Skip to content

How CROC Operates

Inside the CROC watch floor

From the first packet of on-chain activity to a closed incident, every alert moves through the same disciplined, four-part process.

Step 1

Comprehensive Signal Generation

Chain Monitor fuses four independent signal layers into every alert, so nothing is missed and nothing is judged in isolation.

Blockchain Data
Rule-Based Detection

On-Chain Detection

Live transaction data is checked against security rules and client-specific operational policies in real time.

Risk Intelligence
Behavioral Analysis

Risk & Behavior Screening

Behavioral baselines and risk intelligence work together to flag both known threats and activity that simply doesn't fit the pattern.

Core Competency 01

24×7 Watch Operations

Security does not keep office hours and neither do we. The CROC watch floor runs on overlapping shift blocks so that handovers are covered, not gapped, and a trained Watch Officer owns every alert from the moment it lands.

Every hour manned

Minimum analyst floor maintained around the clock, seven days a week

Overlapping shifts

Morning, general, afternoon and night blocks overlap rather than abut with no handover blind spots

Named ownership

Each alert batch is owned end-to-end by a designated Watch Officer

Coverage blocks, 24-hour cycle

Morning06:00 – 15:00
General09:00 – 18:00
Afternoon14:00 – 23:00
Night22:00 – 07:00
00:0006:0012:0018:0024:00

Shift windows overlap by design, every handover happens with both teams on the floor.

Core Competency 02

Alert Triage & Classification

Raw alert feeds are noisy. Our analysts apply a disciplined, client-aligned severity framework to every alert to separate genuine threats from routine operational events and correct vendor mislabels so the client only acts on what matters.

Critical

When it applies

Anything new, unfamiliar, or unexplainable. Privileged actions such as role grants or configuration-flag changes. Unknown addresses and brand-impersonation events.

CROC Response

Immediate call + contextualized email at T0. Escalation timers armed.

High

When it applies

Known event types occurring outside the established daily pattern, or at unusual volume or timing.

CROC Response

Prioritized notification with analyst context; tracked to acknowledgement.

Informational

When it applies

Routine, expected operational activity, recognized wallets, standard issuance and transfer flows.

CROC Response

Logged, classified, and rolled into periodic reporting. No call required.

Threat Intelligence Map

On every investigation

Opening any alert surfaces a visual relationship graph of every connected entity, networks, smart contracts, transaction clusters, wallets, and related open alerts, as color-coded nodes, alongside runbook guidance, AI analysis, and transaction metadata: everything an analyst needs to complete an investigation from a single view.

Core Competency 03

Incident Management & Tiered Escalation

When an alert is real, speed and structure decide the outcome. CROC operates a tier-matched escalation chain where analysts, shift leads, and leadership engage their client-side counterparts level for level, with escalation timers that fire automatically if acknowledgement stalls.

T0: call and email fire simultaneously

Critical alerts trigger a verbal call in under one minute, in parallel with the contextualized email

T+10: automatic escalation

No acknowledgement within ten minutes escalates the incident up the chain without debate

Leadership reachable 24×7

Manager and director tiers are on-call around the clock, through to major incident bridge support

Tier-matched escalation chain

Tier 1

Shift Analyst / Watch Officer

First triage, notification & tracking

Tier 2

Shift Lead

Regional coordination & follow-up

Tier 3

Operations Manager

Incident command, reachable 24×7

Tier 4

Director

Executive engagement & major-incident bridge

Tamper-Proof Audit Trail

Every action is permanently recorded with user, timestamp, and IP address, and can never be edited or deleted, so investigation decisions stay traceable to a specific analyst, disposition changes are always logged with context, and compliance documentation writes itself.

Core Competency 04

SLA Governance & Transparent Reporting

Every alert is timestamped hop by hop from receipt, through notification, to client acknowledgement. We measure ourselves against hard SLA targets, publish the results, and flag every breach with a named owner and corrective action.

H1

Alert received

Watch Officer begins analysis & drafts context

H2

Notification sent

Contextualized email forwarded to client

H4

Verbal escalation

Direct call placed for critical alerts

H5

Acknowledged

Client acknowledgement closes the cycle

≤ 10 min

Lead Time (H1 → H2)

Owned entirely by CROC

≤ 15 min

Cycle Time (H1 → H5)

Co-owned with the client

Hop-level

Timeline evidence

Every incident reconstructed minute by minute

Built-in SLA targets by severity

< 15 min

S1 Critical

< 60 min

S2 High

< 240 min

S3 Low

Around-the-clock global coverage

Security operations around the world.

No matter where your team or your customers are, someone at CROC is already watching.

Talk to the CROC team