Operational Security

Security beyond the smart contract

300+ audits · $70B in assets protected · Founding collaborator of Security Alliance (SEAL)

The code is only half the attack surface. Dedaub extends its audit-grade expertise beyond smart contracts to your keys, treasury, and operational workflows.

Operational Security
Six Domains

Web3 operational security

From signing keys and treasuries to pipelines, domains, and people: six assessment domains, each tying an operational weakness back to exactly what it can do to funds onchain.

Multisig Ops

Governance and signer review backed by onchain proof of impact. We assess your M-of-N design, signer hygiene, key rotation, and recovery, then map every privileged role to the funds it can actually move.

What we assess

  • Governance and inventory: a named multisig operations owner, plus a complete registry of every multisig with its address, network, threshold, signers, controlled contracts, and onchain roles.
  • Risk and classification: risk-tiered controls per multisig, contract-level limits that cap the impact of a compromise, a tracked exception process, and wallet segregation.
  • Signer security: signer address verification, key management and seed phrase backup standards, signer onboarding and offboarding, security training, hardware wallet standards, secure signing environments, and signer diversity across roles, entities, and geographies.
  • Operational procedures: a documented propose, verify, execute transaction process, full audit trails, vetting of signing tools and platforms, and backup signing infrastructure.
  • Communication: secure communication procedures with identity verification, and a current emergency contact list.
  • Emergency operations: step-by-step playbooks, round-the-clock signer reachability and quorum, monitoring and alerts on every multisig, and regular emergency drills.

Treasury Ops

Custody, policy, and onchain control verification for protocol and DAO treasuries. We confirm the limits, signers, and delays you documented are the controls that actually execute onchain.

What we assess

  • Governance and architecture: a named treasury operations owner, a complete registry of treasury wallets and accounts, documented custody architecture rationale, and change management for treasury infrastructure.
  • Risk and fund allocation: risk classification of every wallet, portfolio concentration limits and rebalancing triggers, and per-actor and per-path exposure limits.
  • Access control and platform security: custody platform security configuration, credential and secret management, periodic access reviews, personnel operational security, and tightly controlled privileged access.
  • Transaction security: a defined verification and execution process, signer and approver security knowledge, and secure communication with identity verification.
  • Protocol deployments: evaluation and exposure limits before treasury funds enter external protocols, and position lifecycle management.
  • Monitoring and incident response: treasury monitoring for anomalous activity and a tested incident response plan.
  • Vendors and infrastructure: security management of third-party services and backup access to treasury operations.
  • Accounting and reporting: financial recordkeeping, periodic reconciliation, and appropriate insurance coverage.

Incident Response

Detection, escalation, and emergency execution for the moments that decide outcomes. We assess whether your monitoring, playbooks, and signers can actually contain an incident at any hour, before losses compound onchain.

What we assess

  • Governance and team: an incident response team with clearly defined roles, and current contacts and coordination procedures for every party needed during an incident.
  • Monitoring, detection, and alerting: a threat model covering protocol operations and external dependencies, monitoring coverage of critical systems and attack surfaces, alerting and paging that reliably reaches available responders, and tamper-evident logs with adequate retention.
  • Response and emergency operations: playbooks for common incident types, signer reachability for emergency onchain actions at any hour, and backup signing infrastructure with pre-prepared emergency transactions.
  • Communication and coordination: secure dedicated incident channels, internal status updates, and public communication procedures.
  • Testing and improvement: regular incident response drills with evaluated results.

DevOps & Infrastructure

Pipelines, source code, and cloud: the offchain systems attackers use to reach onchain funds. We assess your repositories, secrets, delivery pipelines, and infrastructure the way an attacker maps them.

What we assess

  • Governance and development environment: a named security owner for development and infrastructure, documented security policies, isolation of development from production, and an approved tools process.
  • Source code and supply chain: repository security controls, secret scanning, enhanced review for external contributions, and dependency management against supply chain attacks.
  • Pipeline security: control over who can modify and execute deployment pipelines, secrets management for pipelines and applications, and security testing integrated into continuous integration and deployment (CI/CD).
  • Infrastructure and cloud: infrastructure as code with version control and review, least-privilege access controls, tested backup and disaster recovery, and cloud security monitoring.

DNS & Registrar

Domain, DNS, and certificate integrity monitoring for the layer audits never touch. We verify your registrar hardening and DNS monitoring are configured to catch a record or certificate change the instant it happens.

What we assess

  • Governance and domain management: a named domain security owner and a complete inventory of all domains and their configurations.
  • Risk and classification: risk-tiered domains, with enterprise-grade registrar requirements for the critical ones.
  • Access control and authentication: locked-down registrar and DNS management access, an independent domain security contact email, and change management for critical domain operations.
  • Technical controls: DNS security standards, email authentication standards with violation monitoring, domain locks against unauthorized transfers, and full TLS certificate lifecycle management.
  • Monitoring and detection: monitoring for unauthorized DNS and registration changes, Certificate Transparency log monitoring, and active domain expiration prevention.
  • Incident response: alerting and emergency contacts, plus a response plan for domain hijacking and DNS compromise.

Identity & Accounts

Account ownership, credentials and access lifecycle: the accounts an attacker reaches before ever touching a key. We assess how organizational accounts are protected, reviewed and revoked, how takeover is detected, and what each account can actually reach.

What we assess

  • Governance and inventory: a named account security owner and an inventory of organizational accounts with defined ownership.
  • Authentication and credentials: phishing-resistant multi-factor authentication (MFA) on organizational accounts, credential standards with individual accountability, and account recovery restricted to organizational channels.
  • Access and lifecycle: full account lifecycle management from provisioning through offboarding, with periodic access reviews.
  • Monitoring and third parties: monitoring for account takeover and credential exposure, and time-limited, purpose-specific third-party access.

Aligned with the SEAL Certifications framework

Our six assessment domains map one-to-one to the SEAL Certifications framework, the open-source operational security standard for crypto organizations published by the Security Alliance (SEAL). Every item we assess follows the framework's published control criteria, from multisig governance to account takeover monitoring. Dedaub is a founding collaborator of Security Alliance (SEAL).

Explore the framework

Why Dedaub?

Dedaub is a leading blockchain security technology and auditing firm that combines deep security research, academic rigor, and practical hacker expertise. The operations around your contracts now get the same treatment as the contracts themselves.

$3M

Bug Bounties Across
11 Critical Claims

$Billions

TVL Secured Via
White-Hat Hacking

300+

Security Audits
Protecting $70B in Assets

Trusted

Trusted

Relied on by security teams at leading DeFi protocols and Web3 organizations worldwide.

Expertise

Expertise

Years of smart contract and protocol security expertise, plus the Security Suite and Decompiler tooling, now applied to operational risk.

Knowledge

Knowledge

Threat intelligence and security insight from researchers who have been in the live war rooms behind the industry's biggest incidents.

Chainlink Build Program Partnership
Arbitrum DAO Security Advisor
Oasis Protocol Sapphire's Security Partner
Founding Collaborator of Security Alliance (SEAL)
Uniswap Foundation Security Provider
Member of zkSync Security Council

Secure what your audit cannot reach.

Your code is reviewed. Now harden the keys, treasury, infrastructure, and people around it.

Request an OpSec Assessment