How CROC Operates
Inside the CROC watch floor
From the first packet of on-chain activity to a closed incident, every alert moves through the same disciplined, four-part process.
Step 1
Comprehensive Signal Generation
Chain Monitor fuses four independent signal layers into every alert, so nothing is missed and nothing is judged in isolation.
On-Chain Detection
Live transaction data is checked against security rules and client-specific operational policies in real time.
Risk & Behavior Screening
Behavioral baselines and risk intelligence work together to flag both known threats and activity that simply doesn't fit the pattern.
Core Competency 01
24×7 Watch Operations
Security does not keep office hours and neither do we. The CROC watch floor runs on overlapping shift blocks so that handovers are covered, not gapped, and a trained Watch Officer owns every alert from the moment it lands.
Every hour manned
Minimum analyst floor maintained around the clock, seven days a week
Overlapping shifts
Morning, general, afternoon and night blocks overlap rather than abut with no handover blind spots
Named ownership
Each alert batch is owned end-to-end by a designated Watch Officer
Coverage blocks, 24-hour cycle
Shift windows overlap by design, every handover happens with both teams on the floor.
Core Competency 02
Alert Triage & Classification
Raw alert feeds are noisy. Our analysts apply a disciplined, client-aligned severity framework to every alert to separate genuine threats from routine operational events and correct vendor mislabels so the client only acts on what matters.
Critical
When it applies
Anything new, unfamiliar, or unexplainable. Privileged actions such as role grants or configuration-flag changes. Unknown addresses and brand-impersonation events.
CROC Response
Immediate call + contextualized email at T0. Escalation timers armed.
High
When it applies
Known event types occurring outside the established daily pattern, or at unusual volume or timing.
CROC Response
Prioritized notification with analyst context; tracked to acknowledgement.
Informational
When it applies
Routine, expected operational activity, recognized wallets, standard issuance and transfer flows.
CROC Response
Logged, classified, and rolled into periodic reporting. No call required.
Threat Intelligence Map
On every investigation
Opening any alert surfaces a visual relationship graph of every connected entity, networks, smart contracts, transaction clusters, wallets, and related open alerts, as color-coded nodes, alongside runbook guidance, AI analysis, and transaction metadata: everything an analyst needs to complete an investigation from a single view.
Core Competency 03
Incident Management & Tiered Escalation
When an alert is real, speed and structure decide the outcome. CROC operates a tier-matched escalation chain where analysts, shift leads, and leadership engage their client-side counterparts level for level, with escalation timers that fire automatically if acknowledgement stalls.
T0: call and email fire simultaneously
Critical alerts trigger a verbal call in under one minute, in parallel with the contextualized email
T+10: automatic escalation
No acknowledgement within ten minutes escalates the incident up the chain without debate
Leadership reachable 24×7
Manager and director tiers are on-call around the clock, through to major incident bridge support
Tier-matched escalation chain
Tier 1
Shift Analyst / Watch Officer
First triage, notification & tracking
Tier 2
Shift Lead
Regional coordination & follow-up
Tier 3
Operations Manager
Incident command, reachable 24×7
Tier 4
Director
Executive engagement & major-incident bridge
Tamper-Proof Audit Trail
Every action is permanently recorded with user, timestamp, and IP address, and can never be edited or deleted, so investigation decisions stay traceable to a specific analyst, disposition changes are always logged with context, and compliance documentation writes itself.
Core Competency 04
SLA Governance & Transparent Reporting
Every alert is timestamped hop by hop from receipt, through notification, to client acknowledgement. We measure ourselves against hard SLA targets, publish the results, and flag every breach with a named owner and corrective action.
H1
Alert received
Watch Officer begins analysis & drafts context
H2
Notification sent
Contextualized email forwarded to client
H4
Verbal escalation
Direct call placed for critical alerts
H5
Acknowledged
Client acknowledgement closes the cycle
≤ 10 min
Lead Time (H1 → H2)
Owned entirely by CROC
≤ 15 min
Cycle Time (H1 → H5)
Co-owned with the client
Hop-level
Timeline evidence
Every incident reconstructed minute by minute
Built-in SLA targets by severity
< 15 min
S1 Critical
< 60 min
S2 High
< 240 min
S3 Low
Security operations
around the world.
No matter where your team or your customers are, someone at CROC is already watching.
Talk to the CROC team