Public scan · no wallet · evidence-first

Paste a crypto target. Get an evidence report.

Quick scan

One paste. Auto-detect route. Review the report.

No walletNo loginEvidence-based

Start with one action: paste a token address, explorer URL, DexScreener pair, public GitHub repo, or Solidity URL. VegaSec routes it into a read-only scan and returns score, confidence, evidence, limitations, and a shareable report.

Operating lanes

Three product paths, one evidence model.

Start with an automated public scan, escalate to operator review when buyers need attestation, then keep the baseline honest with recurring watch events.

No wallet, no login, no signature.
Public sources only; missing context fails closed to UNKNOWN.
01

Instant scan

Scan: public-source triage in seconds.

Paste a token / pair URL, a public repo, a Solidity contract or an NFT contract URL. VegaSec runs read-only public APIs plus static analysis where source is available, then returns a shareable report with score, evidence, source confidence and a clear next action. Fail-closed to UNKNOWN when context is missing — never demo fallback.

  • Automated. No human attestation in this lane.
  • Free. No wallet, no login, no signature.
  • Shareable. Each scan returns a public report URL.
Run an instant scan
02

Private Review

Review: operator-reviewed memo for launches and buyer calls.

When a public scan is not enough, VegaSec confirms scope and returns a confidential risk memo signed by an operator. The memo separates deterministic evidence, agent draft text, and operator-approved claims. Free intake, quote after triage. Paid review does not raise the public score.

  • Human operator review. Confidential.
  • NDA on request. 90-day default retention.
  • No wallet, no custody, no API keys ever requested.
Request a Private Review
03

Continuous Watch

Monitor: stale-change checks after the baseline.

Recurring watch keeps the baseline honest after launch: repo changes, contract/source changes, governance movement and re-review triggers are treated as evidence events, not marketing claims.

  • Repo Watch for public code changes.
  • Contract/source posture checks.
  • Re-scan and Private Review follow-up path.
Explore Continuous Watch

Methodology

Scan, Review, Monitor — one evidence model across every surface.

VegaSec keeps the report model consistent: public Scan creates the baseline, Private Review adds operator approval, and Continuous Watch checks whether code or contract state changed after the baseline. Score, confidence, evidence, limitations and next action stay visible across all three.

01

Evidence

Public market data, GitHub signal, verified contract source, NFT interface probes — collected server-side.

02

Score

Deterministic 0–100 derived from severity counts. Same formula across every report; nothing hand-tuned.

03

Confidence

Separate axis. Low confidence pushes the verdict toward UNKNOWN. The two are never collapsed into one number.

04

Next action

Verdict copy is operator-facing English: re-scan, run a Private Review, ship a remediation, or escalate.

Who VegaSec is for

Built for teams that need proof before distribution.

The interface separates automated signal, operator approval, and missing-context limitations so every audience knows what is evidence and what still needs review.

Buyer persona

Launch teams

Catch contract, repo and pair issues before a public launch or buyer call.

Buyer persona

Diligence teams

Reach an evidence-backed view of a target inside one buyer conversation.

Buyer persona

Founders + ops

Forward a shareable trust artifact instead of a screenshot or a tweet thread.

Buyer persona

Operators

Use Private Review to attach human attestation when public scans are not enough.

Public sources VegaSec reads

Read-only, server-side, no wallet, no login.

Every signal comes from a public provider we name. No paid data resold, no opaque "intelligence feed", no scraping behind login walls.

All keys are server-side only

DexScreener

DEX

Token + Pair market data

Public, key-less pair lookup. Liquidity / holder posture / trading signal.

GitHub public API

GIT

Repository metadata + commits

Default branch, latest commit SHA, license, README, CI signal, security policy.

Etherscan v2 · Basescan

SRC

Verified Solidity source

Acquisition path for slither + semgrep static analysis. Key never exposed to the browser.

Public chain RPC

RPC

NFT interface probes

ERC-721 / ERC-1155 detection, tokenURI inspection, owner / proxy state. Anonymous read.