The team fills out a structured OpSec questionnaire — who has access to what, how keys move, which SaaS platforms are in use, and how a deployment reaches production. Most of it is answerable without a call.
OpSec
Operational security for teams, keys, releases, and response.
Keel Formal depends on the humans, infrastructure, and processes around the code. Keel Formal helps teams harden the operational paths adversaries actually target.
Reduce operational attack surface.
We assess how sensitive actions happen in practice: who can execute them, what can go wrong, and how the team would detect and contain compromise.
The review runs across every platform the company depends on rather than deep into a single one — the cloud consoles, the code host, the chat tools, the social accounts, the laptops. Most operational compromises do not start at the most guarded system. They start at the one nobody remembered was connected to it.
- Key management Multisig structure, signer hygiene, custody assumptions, transaction simulation, and access recovery.
- Access and permissions Who can do what across every system, whether SSO and 2FA are actually enforced, how joiners and leavers are handled, and which accounts still work after someone leaves.
- Secrets handling Where API keys, tokens, and private keys are stored and shared day to day, who and what can read them, and how often they are rotated in practice.
- Release process Deployments, upgrades, verification, environment separation, and change-control procedures.
- Infrastructure Admin panels, CI/CD, automation servers, RPC dependencies, monitoring systems, bots, and privileged backend services.
- Devices and developer hygiene Laptop and phone security for the people holding keys, disk encryption, updates, and what an attacker gets from one compromised workstation.
- Communications and social accounts Where sensitive decisions are discussed, and how the X, Discord, and Telegram accounts users trust are protected from takeover.
- Incident readiness Runbooks, escalation channels, emergency roles, and rehearsal of containment decisions.
How it works
Your answers are measured against Keel Formal's OpSec standard, built on the SEAL operational security framework and the Web3 OpSec Standard, so nothing is graded on instinct.
Anywhere the answers are ambiguous, contradictory, or point at real risk, a Keel Formal engineer digs in directly with the people who operate the system.
Typical scope
Personal security, signer workflows, social recovery, and approval discipline.
How contracts, configs, and upgrades move from branch to chain.
Pausing, communication, multisig coordination, and forensic preservation.