Solana Ecosystem
A structured approach to evaluating the security posture of projects in the Solana ecosystem. Eight pillars, each scored on a four-point maturity scale — from Not Implemented to Advanced.
Scoring System
Each control is scored on a four-point scale. Pillar scores average their underlying controls and map to a risk tier.
Framework
Controls are organized into eight pillars, each targeting a distinct domain of the security posture.
Code review, external audits, bug bounties, defense-in-depth mechanisms, and automated security tooling
→Privileged roles, upgrade authority, timelocks, multisig configuration, and risk parameter controls
→Dependency mapping, oracle architecture, staleness handling, and blast radius containment
→DNS and domain security, web application security, key management, off-chain services, and RPC
→Dependency pinning, branch protection, code review, signed releases, and CI/CD pipeline security
→Endpoint security, multisig operations, access management, communications, treasury, and inventory
→On-chain monitoring, circuit breakers, incident response playbooks, on-call, and security partners
→Log coverage, collection and retention, normalization, detection rules, and alerting escalation
→