Company

Make deep security something every builder can reach.

Trilocore is a small team working on EVM and Solana (SVM) internals, program analysis, and applied AI for security.

Our mission

Audit-grade tooling, without the scarcity

On-chain code moves real value, yet audit-grade tooling stays locked behind scarce engagements. We're putting replay-verified analysis in every developer's hands — and giving auditors leverage to go deeper, faster.

What we build

One workspace, three surfaces

The Contract IDE is where contracts are written, compiled, and reviewed. The Architecture Explorer resolves who actually holds authority over them, read from deployed state rather than from documentation. The Auditing IDE is where they are taken apart — Composer, Scanner, and MorphVM working against the same live fork of real chain state, so a finding is proven by execution instead of argued from a report.

Those three surfaces share one foundation: the fork environments the work runs on, and the analysis engine that reads the bytecode. The intelligence layer over them, Janus AI, is in development and not yet available.

Read how we think about it in our research →

Contract IDE

Where contracts are written, compiled and prepared for review.

  • SurfaceDevelopers
  • ProofCompile, deploy to a fork
Explore the Contract IDE

Auditing IDE

Where they are taken apart, against the same live fork.

  • SurfaceAuditors
  • ProofReplayed on a pinned block
Explore the Auditing IDE

Architecture Explorer

Who holds authority over both, resolved from chain state.

  • SurfaceBoth
  • ProofRead from deployed storage
Explore the Architecture Explorer
Contact

Talk to us

General enquiries go to hello@trilocore.com. Vulnerability reports go to security@trilocore.com; the process is on the Trust Center.

For customers

For protocol teams, audit firms and security engineers who need to prove a finding with reproducible evidence.

Build with us

Work with us on EVM and Solana internals, program analysis and applied AI for security — as an engineer, researcher, partner or backer.

Questions

What people ask first

How is my code and data handled?

Workspaces are private by default: your contracts and programs, session state, and findings are visible only to the people you explicitly share a session with. Verification runs exclusively against isolated forks and captured account state. Live networks are read to source that state, never written to.

How are findings verified?

Every candidate finding is replayed as a proof-of-concept against the pinned fork (EVM) or the captured account set (Solana) of the target chain. If it doesn't reproduce, it isn't reported.

Does this replace a manual audit?

No. Trilocore makes review evidence-based and faster — developers catch what's catchable before review, and auditors spend their scarce time on the reasoning only humans do. High-value protocols should still get expert review.

See it on your own code

Open the workbench, or read how the fork and analysis pipeline fits together.