# Trilocore > Trilocore is a smart contract security workbench for developers and auditors. Teams use it > to build and test contracts against real chain state (Contract IDE, fork environments), to > find, replay and report issues in deployed contracts (Auditing IDE, Architecture Explorer, > contract analysis), and to find the contracts worth reviewing (Tradar). A finding is replayed > on an isolated fork before it is reported; no transaction reaches the live network. > > Two ecosystems are supported: six EVM networks (Ethereum, BNB Chain, Polygon, Arbitrum, > Optimism, Base) and Solana (SVM). On EVM a session runs on a fork pinned to a historical > block; on Solana a session captures live account state, and program source is read and > analyzed as Rust rather than compiled. Capability status in the support table uses exactly > two words: Available, or Not available. Janus AI is in development and not available. > Using the product requires an account: sign in or create one at https://app.trilocore.ai. Every page listed in [sitemap.xml](https://trilocore.com/sitemap.xml) is also published as clean markdown at the same path with a `.md` extension (for example `/platform/contract-ide.md`). Prefer the markdown twin over parsing the HTML. The product itself runs at `https://app.trilocore.ai`; its API is `https://api.trilocore.ai` and is documented on a separate docs site. ## Product - [Product overview](https://trilocore.com/platform/index.md): capabilities grouped by what you are trying to do, the teams they serve, the ecosystem support matrix, access and limits. - [Contract IDE](https://trilocore.com/platform/contract-ide.md): write, compile and deploy contracts in the browser — Solidity and Vyper on EVM, Rust programs read and analyzed on Solana — with source kept in private workspace storage and a read-only handoff to an audit team. - [Fork environments](https://trilocore.com/platform/fork-environment.md): test against real chain state, isolated from the network — a fork pinned to a block on EVM networks, captured live account state on Solana; act as any sender, override balances, share the state with your team. - [Auditing IDE](https://trilocore.com/platform/auditing-ide.md): find, replay and report on issues in deployed contracts, working on transactions, calldata and storage against a fork you control. - [Architecture Explorer](https://trilocore.com/platform/architecture-explorer.md): map a protocol's roles, permissions and upgrade paths from deployed state. The explorable map is an EVM capability. - [Contract analysis](https://trilocore.com/platform/analysis-engine.md): analyze deployed contracts, with or without verified source, and review findings that are confirmed on a fork before they are reported. - [Tradar](https://trilocore.com/platform/radar.md): search deployed Ethereum contracts by what they do — address, code hash, function selectors, proxy and admin shape, verified-source and compiler facts. Available today. Coverage is an indexed slice of Ethereum, and every response reports that coverage as incomplete; an empty result means "nothing in the indexed slice", never "nothing on Ethereum". A match is a structural fact about code, not a confirmed vulnerability; there is no monitoring or alerting. - [Janus AI](https://trilocore.com/platform/janus-ai.md): an AI assistant for audit work. In development — not yet available, and nothing in the product calls it today. ## Documentation - [Introduction](https://platform.trilocore.com/docs/en/intro/): what Trilocore is and where to start. - [Quickstart](https://platform.trilocore.com/docs/en/quickstart/): first session, end to end. - [API overview](https://platform.trilocore.com/docs/en/api/overview/): the public HTTP API at api.trilocore.ai. - [API reference](https://platform.trilocore.com/docs/en/api/reference/): per-endpoint reference. - [Authentication](https://platform.trilocore.com/docs/en/api/authentication/): bearer API keys prefixed `jns_`. - [Errors](https://platform.trilocore.com/docs/en/api/errors/): error shapes and status codes. - [Rate limits](https://platform.trilocore.com/docs/en/api/rate-limits/): quotas and limits. - [Idempotency](https://platform.trilocore.com/docs/en/api/idempotency/): mutating calls require an `Idempotency-Key`. ## For agents - [auth.md](https://trilocore.com/auth.md): how an agent authenticates, and what does not exist (no OAuth/OIDC discovery, no agent self-registration, no published OpenAPI file). - [API catalog](https://trilocore.com/.well-known/api-catalog): RFC 9727 linkset pointing at the API documentation. - [Capability manifest](https://trilocore.com/.well-known/ai-catalog.json): ARD manifest for this origin. - [Agent skills](https://trilocore.com/.well-known/agent-skills/index.json): skills discovery index. - [Security policy](https://trilocore.com/.well-known/security.txt): RFC 9116 vulnerability reporting. - [Sitemap](https://trilocore.com/sitemap.xml): every canonical URL on this site. ## Research - [Research index](https://trilocore.com/research/index.md): on-chain incidents rebuilt on a pinned fork, and the vulnerability patterns behind them. - [Re-auditing the Euler attack](https://trilocore.com/posts/euler-donation-retrospective.md): how the Euler donation attack worked, why audits missed it, and how an auditor recognises and confirms the same missing-invariant bug on a fork. - [The exploit hiding in dead code](https://trilocore.com/posts/orphan-block-delegatecall.md): how a computed jump into an orphan basic block can hide a DELEGATECALL takeover from source review, and how a defender confirms whether it is reachable. ## Optional - [Company](https://trilocore.com/company.md): mission, what we build, how to reach us. - [Book a demo](https://trilocore.com/demo.md): what a technical walkthrough covers, and how to request one. - [Trust Center](https://trilocore.com/security.md): our security and privacy commitments, what is and is not offered today, and how to report a vulnerability. - [Privacy Policy](https://trilocore.com/privacy.md) - [Terms of Use](https://trilocore.com/terms.md)