PROBUS CHECK

Clear your code
before launch.

Security checks for Solana programs, built for builders who ship with AI, not for security teams. Connect a repo and know what’s risky in minutes, not weeks.

Connect a repo · report £15

Connecting is free. You pick which repositories Probus can read, and you can disconnect at any time.

Minutes
to your report
Anchor
programs
4
severity levels, plain English

Build, audit, fix. All with AI.

The same tools you already use to write the code are the ones you use to secure it.

01

Build

Ship your program with Claude Code, Cursor, or Nanocoder, however you already work. Probus doesn’t change how you build.

02

Audit

Run Probus against the repo. Findings come back ranked by severity and explained in plain English, not security jargon.

03

Fix

Paste the fix brief straight back into your AI coding tool. Or, if you’d rather not, Ava can fix it for you.

BUILT FOR SOLANA, NOT BOLTED ON

A generic code review doesn’t know what a signer check is.

Ask a general-purpose AI to review a Solana program and it reasons from web and Ethereum patterns, because that’s most of what it’s seen. The failure modes here are structurally different.

MISSING SIGNER CHECK

No caller identity, unless the instruction demands one.

Solana instructions execute against whatever accounts are passed in. There’s no session or auth token by default. If an instruction doesn’t explicitly require is_signer on the right account, anyone can call it as anyone.

A generic review checks for access control in the web sense, routes, roles, permissions. It won’t know this explicit check is the actual boundary here.

UNCHECKED ACCOUNT OWNERSHIP

Any account can be passed into any instruction.

Reading data from an account without confirming your own program actually owns it means a lookalike account can be swapped in and trusted by mistake.

There’s no equivalent failure mode in most codebases a general model has trained on, so there’s nothing to pattern-match against.

COLLIDING PDA SEEDS

Deterministic addresses can collide across upgrades.

Program Derived Addresses are computed from seeds. Change the seed structure in an upgrade without versioning it, and a future address can collide with one that already exists.

PDAs don’t exist outside Solana. A generic reviewer has no concept of a deterministic, seed-derived address to reason about at all.

The rule pack is built around findings like these because they’re the ones raw prompting reliably misses, not the ones any tool would catch.

WHY TRUST A SCORE

A number only matters if you know what it’s measuring.

Probus Verified means an Ava engineer has reviewed the automated findings and confirmed the ones that matter.

It’s the accessible middle layer between shipping with no checks at all and commissioning a full professional audit, not a replacement for one. For a program handling significant value ahead of a raise or mainnet launch, a dedicated audit firm remains the right call.

No automated tool, including this one, catches everything. A review reflects what was found in the code as it stood at one commit. If an issue surfaces later, that reflects the limits of a point-in-time review, not a guarantee that was made and broken — see our terms.

—
Real incidents tested against
—
Vulnerability classes caught pre-launch
—
Solana repos scanned to date
Published once the first benchmark run is complete
PRICING

Pay for what you’re risking, not for using the tool.

Connecting a repo is free. You pay when you want the review.

Baseline

One-off report

£15 / repo

A full review of one program, and a re-scan once you’ve fixed things.

  • Every finding, with file and line
  • Fix brief for your AI coding tool
  • Health score and severity breakdown
  • One re-scan within 30 days
Connect a repo
Need it fixed, not just found? Ava does fixed-price remediation work, from £1,500.
Get a quote →
Running a hackathon or grant program? We audit at cohort scale for ecosystems and foundations.
Talk to us →

Know before you ship.

Connect a repo · report £15

Connecting is free. The report is £15 for one repository, and includes a re-scan once you’ve fixed things.