

VIOLET SKY SECURITY
Smart contract security for regulated digital-asset markets, focused on the Cayman Islands (CIMA) tokenised-fund and VASP regime.
Smart Contract Audits · vCISO · GRC · Threat Modelling · AI Implementation
POST-QUANTUM Readiness & Crypto-Agility
Strategic advisory for the 2030/2035 migration cliff. If your data must stay confidential past 2030, the migration clock has already started. NIST IR 8547 deprecates classical key-establishment by 2030 and disallows it after 2035 even in legacy systems; UK NCSC sets the same 2035 date; CNSA 2.0 mandates ML-KEM and ML-DSA.
We deliver what auditors will ask for: CBOM inventory aligned to CycloneDX 1.7 and PCI DSS 4.0 Req 12.3.3, Harvest-Now-Decrypt-Later exposure analysis using our two-clock model, crypto-agility scoring, and hybrid deployment (X25519MLKEM768 0x11EC, ML-DSA-65/87) with enforced downgrade refusal, not merely offered.
Built from production, not slides: live hybrid X25519+ML-KEM-768 TLS and escrow, on-chain ZK verification, and PQChecker, our 8-step transaction-chain verifier that measures whether every hop enforces post-quantum protection, not just offers it, and fails closed at the exact step. The weakest hop sets the chain verdict; posture is never inherited. Verification runs entirely in your browser.
Try it at https://foss.violetskysecurity.com/PQChecker.html
Maps to DORA Art.9, NIS2 Art.21(2)(h), CNSA 2.0, and NIST 2030/2035 timelines. Offered as a fractional CISO retainer or a 6-week PQC Sprint with board pack, vendor roadmap, and receipt-based evidence.
COMPLIANCE ASSISTANCE
Technical security assessment aligned with regulatory frameworks including:
· CIMA (Cayman Islands 2026 Tokenized Fund Amendments)
· BMA Operational Cyber Risk Management Code 2024
· MiCA (EU)
· VARA (UAE)
· MAS Project Guardian
· DORA (EU financial entities)
· NIST CSF
· ISO 27001
· PSD2
· GDPR.
VSS delivers the technical security review only; any legal or regulatory opinion is issued by qualified counsel or a CIMA-approved auditor, not by VSS. We work alongside Cayman counsel rather than in place of them.
Multi-chain smart contract security built on the 7-step Halborn agentic AI methodology.
Every engagement delivers:
· STRIDE threat model specific to your contract architecture
· Evidence-based proof of exploit for every High and Critical finding
· Echidna fuzzing invariant candidates validated by the auditor
· Per-finding Tenderly and Forta monitoring configurations
· BSSC SCS v1 (2026) conformance assessment
· Three-Document Alignment Review for Cayman tokenised funds
(CIMA registration → constitutional documents → smart contract code)
Audit reports aligned with BSSC SCS v1 (2026), OWASP SCS, and SWC
Registry. BVSS-scored findings. SHA-256 file integrity verification.
All analysis runs air-gapped, no source code transmitted to third-party services.
SOLUTION & SECURITY ARCHITECTURE
Security architecture for blockchain and digital asset infrastructure. Design, review, and implementation of secure systems from initial architecture through production, applying security-by-design principles at every layer. Covers cloud, on-chain, and hybrid architectures for regulated environments.
THREAT MODELLING
Threat modelling using STRIDE, PASTA, and MITRE ATT&CK frameworks — covering technology, process, human factors, and organisational culture. Delivered for banks, fintechs, and regulated Web3 environments.
AI Implementation
AI adoption that survives audit. Independent advisory for organisations bringing Claude and other LLMs into regulated environments.
Security-by-design for the agentic enterprise.
We build, audit, and govern AI systems that boards, regulators, and CISOs can defend.
CYBER SECURITY & GOVERNANCE (GRC)
Enterprise GRC advisory covering Cyber Security, Risk, and Compliance management. SIEM implementation, threat intelligence, incident response planning, and Data protection advisory (GDPR) — prior DPO experience available on request.
Delivered for regulated financial institutions and digital asset businesses requiring board-level risk governance.
vCISO / vCTO
Fractional CISO and CTO services for regulated digital asset businesses. Security programme design, board-level risk reporting, regulatory engagement, and security team leadership, without the overhead of a full-time hire.

OUR MISSION
Securing regulated digital asset infrastructure with institutional-grade methodology. Bridging the gap between smart contract security and regulatory compliance, for the markets that need both.

Industries
Banking & Financial Services · Fintech · Telecommunications · Software Development · Consulting
Sectors we audit (smart-contract security & advisory):
DeFi · Tokenized Funds & RWA · Digital-Asset Issuers · NFT platforms · Regulated Exchanges / VASPs
Regulatory frameworks:
Cayman Islands (CIMA) — primary · with alignment to MiCA (EU), VARA (UAE), MAS (Singapore), BMA (Bermuda)

GET IN TOUCH
OUR OFFICES
Violet Sky Security SEZC
Incorporated in Cayman Islands, Special Economic Zone.
Mobile: +1 345-328-8947
For any general inquiries, please fill in the following contact form:

Founder and Lead Auditor

Rudold J. Coetzee
Mobile: +1 345 328 8947
rudi(a)violetskysecurity.com
CISSP-ISSAP · CISSP-ISSMP · CSSLP · GSLC
· ISO27001 LA · CCI+ · GCHQ CIRP
31 years in IT, 22 years cybersecurity · Tier 1 European banking
Author of the SPT-Txn Internet-Draft (draft-coetzee-oauth-spt-txn-tokens), an IETF OAuth Working Group submission extending RFC 9700, with formal security proofs (Zenodo) and an OpenBSD reference implementation.
Est 2011 since Violet Sky Security