CertiK has repositioned itself as “The Trust Layer for Digital Value,” expanding its public identity beyond smart contract auditing and toward continuous security, compliance, and risk-management infrastructure for digital-asset markets.
The company announced the brand refresh on Oct. 7 during the TOKEN2049 conference in Singapore. CertiK said the updated positioning reflects a plan to serve financial institutions, regulators, enterprises, and digital-asset businesses that need ongoing technical oversight rather than a security review conducted only before a product launch.
Jiang said the shift builds on CertiK’s Web3 security business while extending into the wider digital economy. The company’s framing places security monitoring, regulatory compliance, reserve verification, and code assurance under one operating model designed for markets where digital assets move continuously.
The announcement arrives as thefts and technical exploits remain a costly problem for the sector. CertiK reported that hackers stole about $1.26 billion across 247 security incidents during the third quarter of 2026, following $972 million in losses during the first half of the year. Those figures underscore the limitations of a security process centered entirely on a one-time audit before deployment.
A security suite built for ongoing oversight
CertiK named four core products under its new positioning: Skynet, CertiK Compliance, CertiK Supervision, and CertiK AI Auditor. Together, the tools are intended to provide continuous monitoring of security risks, help organizations manage compliance requirements, oversee digital-asset activity, and use artificial intelligence to assist in reviewing software code.
Skynet has been CertiK’s monitoring platform for detecting on-chain threats and suspicious activity. Its inclusion in the refreshed suite suggests that real-time surveillance is becoming central to the company’s commercial pitch, rather than a supplementary service attached to contract audits.
CertiK Compliance and CertiK Supervision are directed at institutions operating under growing regulatory expectations. The company described the products as tools for compliance risk management and digital-asset oversight, two areas that have become increasingly relevant as banks, payment companies, fund managers, and regulated token issuers assess how to handle blockchain-based assets.
CertiK AI Auditor adds an automated component to code assessment. AI-assisted review can help security teams examine large volumes of code and identify areas that warrant deeper human analysis, though automated tools do not remove the need for manual review, formal verification, or testing of how a system behaves under real operating conditions.
The product lineup is paired with CertiK’s existing professional services, including smart contract audits, expert-led formal verification, penetration testing, proof of reserves, and node validation. Formal verification uses mathematical methods to test whether code conforms to defined rules or properties. It can offer a deeper level of assurance than conventional code review for certain high-value systems, although its usefulness depends on the assumptions and specifications used in the process.
From audits to risk management
The company’s updated model reflects a practical change in how digital-asset security is being sold and assessed. Smart contract audits remain a common safeguard before a protocol launches or upgrades, but an audit only assesses a particular version of code within a defined scope. It may not capture later changes to administrative controls, oracle feeds, bridges, wallet permissions, market manipulation risks, or vulnerabilities introduced through connected third-party services.
Continuous monitoring is meant to address some of those operational gaps. It can track unusual asset flows, changes in privileged addresses, liquidity movements, and other on-chain signals that may indicate an exploit or emerging risk. Proof-of-reserves work can also provide visibility into whether a custodian or platform can demonstrate assets associated with user balances, although the scope and methodology of each attestation remain crucial.
CertiK’s emphasis on compliance adds another layer. Digital-asset companies are increasingly expected to show that they can manage technical controls alongside requirements related to market conduct, custody, disclosures, financial crime controls, and consumer protection. A company that combines technical testing with compliance systems could appeal to organizations seeking fewer separate vendors for those functions.
CertiK said its policy-related technical support has extended to the United States, Hong Kong, Singapore, and the United Arab Emirates. The company described that work as connecting technical security assessments with requirements in regulated digital-asset markets. Those jurisdictions have each developed distinct approaches to licensing, stablecoins, custodial services, token offerings, or virtual-asset supervision, creating demand for security providers that can translate blockchain risks into operational controls.
Company cites global client base and vulnerability findings
Founded in 2017 by professors from Yale University and Columbia University, CertiK said its work originated in formal verification research. The firm reported that it has served more than 5,500 clients in over 150 countries and regions, identified more than 119,000 code vulnerabilities, and helped protect more than $600 billion in digital assets.
Those company-reported figures portray CertiK as one of the larger specialist security providers in the sector, but the brand refresh also broadens the competitive field it is entering. Firms offering cybersecurity services, blockchain analytics, compliance software, custody technology, and risk intelligence are all pursuing institutional digital-asset clients.
CertiK co-founder Gu has argued that multi-layered defenses should become standard practice for the industry. The company’s rebrand puts that argument at the center of its business strategy: security is presented as a continuing operational function involving code, infrastructure, reserves, governance, transaction monitoring, and regulatory controls.
For token issuers, DeFi protocols, custodians, and institutions handling digital assets, the practical test will be whether these services can identify and contain risks after deployment, when the largest financial exposures often emerge. CertiK’s new identity places it squarely in that higher-stakes segment of the market.
Strengthen your Web3 security stack with Toobit’s advanced risk control system and institutional-grade protection tools.
Disclaimer: The content on this page is provided for general informational purposes only and does not represent the views or financial advice of Toobit. We make no guarantees regarding the accuracy or completeness of this information and shall not be held liable for any errors, omissions, or outcomes resulting from its use. Investing in digital assets involves risk; users should independently evaluate their financial situation and the risks involved. For further details, please consult our Terms of Service and Risk Disclosure.
