Yearly running cost Assuming 7,200 alerts a year
By hand $120K / year 1,200 hours of work
Hosted service $14.4K+ / year
This workflow $691 / year Machine usage only; setup, hosting and review are extra. What should the triage do? Get a brief for each alert, or also page responders and open incident tickets.
Explain each alert Get evidence, suggested urgency and a response runbook. $1,080 – 3,120 setup Add paging and incident tickets Also page responders and group related alerts. $1,656 – 4,920 setup
Which monitoring tool sends your alerts?Hypernative Blockaid BlockSec Phalcon OpenZeppelin Monitor Tenderly Other Your responders decide and act. It never signs transactions, pauses contracts, moves funds or contacts outside parties.
What is included Receive each alert, decode the transaction and contracts involved, check related addresses and past alerts, and post a brief with suggested urgency, value at risk and the matching runbook.
Start with your monitoring tool, the contracts and wallets you watch, your incident runbooks and past alerts, including real incidents and false alarms. The incident option groups related alerts, pages the on-call responder for urgent ones, opens an incident ticket and keeps a timeline.
How reliable should urgency and briefs be? Set targets for catching urgent alerts, identifying false alarms and producing accurate briefs.
Standard Urgent alerts caught, false alarms explained, uncertain alerts sent to a responder. Real incidents marked urgent: ≥98% False alarms marked low: ≥70% Included Strict A second check on urgency and facts, and more replays of past incidents. Real incidents marked urgent: ≥100% False alarms marked low: ≥80% Setup +$288 – 840 My own targets Agree your own acceptance requirements with the provider. Quote separately
How these standards are measured Replay past alerts, including real attacks, near misses and known false alarms, and seeded incidents on a test network. Measure urgent alerts caught separately from false alarms correctly marked low. A brief without the transaction hash, block and alert reference counts as a failure.
Targets for your selected standard What is checked Target Real incidents marked urgentReplayed real attacks and seeded incidents marked urgent, divided by all such alerts in the test set. A missed or failed brief counts as a miss. ≥98% False alarms marked lowKnown false alarms marked low urgency with a stated reason, divided by all known false alarms. ≥70% Brief facts correctAmounts, addresses, function names and balance changes in briefs that match chain data, divided by all such facts stated. ≥98% Right runbook linkedAlerts that link the runbook your team agrees applies, divided by all alerts with an applicable runbook. ≥90% Briefs with referencesEvery brief must give the transaction hash, block, chain and alert reference it is based on. ≥100%
A brief is decision support, not a verdict. When the workflow is unsure it marks the alert for a responder; it never lowers urgency to stay quiet.
How quickly should a brief appear? Choose how soon after an alert arrives the brief is posted. Detection by your monitoring tool and the responder decision are separate.
Within 2 minutes Included Within 60 seconds Setup +$144 – 480 Within 30 seconds Setup +$288 – 840
Timing details Time from receiving the alert to the posted brief, including fetching and decoding the transaction, contract and address lookups, model calls, queueing and retries. Slow archive node responses count. Confirm alert volume, chains and node access with your provider.
The target applies to at least 95% of agreed test runs, with 4 in progress at a time.
How much do you want to spend per alert? Set the AI processing budget for investigating each alert.
Up to $0.30 Included Up to $0.20 Setup +$72 – 360 Up to $0.12 Setup +$216 – 600
Cost details Includes model calls, retries and a shared hosting allocation. Your monitoring tool, node or trace provider plans, block explorer keys, paging plans and responders’ time are separate. A repeated alert for the same transaction is another run unless grouped.
Reference machine cost: $0.15 – 0.20 per alert at 600 alerts a month. The selected cap is a target to test, not a replacement for this estimate.
Where do you want it to run? Run it in your cloud or on your own server. Choose whether alert and transaction details may go to an approved AI service.
Run it onYour cloud Local environment AI model accessApproved model API Private model only
Data and access details Runs in a cloud account you control, with access controls and logs.
Only the alert, decoded transaction, public contract code and runbook excerpt go to the selected external model. Agree access and retention first.
Give the workflow read access to alerts, your node or trace provider and your runbooks, and permission to post messages only. It never holds keys, signs transactions or triggers pauses. Private model only keeps alert details and runbooks on your hardware; the workflow still reads public chain data.
How do you want to use it? Choose where you want to use it. You can select more than one.
Briefs in my alert channel Each brief appears in the Slack, Telegram or Discord channel where your team already receives alerts. Included My existing AI agent Let your security agent pull the brief, the decoded transaction and the runbook for any alert. Setup +$72 – 240 An alert review page See past alerts, the urgency each received, what responders decided and which detection rules are noisy. Setup +$144 – 480