Turn security tooling into an operating system.

In 14 days, we map critical assets, verify alert routes, write three protocol-specific runbooks, test one scenario, and deliver a decision-ready evidence package.

Sprint delivery planFixed scope
Assets, owners, dependenciesRegistry
Coverage and routing reviewMatrix
Three response runbooksVersioned
Tabletop or alert testEvidence
Report and executive readoutDecision

Who this is for

The sprint is designed for live or near-live protocol teams that already use monitoring, Safe, engineering alerts, or security partners but do not have a dedicated operational readiness function.

  • Approximately $10 million to $500 million in TVL or comparable value at risk
  • A recent mainnet launch, upgrade, migration, audit, or new-chain deployment
  • Multiple contracts, chains, dependencies, owners, or emergency authorities
  • A named technical owner and decision-maker who can participate during the sprint

What you own on day 14

Critical asset registry

Contracts, wallets, Safes, chains, dependencies, criticality, operational owners, explorer links, and documented emergency capabilities.

Monitoring coverage matrix

A visible mapping of risk scenarios to monitoring sources, routing paths, named owners, and known gaps. The matrix distinguishes configured coverage from assumptions.

Three response runbooks

Versioned, protocol-specific operating procedures with facts to verify, decision authority, escalation steps, communications, evidence requirements, and test history.

One facilitated exercise

A tabletop or alert-routing test that records what worked, what failed, who participated, and which remediation items remain open.

Readiness report and portal

A baseline-to-final summary, evidence index, unresolved risks, and a prioritized 30-day backlog delivered through the Onchain On-Call workspace.

How the sprint runs

PhaseOur workYour participation
IntakeSecure scope, tool, asset, and ownership reviewOne technical owner and one decision owner
ImplementationRegistry, coverage matrix, routes, runbooks, portalValidate facts and grant required access
TestingFacilitate one bounded scenario and capture evidenceParticipate with the actual escalation group
CloseoutRemediation, report, executive readoutChoose close, self-manage, or continue

Pricing

Founding-client rate: $3,500 paid upfront for the first two qualified engagements. Standard rate: $6,500. Multi-chain or multi-entity scopes are quoted after intake.

Managed Readiness Operations begins at $4,500 per month and is available only after the sprint establishes the assets, coverage window, responsibilities, and recurring delivery requirements.

Boundaries that protect both teams

This is not a smart-contract audit or emergency recovery service.

We do not request private keys, custody assets, sign transactions, unilaterally pause protocols, guarantee detection, or imply 24/7 coverage unless a later signed scope explicitly establishes qualified coverage.

Existing audit, monitoring, legal, insurance, emergency-response, and law-enforcement relationships remain in place. Our job is to make the operating layer around those resources explicit, testable, and auditable.

What happens after the sprint

You can take the artifacts and operate them internally, schedule a later retest, or move into Managed Readiness Operations. Continuing is a decision, not an automatic subscription.

Make the next alert easier to own.

Start with a fixed-scope readiness sprint. Keep the tools you already trust.