Terms of Service
Last updated: 1 August 2026
These terms apply to smart contract security reviews and audits provided by Adomas Venslovas, trading as Alex Cipher. Anything agreed in writing for a specific engagement takes precedence over what is written here.
Scope of an engagement
Each engagement covers a defined set of contracts at a defined commit or deployed address, agreed in writing before the work starts. Code outside that scope is not reviewed.
If the scope changes after work has begun — new contracts, significant rewrites, or a materially larger codebase than described — the price and delivery date are re-agreed before the additional work is carried out.
Pricing and payment
Prices published on this site are fixed for the scope they describe. Final pricing is confirmed after a scoping call based on the actual size and complexity of the code.
Payment is arranged before the review begins. The agreed price is the total price for the agreed scope; there are no hourly overruns.
No-findings refund
If a completed review surfaces no issue rated above informational severity, you are entitled to a full refund of the fee for that engagement, and you keep the delivered report.
Severity ratings are assigned using the impact-and-likelihood scale set out in the report itself. Refund requests should be raised within 14 days of delivery.
This applies to the agreed scope as delivered. It does not apply where the review could not be completed because access to the code was withdrawn or the scope was materially misrepresented.
Delivery
Delivery timelines are stated per tier and start from the point the final code and any required context are provided. Delays in providing access to the codebase move the delivery date accordingly.
Deliverables are a written findings report with severity ratings and remediation guidance, plus the follow-up support described for the tier you booked.
What an audit is, and is not
A security review is a best-effort expert assessment carried out within an agreed time and scope. It is not a guarantee that the code is free of vulnerabilities, and it is not insurance, a warranty, or financial advice.
No audit — from any auditor or firm — can prove the absence of bugs. Findings and recommendations are advisory: you remain responsible for deciding what to implement and for the security and operation of anything you deploy.
Liability arising from an engagement is limited to the fees paid for that engagement, to the extent permitted by law.
Confidentiality
Your code, findings, and correspondence are treated as confidential and are not published or shared without your written permission. A mutual NDA can be signed on request.
Reports are published on this site only where the client has agreed to it.
Intellectual property
You own your code. You receive the report and full rights to use it internally and to publish it, provided it is published unaltered and in full.
Articles, reports, and other material published on this site remain my copyright and may be quoted with attribution.
Contact
Questions about these terms can be sent to hello@alexcipher.xyz.