocol.

    • Redundant price sources, not a single point
    • Time-weighted averaging against brief manipulation
    • Movement bounds and circuit breakers

    Typical duration: 2–4 weeks

  • Post-exploit protocol rescue

    Stopping the bleeding, establishing what happened, securing what remains, and building a recovery path that can be explained to holders.

    • Stop the bleeding first, investigate second
    • Fund tracing and securing what remains
    • Establishing the attacker’s entry path

    Typical duration: Immediate, then 2–6 weeks

Request consultation

Talk to us about scope and pricing.

Questions we are asked most

When is blockchain actually the right tool?

When several parties who do not trust one another must agree on the same record, and the rules have to be readable in the open so nobody can quietly change them. If everyone already trusts a single operator, an ordinary database is cheaper and faster — and that is what we will recommend.

Which networks do you work on?

Ethereum-compatible networks, including Polygon and Base where low network fees matter. The choice is driven by cost, liquidity, and where your investors already are — not by our preference.

What does publishing a contract cost?

The network fee itself is small; what drives cost is the design and the audit. A contract audit up to 500 lines is a fixed USD 5,000 including one retest, and 500 to 1,500 lines is USD 9,500. For a full platform, the figure is locked once the token design is final.

Is the contract reviewed before launch?

Always, and it is not an optional extra. We review dimension by dimension — arithmetic, access control, external calls, price references, economic resilience — then test with randomised input rather than only the happy path. Once published, a mistake cannot be recalled.

Who holds the keys and the authority?

You do. We set up multi-signature wallets, approval thresholds, and key rotation procedures, then hand over control at completion. We do not hold client keys — one person holding every key is the most common way funds are lost permanently.

How we engage

Choose the engagement that fits where you are

Not every piece of work belongs in a big project. These four are what we normally use — scope and duration agreed before anything starts.

  • Rapid assessment

    Find out what is actually broken before committing a large budget.

    1–2 weeks

    • Interviews with the people who actually run the process
    • A count of the hours and money currently being lost
    • Findings ranked by real cost, not by volume
    • A staged recommendation with time and cost estimates

    Best when: You know something is wrong, but not yet which part is costing you most.

  • Fixed-scope project

    The outcome, the date, and the scope agreed up front.

    4 weeks – 8 months

    • A written scope, a delivery date, and agreed acceptance criteria
    • A demo every two weeks — you watch progress instead of waiting for news
    • Testing plus hand-over of the code and its documentation
    • A warranty period for fixes after the system goes live

    Best when: The need is already clear and you want budget certainty.

  • Dedicated team

    Our team works full time for you, following your priorities.

    From 3 months

    • A standing team: engineering, testing, and one accountable lead
    • You set the priorities, reviewed every two weeks
    • Working Indonesian hours, adjustable to your time zone
    • Scaled up or down month by month

    Best when: The roadmap is long and priorities will still shift along the way.

  • Monthly retainer

    A live system kept running, updated, and watched.

    Monthly, cancel any time

    • Monitoring, backups, and security updates
    • A fixed block of hours each month for fixes and small features
    • An agreed response time when something goes wrong
    • A monthly report on what was done and what needs deciding

    Best when: The system is live and you would rather not wait until it breaks.

  • The code and documentation become yours
  • An NDA from the first conversation
  • A post-release fix warranty
  • Progress reported every two weeks
  • No vendor lock-in — another team can take over

Talk through web3 & blockchain for your organisation

One conversation is enough to know whether this is worth doing now or later.

Web3 & Blockchain — Neuraltan