Skip to content

For owners of crypto casinos and payment operators

Even after a clean audit, one insider can still move your treasury.

Or one compromised laptop. SafeShield watches every config, access, key and limit change that can move money, and tells the owner through a channel the team can't mute.

  • Read-only integrations
  • Never holds keys or seed phrases
  • Owner sign-in your admins don't control

What SafeShield watches for

Examples
  • CustodyWithdrawal whitelist edited
  • CustodyTransaction policy widened
  • CloudNew cloud admin granted
  • Back-officePlayer balance adjusted by hand
  • IdentityTwo-factor reset for an admin
  • CodeWallet config changed in a repository

Each one reaches the owner with who made the change and what is at stake.

The problem

A clean audit doesn't watch what changes next

Audits and custody policies matter, but they describe your setup on the day they were done. The risk that remains is people with legitimate access, and the laptops they use.

  • An audit describes one moment

    Whitelists, signing policies, cloud roles and limits keep changing after the audit is signed off. Most changes are routine, which is exactly why a harmful one goes unnoticed.

  • One person can be enough

    An insider, or an attacker on one compromised laptop, uses access that already exists. The change goes through your normal tools, so nothing looks broken until money has moved.

  • Alerts reach the people being watched

    Security alerts usually go to the same team whose access is at risk, and an admin can mute them. The owner often finds out last, after the money has left.

How it works

Read-only eyes on every system that can move money

SafeShield connects to the five surfaces where your treasury can be changed. It reads metadata and audit events only: no write access, no keys, no secrets.

  • Custody

    Wallet policies, withdrawal whitelists, signers and approvals, plus your treasury addresses on chain.

    Sources: Custody platform, on-chain watcher

  • Cloud

    Admin roles, access keys, security settings and changes to the audit trail itself.

    Sources: Cloud audit trail

  • Back-office

    Manual balance adjustments, withdrawal approvals and changes to player limits.

    Sources: Back-office webhook

  • Identity

    New admins, role changes, two-factor resets and accounts of people who have left.

    Sources: Identity provider

  • Code

    Changes to payment, wallet and deployment configuration in your repositories.

    Sources: Code hosting

From event to owner alert

  1. Tripwires

    Rules for changes that should never happen quietly: a new whitelist address, a widened transaction policy, a new cloud admin. Each rule sets the severity of its alert.

  2. Baselines

    SafeShield learns how each person and service normally works, and flags what is new: an unfamiliar network, an unusual hour, a first-time action.

  3. Correlation

    Related events across surfaces become one story, such as a cloud admin grant followed by a whitelist edit. You see the path to money, not five separate alerts.

The owner is told

What changed, who did it, what is at stake and what to do next, through a channel your team can't mute: email, Telegram, Discord or SMS, whichever suits you. Severity always comes from the rules. An AI model only writes the explanation: it can never suppress an alert, lower its severity or close it.

Integrations

Works with the stack you already run

Read-only connections to the platforms behind your treasury, and alerts delivered wherever the owner already is.

  • Cloud

    Available

    • AWS

    Coming soon

    • Google Cloud
    • Microsoft Azure
  • Custody and wallets

    Available

    • Fireblocks
    • Privy
    • Safeheron

    Coming soon

    • BitGo
    • Copper
    • Fordefi
  • Identity

    Available

    • Google Workspace
  • Code

    Available

    • GitHub

Alerts on the channel that suits you

SafeShield delivers owner alerts on any channel you prefer, and your team can't mute it.

Channels

  • Email
  • Telegram
  • Discord
  • SMS

Owner Console

The decisions only the owner can make, in one place

What needs you now, who can move money, and a tamper-evident record of every decision. It works on a phone, because owners often decide from one.

Overview
Perimeter status at a glance: Calm, Needs attention or Critical.
Alerts
SafeShield's analysis, what is at stake and the timeline. Mark it expected, send it to an analyst or open an incident, always with a reason.
Money access
Every path from a person or service to money, including people who have left.
Audit log
Owner decisions, exceptions and alert deliveries in a hash-chained log you can verify.
Settings
Recipients, thresholds and exceptions. Only the owner creates exceptions, each with a reason.
The Overview screen, illustrated with demo data.

Security

How SafeShield protects itself

An overseer that can be switched off, bypassed or turned into a way in is worse than none. These are design rules, not settings.

  • Read-only by design

    Integrations never request write access. SafeShield cannot move funds, approve a withdrawal or change a setting in your systems.

  • No keys, no secrets

    It never reads or stores secret values, private keys or seed phrases. It works only with metadata and audit events.

  • Sign-in your admins don't control

    The owner signs in with a passkey and a hardware-key backup, not through your company's identity provider, so its admins can't sign in as you.

  • A log that can't be rewritten

    Owner decisions, exceptions and alert deliveries go into an append-only log. Each entry carries the hash of the one before it, so a changed or deleted entry breaks the chain.

Silence is a signal

If a source stops sending events, or SafeShield's access is revoked, the owner is alerted. Switching SafeShield off is itself an alert.

Pilot

Start with an 8-week pilot

See what SafeShield finds in your own perimeter before you commit to anything.

  1. Connect

    We set up read-only access to the systems you choose and map who can move money.

  2. Calibrate

    New rules start in shadow mode while SafeShield learns what normal looks like for your team.

  3. Watch

    Alerts reach the owner through the independent channel, with a report every week.

  4. Review

    Together we go through what was found, what was noise and whether to continue.

What we need from you

  • An owner, or someone the owner trusts, to receive alerts and decide on them.
  • Read-only access to the systems you want covered.
  • A technical contact to set up that access.
  • Your treasury addresses and the roles allowed to move money.
Request a pilot

FAQ

Questions owners ask

We passed a security audit. Why do we need this?

An audit checks your setup at one point in time. SafeShield watches what changes after it, every day: config, access, key and limit changes, and who made them.

Does SafeShield need write access to our systems?

No. Every integration is read-only. SafeShield never requests write scopes, so it cannot move funds, approve withdrawals or change your settings.

Will SafeShield see our private keys or seed phrases?

No. It never reads or stores secret values, private keys or seed phrases. It works with metadata and audit events, such as “the withdrawal whitelist changed, and who changed it”.

Who receives the alerts?

The owner, and anyone the owner adds as a recipient. Your team cannot mute the owner’s channel. Every owner decision needs a reason, goes into the audit log and is copied to the other recipients.

What if someone cuts SafeShield off?

Silence is a signal. If a source stops sending events, or SafeShield’s access is revoked, the owner is alerted.

Can SafeShield block a suspicious transfer?

Not today. SafeShield observes and alerts. Owner co-signing, veto and freeze controls are planned for a later phase.

Does an AI decide what is important?

No. Rules decide severity. An AI model writes the explanation and links related events, but it can never suppress an alert, lower its severity or close it.

Is SafeShield a compliance product?

No. It does not certify you or make you compliant with any regulation. It protects the owner from insider and account-takeover risk, and its tamper-evident record helps you show partners how access to money is watched.

Contact

Request a pilot

Online requests are not open yet.

The request form will ask for your name, company, role, email, an optional treasury size band and a short message. It sends your request straight to the SafeShield team, with no third-party form service and no tracking.