Ascend runs end-to-end on a public testnet today. The system was built in-house; OpenZeppelin is the security and audit partner. A working testnet is not yet a release candidate. Two stages separate today from mainnet in early 2027: Stage A — five internal readiness gaps, no external party needed — produces the release candidate; Stage B — three externally procurable verification legs — takes it to mainnet. Each external leg maps one-to-one to a part of the scope-of-work document now going to vendors, so incoming quotes land apples-to-apples against the cost cards on this page. How the system got here — what shipped, when, and by whom — is charted in the development history below.
Ascend has been paying for platform development since about January 2026.[17] The chart shows what shipped, when, and by whom — from the OpenZeppelin engagement through the June 9 decision to build in-house, to today. The repository record shows the shape plainly: no shipped code in January, OpenZeppelin's first feature commits in early February, and an MVP-grade private beta by late May. The in-house era opens June 8; a full end-to-end stack was live on the Ascend testnet by June 11 and has grown into today's full-featured private beta. Every dated element carries its provenance; single-source and asserted dates are tagged.
Marcelo (CSO) works the commercial and strategy track — the OpenZeppelin commercial relationship and partner engagements. That stream ships no code, so he carries no bar color and is not folded into any other contributor; he is part of the June 9 build-in-house decision milestone. Lane colors identify contributors only — they carry no status or performance meaning.
Bars are feature groups colored by contributor; widths are calendar spans from the repository record, not effort. The right edge of this chart hands off to the 'Now' node of the roadmap in the next section.
The projected row is normalized at the low end of Dennis's 40–50% band; if Dennis lands higher, the difference comes out of Manny's share. Manny grows with the SDD gauntlet (+10 pts) and auth/wallets/onboarding (+10 pts) — the same Stage A items, so the projection inherits Stage A risk.
The release candidate is the hard boundary: everything to its left is Ascend's own work; everything to its right verifies and remediates the candidate — it does not add features. Two calendar facts drive procurement: the Q4 2026 closed beta overlaps Leg 1, and top audit firms book out six to eight weeks[7] — so Ascend must reserve the Leg 3 audit slot around September, while Stage A is still running (conditional on Stage A effort estimates firming by end-August).
Five gaps stand between today's testnet and the release candidate — all Ascend-internal; none needs an external services firm (wallet infrastructure consumes third-party wallet providers as components, decided and integrated internally). Internal cost is the team's own effort and calendar time, estimated where known and marked pending where not. Rank one is the SDD gauntlet: it turns Leg 1 from open-ended vendor discovery into a defined, quotable engagement. It outranks CI/CD but depends on it in sequence — the diagram shows both.
Branch-based test environments, repeatable deploy pipeline, infrastructure as code; today all testing runs on developer machines (CI/CD · DevOps · IaC).
Runs before the gauntlet despite ranking below it.
Everything needed to accept real users.[2]
Endpoints first (API gateway); an SDK if partner demand warrants.
Written docs stop every external firm billing ramp-up time to learn the system.
Stage B is the verification program: three separate engagements, one per part of the outbound scope-of-work document, so every vendor quotes the same scope. The leg cards carry each engagement's full scope; the matrix beneath separates four often-conflated security terms.
A firm-run acceptance gauntlet — external testers execute the SDD gauntlet against the release candidate — layered with closed-beta playtesting by the planned Q4 beta group. Ascend's own effort (spec-pack upkeep, triage, the fix loop) stays internal; the external quote covers only the gauntlet.
Security professionals attack the running system — web app, API, infrastructure, operations (penetration testing).
Red teaming, defined: hired attackers simulate a real adversary against the whole operation, chaining technical, operational, and human weaknesses.
The audit reads the contract code line by line; the security review examines the design — threat model, access control, upgrade paths, economic and logic attack surfaces. None of the three legs substitutes for another. Contract code freezes for the audit window; fixes batch into the remediation re-review pass.
A separate line keeps vendor quotes comparable.
| Penetration testing | Red teaming | Smart-contract audit | Security review | |
|---|---|---|---|---|
| Who examines | Offensive-security testers | Hired adversaries | Specialist auditors | Senior reviewers |
| What they examine | The running system, attacked from outside — web app, APIs, infrastructure | The whole operation — technical, operational, human | Contract code, read line by line | The design, including economic and logic attack surfaces |
| The question it answers | "Can someone break in?" | "Can a determined adversary succeed end-to-end?" | "Is the code flawed?" | "Is the architecture flawed?" |
Price signals track crypto-native top-tier firms only — the calibre Ascend already works with. Illustrative figures are internal calibration, not quotes; the pipeline below replaces them with real numbers as they land. Leg 3's ~$200K ballpark[8] presumes mid-band researcher-week staffing; at OpenZeppelin or Trail of Bits list rates the same scope prices at or above the public band's $300K+ top — the equivalent-spend chart shows what the same dollars buy at each firm.
Scope: firm-run SDD-gauntlet execution only — the Ascend fix loop stays internal, per Stage B.
≈$25K–$150K at $5.3K–$13K/week benchmark rates
Scope: pen test + red teaming across web app, API, infrastructure, operations.
$10K–$30K[13] FLOOR — pen-test component only, generalist band
Crypto-native scope with wallet and onchain integrations prices above the floor; red teaming is quoted as a separate line above it.
Scope: line-by-line audit + design-level security review + one remediation re-review pass[1].
~$200K illustrative[8] on mid-band staffing, inside the $150K–$300K+ public band[6]
At OZ / Trail of Bits list rates the same scope prices at or above the band's $300K+ top[8].
Vendor scoping and delivery verification are covered today: the CPO runs both as interim owner. What a part-time interim owner cannot supply is full-time engineering execution — and that is the hire: a hands-on director of engineering (senior-staff level). The CEO (Dennis) currently carries the engineering build alongside fundraising, and the named Stage A gaps — CI/CD + IaC, the API gateway + SDK — are exactly the workload the hire absorbs. The hire frees the CPO to run product end-to-end (strategy, technical, marketing) rather than splitting into engineering execution, and gives Ascend an engineering skillset that meets external vendors apples-to-apples: rate-card fluency, scope pushback, billed weeks verified against delivered work. It is also the continuity role — one accountable engineering owner through hardening, audit remediation, and post-mainnet operations (incident response, upgrades) — a role institutional counterparties expect to exist. Spend shape matters as much as rate: the current contract bills monthly for as long as it runs; Stage B is a bounded package delivered in about a quarter.
$120K–$200K/yr[11]
Hands-on director of engineering — full-time, senior-staff level.
Every firm quotes against the same scope-of-work document — the one whose Parts I–III define the three legs — so quotes land apples-to-apples against the cost cards above.
| Firm | Legs quoted | Status |
|---|---|---|
| Holdex (Hong Kong) | Leg 1 | engaged — awaiting scope-of-work |
| Hashlock | Legs 2+3 | engaged — awaiting scope-of-work |
| Cantina / Spearbit | likely Legs 2+3 | no reply yet |
| OpenZeppelin | Parts I–III | receives the same scope-of-work |
| Nethermind | Parts I–III | receives the same scope-of-work |
Every figure on this page carries its provenance: a named document, a public benchmark with its URL, the repository record (commit history pulled July 28–29, 2026), a dated meeting record, "internal technical review, July 27 2026 — single source," or an owner-asserted anchor labeled as such.
A public rehearsal network that mirrors the live blockchain but uses valueless tokens, so the system runs end-to-end without real money at risk.
A feature-complete version of the product that could ship as-is; the last internal milestone before external verification begins.
The live blockchain where transactions move real money. Launching on mainnet means customer funds are genuinely at stake.
Automation that tests every code change and deploys it the same way every time, replacing manual builds and hand-run checks.
The discipline of running software reliably — deployments, environments, monitoring, recovery — treated as engineering, not ad-hoc admin work.
Infrastructure as Code: servers and environments defined in files, so an identical copy of the whole setup can be rebuilt on demand.
Ascend's spec-driven verification harness: written product specs turned into an executable battery of pass/fail checks any tester can run against the system.
The single controlled front door through which outside software reaches the system, handling access, authentication, and traffic limits in one place.
Software Development Kit: a ready-made code package that lets partners integrate in hours rather than building against raw APIs for weeks.
For end-user wallets: the user holds the keys to their own funds; no company — including Ascend — can move the money for them.
A wallet whose key is split into fragments held separately, so no single party — user, provider, or Ascend — can act alone.
A wallet built invisibly into the product itself: users sign up with email or passkeys, with no separate wallet app or seed phrase.
Pass/fail requirements written as plain-language scenarios ("given this situation, when the user does X, then Y happens") that anyone can read and verify.
The final check that the product does what was specified, run against agreed criteria before the work is accepted as done.
Real users exercising the product under realistic conditions to surface problems scripted testing misses — and, here, to generate early market signal.
Security professionals attempt to break into the running system — web app, APIs, infrastructure — and report every way in they find.
Hired attackers simulate a real adversary against the whole operation — systems, processes, people — to show how a genuine attack would unfold.
An independent line-by-line review of the blockchain contract code, hunting for flaws that could put customer funds at risk.
An expert examination of the system's design: who can do what, how upgrades work, where economic attacks could land.
Normalized source lines of code: the standard measure of codebase size audit firms use to scope and price an audit.
A firm's published price list, typically per engineer-week or researcher-week; the baseline before scoping and final pricing.
Links out: the SDD gauntlet explainer (in Stage A). Footnote URLs are citations only; all page assets are inline.