Paste a crypto target. Get an evidence report.
Quick scan
One paste. Auto-detect route. Review the report.
Start with one action: paste a token address, explorer URL, DexScreener pair, public GitHub repo, or Solidity URL. VegaSec routes it into a read-only scan and returns score, confidence, evidence, limitations, and a shareable report.
Operating lanes
Three product paths, one evidence model.
Start with an automated public scan, escalate to operator review when buyers need attestation, then keep the baseline honest with recurring watch events.
Instant scan
Scan: public-source triage in seconds.
Paste a token / pair URL, a public repo, a Solidity contract or an NFT contract URL. VegaSec runs read-only public APIs plus static analysis where source is available, then returns a shareable report with score, evidence, source confidence and a clear next action. Fail-closed to UNKNOWN when context is missing — never demo fallback.
- Automated. No human attestation in this lane.
- Free. No wallet, no login, no signature.
- Shareable. Each scan returns a public report URL.
Private Review
Review: operator-reviewed memo for launches and buyer calls.
When a public scan is not enough, VegaSec confirms scope and returns a confidential risk memo signed by an operator. The memo separates deterministic evidence, agent draft text, and operator-approved claims. Free intake, quote after triage. Paid review does not raise the public score.
- Human operator review. Confidential.
- NDA on request. 90-day default retention.
- No wallet, no custody, no API keys ever requested.
Continuous Watch
Monitor: stale-change checks after the baseline.
Recurring watch keeps the baseline honest after launch: repo changes, contract/source changes, governance movement and re-review triggers are treated as evidence events, not marketing claims.
- Repo Watch for public code changes.
- Contract/source posture checks.
- Re-scan and Private Review follow-up path.
Methodology
Scan, Review, Monitor — one evidence model across every surface.
VegaSec keeps the report model consistent: public Scan creates the baseline, Private Review adds operator approval, and Continuous Watch checks whether code or contract state changed after the baseline. Score, confidence, evidence, limitations and next action stay visible across all three.
Evidence
Public market data, GitHub signal, verified contract source, NFT interface probes — collected server-side.
Score
Deterministic 0–100 derived from severity counts. Same formula across every report; nothing hand-tuned.
Confidence
Separate axis. Low confidence pushes the verdict toward UNKNOWN. The two are never collapsed into one number.
Next action
Verdict copy is operator-facing English: re-scan, run a Private Review, ship a remediation, or escalate.
Who VegaSec is for
Built for teams that need proof before distribution.
The interface separates automated signal, operator approval, and missing-context limitations so every audience knows what is evidence and what still needs review.
Buyer persona
Launch teams
Catch contract, repo and pair issues before a public launch or buyer call.
Buyer persona
Diligence teams
Reach an evidence-backed view of a target inside one buyer conversation.
Buyer persona
Founders + ops
Forward a shareable trust artifact instead of a screenshot or a tweet thread.
Buyer persona
Operators
Use Private Review to attach human attestation when public scans are not enough.
Public sources VegaSec reads
Read-only, server-side, no wallet, no login.
Every signal comes from a public provider we name. No paid data resold, no opaque "intelligence feed", no scraping behind login walls.
All keys are server-side only
DexScreener
DEXToken + Pair market data
Public, key-less pair lookup. Liquidity / holder posture / trading signal.
GitHub public API
GITRepository metadata + commits
Default branch, latest commit SHA, license, README, CI signal, security policy.
Etherscan v2 · Basescan
SRCVerified Solidity source
Acquisition path for slither + semgrep static analysis. Key never exposed to the browser.
Public chain RPC
RPCNFT interface probes
ERC-721 / ERC-1155 detection, tokenURI inspection, owner / proxy state. Anonymous read.