Trust and Identity squad

AI smart contract review before and after deployment

Sienna Chain, Senior AI Smart Contract Security Lead, an AI agent by FluxForceSienna Chain — Senior AI Smart Contract Security Lead

Sienna Chain is an AI agent for firms that issue or rely on smart contracts. She reviews contract code before deployment, then watches live contracts for unusual activity and unauthorised upgrades. Findings reach your engineering and compliance teams with the evidence attached. People decide what ships and what gets paused.

Sienna Chain
Sienna Chain, Senior AI Smart Contract Security Lead, an AI agent by FluxForce
Contract upgrade detected
IllustrativeFlagged for review
Change risk · high
Flag explained
“Proxy upgraded by a key outside the approved signer set.”
MiCADORA
REPORTS TO
Your CTO and Head of Compliance
Shadow mode first
How Sienna works with your team
Shadow mode
first: nothing acts until you say so
3 bands
of autonomy you configure
Every decision
has a replayable record
1 per agent
kill switch
SaaS · on-prem · hybrid
deployment
Product controls, not performance claims. Performance is measured on your data, in shadow mode.
The problem

The smart contract problem compliance can't see

A smart contract runs rules your customers rely on: who can move funds, when, and how much. Once it's live, a bug or an unapproved upgrade changes those rules for everyone. Compliance often learns about it from the incident.

LIVE CONTRACTS
One upgrade

can change every rule

Users feel it the moment it lands.

Pre-release review

Code that ships under pressure

External audits are booked well ahead and cover one version. Changes made after the audit can go live without the same review.

Unauthorised upgrades

The approved contract isn't the one running

Upgradeable contracts can be changed by whoever holds the admin key. A change outside your approved process is a control failure.

Change evidence

No record of who approved what

Regulators ask for change control evidence. A deployment hash in a chat thread doesn't answer that.

Job description

What Sienna Chain does Job description

Sienna Chain is a Senior AI Smart Contract Security Lead. She sits in your release process and beside your deployed contracts, reviews code before it ships and watches what happens after.

AI AGENT · TRUST AND IDENTITY SQUAD
Sienna Chain, Senior AI Smart Contract Security Lead, an AI agent by FluxForce
SIENNA CHAIN
Senior AI Smart Contract Security Lead
REPORTS TO
Your CTO and Head of Compliance
WORKS WITH
Your code repositories, release pipeline and blockchain nodes
DEPLOYED
Shadow mode first, then the autonomy you set
KEY RESPONSIBILITIES
01Review smart contract code for known vulnerability patterns before each deployment
02Compare the deployed contract with the version your team approved
03Watch live contracts for unusual calls, fund movements and admin actions
04Flag upgrades or admin actions made outside your approved signer set and process
05Send findings to engineering and compliance with the code, transactions and evidence attached
AUTONOMY MODEL
Low risk
Can log routine activity with a reason, if you allow it
LOW
Medium risk
Goes to your team by default
MEDIUM
High risk
Always goes to your team
HIGH
You set the threshold per rule.
Kill switch: Turn Sienna off at any time
Shadow mode

What to measure in shadow mode on your own data

We don't publish detection numbers from our own tests. Run Sienna Chain on your contracts and releases and measure what she finds before she acts on anything.

01
Findings confirmed
Share of Sienna's pre-release findings your engineers confirm as real issues.
02
Missed-issue review
Every issue found later, by an auditor or in production, that Sienna didn't flag. Read this number first.
03
Version match
Share of deployed contracts that match the approved version.
04
Admin action coverage
Share of upgrades and admin calls checked against your signer policy.
05
Live anomaly flags
Unusual activity on live contracts, and how much of it your team confirms.
06
Engineer agreement
How often your engineers agree with Sienna's severity rating.
07
Review turnaround
Time from code ready to findings ready, in your release process.
08
Decisions with evidence
Share of decisions with a replayable record. The target is all of them.
Shadow mode results belong to you. We agree the metrics, the time window and who reviews the closures before the trial starts.
How it works

How AI smart contract review works with Sienna Chain

Sienna Chain connects to your repositories, release pipeline and nodes through APIs. Your contracts and keys stay where they are.

01

Review

Before release, contract code arrives from your repository. Sienna checks it for known vulnerability patterns and lists every change since the last approved version.

02

Verify

At deployment, she compares the deployed code with the approved version and records who signed the deployment.

03

Watch

After release, she reads activity on your contracts and flags unusual calls, large fund movements and admin actions outside your approved signer set.

04

Route and record

Medium findings go to your team by default, and high findings always do. Every finding, its evidence and the human decision go into tamper-evident evidence storage.

Want to see this on your data?

Run Sienna Chain in shadow mode on your next release and your live contracts. She reviews, flags and records, and nothing is paused or held. Compare her findings with your engineers' and auditors' before you switch anything on.

Request a shadow mode trial
Compliance and regulatory mapping

Regulatory frameworks Sienna Chain supports

Sienna doesn't make you compliant. She produces the change and incident evidence these frameworks expect you to keep.

MiCA (Regulation 2023/1114)
Sets the EU framework for crypto-asset issuers and service providers. Sienna keeps a review record for the contracts behind your crypto-asset services.
DORA
EU financial entities manage ICT risk, test resilience and report major ICT incidents. Sienna's record shows what changed, and when.
FATF Recommendation 15
New technologies are expected to be risk-assessed before launch. Sienna's pre-release review adds evidence to that assessment.
VARA
Dubai's Virtual Assets Regulatory Authority supervises virtual asset firms in Dubai. Sienna prepares technology evidence for your VARA reviews.
Basel Principles for Operational Resilience (2021)
Banks are expected to protect their critical operations. Sienna adds change and incident evidence for smart contracts that support them.
ISO/IEC 27001
A standard you may align your change control to. Sienna's review record supports that evidence.
Analyst view

What your engineering and compliance teams see

Every contract change reviewed, and every finding with its evidence.

BEFORE SIENNA CHAIN
One external audit per major version
Post-audit changes shipped without review
Upgrades noticed after users are affected
Admin key use tracked by memory
Change approvals in chat threads
AFTER SIENNA CHAIN
A review on every release
Changes since the approved version listed
Upgrades outside policy flagged when they happen
Admin actions checked against your signer set
Every approval replayable for an examiner
Options

How the options compare

CRITERIA External auditOpen-source scanners Sienna Chain, Senior AI Smart Contract Security Lead, an AI agent by FluxForceSienna Chain
Time to first results Booked well aheadSame day Shadow mode on your next release
Who decides Auditor reports, your team decidesYour engineers Your team, with findings ranked by severity
Covers live contracts NoNo Yes, including upgrades and admin actions
Compliance evidence Audit report per versionRaw tool output Linked record from review to deployment
Depth of review Deep expert reviewPattern checks only Pattern and change checks, with human review of findings
Where it's weaker Covers one version at one point in timeNoisy, with no context or record Doesn't replace a full expert audit for new or high-value contracts
Trust Builders

Built for Regulated Financial Institutions

01

Configurable autonomy

Low risk can run on its own if you allow it. Medium risk goes to a person by default. High risk always goes to a person. You set the bands per rule, channel and transaction type.

02

Kill switch

Turn Sienna off without touching the other agents or your core systems. The switch, and who used it, is stamped on the record.

03

Shadow mode

Run Sienna on live data with nothing blocked or closed. Compare the calls with your team's before anything changes.

04

Explainability

Every decision answers why, in plain English, with the signals and the rule or policy behind it.

05

Audit trail

Each decision is stored with its inputs, its reasoning and the person who approved it, in tamper-evident evidence storage.

06

No migration

Agents connect beside your systems through APIs. Your core banking, screening and case tools stay where they are.

Questions? We Have Answers

Frequently Asked Questions

FluxForce

Still have questions?

Talk to the people who build the agents. We'll answer per capability, yes or no.

It reviews contract code for known vulnerability patterns before release and checks that the deployed version matches what was approved. Sienna Chain also watches live contracts for unusual activity and unauthorised upgrades, and sends every finding to your team with evidence.

No. A full expert audit still matters for new or high-value contracts. Sienna covers the releases between audits, checks what's actually deployed and watches live contracts, which a point-in-time audit doesn't.

No. Sienna flags and recommends. Your team decides whether to pause, roll back or leave a contract running. A kill switch turns Sienna off without touching your contracts.

The contract enforces rules your customers rely on, so a change to it is a change to a regulated service. Regulators ask for change control and incident evidence for that technology as they would for any other.

Sienna reviews your next release and watches your live contracts, but nothing is paused or held. Your engineers and auditors keep working as they do today, and you compare her findings with theirs. You decide whether, and where, to switch on any autonomy afterwards.

Access to contract source code and your release pipeline, the list of approved signers and admin keys, and read access to the chains your contracts run on.

FluxForce runs as SaaS, on-premise or hybrid, built on Microsoft Azure. We agree data residency and which components run inside your environment during deployment design, before any data moves.

Shadow mode trial

See Sienna on your data before anything changes

Run Sienna Chain beside your current process. She works on your live data and records every call, and nothing is blocked, closed or sent until you decide.

  • Runs in shadow mode on your own data, next to your team
  • You agree the metrics, the time window and who reviews the results
  • Kill switch and a replayable record of every decision from day one
  • SaaS, on-premise or hybrid, with data residency agreed up front

Shadow mode results belong to you.

Take the first step

AI agents that prepare the case. Your team makes the call.

Start with one workflow in shadow mode, then decide how much each agent does on its own.

How we start
Discovery and scoping
Integration beside your systems
Shadow mode
Controlled autonomy
Govern and improve