BlockSentinel logoBlockSentinel

Security model

BlockSentinel is off-chain risk infrastructure. It watches public Ethereum lending activity and prepares advisory packages. It does not take authority over protocol contracts.

BlockSentinel is advisory by design: no custody, no autonomous execution, and no unilateral control over protocol contracts.

What BlockSentinel can and cannot do

Guard proposals can sound like control. This matrix is the contract with customers.

CapabilityBlockSentinel has it?
Read public chain dataYes
Send alertsYes
Generate proposal JSONYes
Draft Safe transaction packageOptional, proposal only
Hold protocol fundsNo
Sign protocol transactionsNo
Execute protocol changes unilaterallyNo
Override governance / multisigNo

Data access model

What we read

  • Public Ethereum event logs via read-only RPC
  • Configured protocol emitters and asset addresses
  • Alert destination config you provide (Slack/email)

What we do not take

  • Protocol admin keys or signer keys
  • Custody of funds
  • Write access to protocol contracts

Guard proposal safety model

  • Mode is propose-only. Execution is always the protocol’s.
  • Actions must be on an explicit per-protocol allowlist.
  • Cooldowns prevent repeated proposals for the same action.
  • Expirations keep stale recommendations from being signed later.
  • Optional two-phase confirmation before any Safe draft is used.

Infrastructure controls

  • AWS least-privilege IAM roles per function
  • Secrets in AWS Secrets Manager
  • Encryption in transit (HTTPS) and at rest
  • CloudWatch logging and operational alerts

Customer responsibilities

  • Confirm contract addresses, markets, and allowlisted actions.
  • Keep alert recipients current.
  • Review every proposal before signing.
  • Treat BlockSentinel as advisory infrastructure, not a control plane.

Responsible disclosure

Report security issues to support@blocksentinel.ai.

Independent monitoring infrastructure. Not affiliated with Aave, Compound, or any protocol unless explicitly stated.