Purchasing Guides / On-Chain Security Alert Triage

On-Chain Security Alert Triage

A guide to buying an AI workflow that explains on-chain security alerts and suggests which need urgent attention, with supporting evidence.

Yearly running cost

Assuming 7,200 alerts a year

By hand
$120K / year
1,200 hours of work
Hosted service
$14.4K+ / year
This workflow
$691 / year
Machine usage only; setup, hosting and review are extra.
What should the triage do?

Get a brief for each alert, or also page responders and open incident tickets.

Your responders decide and act. It never signs transactions, pauses contracts, moves funds or contacts outside parties.

What is included

Receive each alert, decode the transaction and contracts involved, check related addresses and past alerts, and post a brief with suggested urgency, value at risk and the matching runbook.

Start with your monitoring tool, the contracts and wallets you watch, your incident runbooks and past alerts, including real incidents and false alarms. The incident option groups related alerts, pages the on-call responder for urgent ones, opens an incident ticket and keeps a timeline.

How reliable should urgency and briefs be?

Set targets for catching urgent alerts, identifying false alarms and producing accurate briefs.

How these standards are measured

Replay past alerts, including real attacks, near misses and known false alarms, and seeded incidents on a test network. Measure urgent alerts caught separately from false alarms correctly marked low. A brief without the transaction hash, block and alert reference counts as a failure.

Targets for your selected standard
What is checkedTarget
Real incidents marked urgentReplayed real attacks and seeded incidents marked urgent, divided by all such alerts in the test set. A missed or failed brief counts as a miss.≥98%
False alarms marked lowKnown false alarms marked low urgency with a stated reason, divided by all known false alarms.≥70%
Brief facts correctAmounts, addresses, function names and balance changes in briefs that match chain data, divided by all such facts stated.≥98%
Right runbook linkedAlerts that link the runbook your team agrees applies, divided by all alerts with an applicable runbook.≥90%
Briefs with referencesEvery brief must give the transaction hash, block, chain and alert reference it is based on.≥100%

A brief is decision support, not a verdict. When the workflow is unsure it marks the alert for a responder; it never lowers urgency to stay quiet.

How quickly should a brief appear?

Choose how soon after an alert arrives the brief is posted. Detection by your monitoring tool and the responder decision are separate.

Timing details

Time from receiving the alert to the posted brief, including fetching and decoding the transaction, contract and address lookups, model calls, queueing and retries. Slow archive node responses count. Confirm alert volume, chains and node access with your provider.

The target applies to at least 95% of agreed test runs, with 4 in progress at a time.

How much do you want to spend per alert?

Set the AI processing budget for investigating each alert.

Cost details

Includes model calls, retries and a shared hosting allocation. Your monitoring tool, node or trace provider plans, block explorer keys, paging plans and responders’ time are separate. A repeated alert for the same transaction is another run unless grouped.

Reference machine cost: $0.15 – 0.20 per alert at 600 alerts a month. The selected cap is a target to test, not a replacement for this estimate.

Where do you want it to run?

Run it in your cloud or on your own server. Choose whether alert and transaction details may go to an approved AI service.

Data and access details

Runs in a cloud account you control, with access controls and logs.

Only the alert, decoded transaction, public contract code and runbook excerpt go to the selected external model. Agree access and retention first.

Give the workflow read access to alerts, your node or trace provider and your runbooks, and permission to post messages only. It never holds keys, signs transactions or triggers pauses. Private model only keeps alert details and runbooks on your hardware; the workflow still reads public chain data.

How do you want to use it?

Choose where you want to use it. You can select more than one.

Anything else your provider should know?

Optional. Your choices are included automatically.

Common questions

Does this replace our monitoring tool or automatic pause?

No. Your monitoring tool still detects threats and any pre-approved automatic response stays where it is. This workflow explains each alert to the responder who decides what happens next.

Will it act on an alert by itself?

No. It posts briefs and, in the incident option, pages and opens tickets. It never signs, pauses or moves funds.

What happens if it is unsure?

It marks the alert for a responder and says what it could not confirm. It is tested so that real incidents are not marked low to reduce noise.

Can I run it without sending alert details to an external AI service?

Yes. Choose a private model and supply your own hardware. Measure brief quality, speed and running cost during the pilot.

Download RenX

Get the app.

Install, sign up, and start on your free plan with welcome credit included. No credit card required.

On a platform not listed? Leave your email and we'll notify you when a build is available.