Security model
BlockSentinel is off-chain risk infrastructure. It watches public Ethereum lending activity and prepares advisory packages. It does not take authority over protocol contracts.
BlockSentinel is advisory by design: no custody, no autonomous execution, and no unilateral control over protocol contracts.
What BlockSentinel can and cannot do
Guard proposals can sound like control. This matrix is the contract with customers.
| Capability | BlockSentinel has it? |
|---|---|
| Read public chain data | Yes |
| Send alerts | Yes |
| Generate proposal JSON | Yes |
| Draft Safe transaction package | Optional, proposal only |
| Hold protocol funds | No |
| Sign protocol transactions | No |
| Execute protocol changes unilaterally | No |
| Override governance / multisig | No |
Data access model
What we read
- Public Ethereum event logs via read-only RPC
- Configured protocol emitters and asset addresses
- Alert destination config you provide (Slack/email)
What we do not take
- Protocol admin keys or signer keys
- Custody of funds
- Write access to protocol contracts
Guard proposal safety model
- Mode is propose-only. Execution is always the protocol’s.
- Actions must be on an explicit per-protocol allowlist.
- Cooldowns prevent repeated proposals for the same action.
- Expirations keep stale recommendations from being signed later.
- Optional two-phase confirmation before any Safe draft is used.
Infrastructure controls
- AWS least-privilege IAM roles per function
- Secrets in AWS Secrets Manager
- Encryption in transit (HTTPS) and at rest
- CloudWatch logging and operational alerts
Customer responsibilities
- Confirm contract addresses, markets, and allowlisted actions.
- Keep alert recipients current.
- Review every proposal before signing.
- Treat BlockSentinel as advisory infrastructure, not a control plane.
Responsible disclosure
Report security issues to support@blocksentinel.ai.
Independent monitoring infrastructure. Not affiliated with Aave, Compound, or any protocol unless explicitly stated.