Incident Management

Mitigate critical incidents
across production systems

Detect issues across protocols and chains, validate every response action against live state, and trace any incident back to its source with full system observability.

War room · 5 online
last drill · 4h ago
Live alerts
⚠ Health factor 0.96 on Aave market 0xAa…
⚠ Oracle deviation +2.1% on ETH/USD
✓ Auto-pause armed on USDC market
⚠ Withdrawal queue depth > 80%
Drill in progress
Multisig pause · Aave USDC3 of 5 signers · simulated
Plan loaded
Signers ready
Simulating pause()
Outcome verified
Armed
responders: alice · jamie · sam · noah · priarmed
The value

Detect, inspect, and resolve incidents with confidence

When onchain incidents occur, the time-to-reaction determines the outcome. Catch early signs of production failures across protocols and mitigate damage with verified responses before it cascades across pools, markets, and chains.

Reduce response times to critical issues

Move from early signals of critical failures or potential exploits to mitigation in minutes with the full detection-to-response pipeline already in place before any incident occurs.

Validate responses before execution

Test asset recovery, protocol pauses, parameter changes, and governance actions against live production conditions to preview the expected outcomes before taking action.

Act from a single operational layer

Close the full incident response lifecycle so your teams can investigate issues, validate responses, and conduct post-incident reviews from a single operational layer.

The lifecycle · operating now
continuous loop
01
🛡
Prevent
Recovery playbooks validated end-to-end against production-synced state.
02
Detect
Real-time alerts on invariants, balances, oracle deviations, governance.
03
Respond
Every action simulated before execution — outcome verified before signing.
04
Review
Shareable audit trail across teams · post-incident, audit, regulators.
The lifecycle

Close the entire incident management loop

Cover proactive and reactive security and incident response measures from the same operational platform.

Emergency procedure testing

Validate asset recovery and monitoring procedures

Set up validated asset recovery measures by testing them end-to-end before any incident occurs. Configure custom adverse states, run asset recovery scripts and multisig actions, and ensure the effectiveness of the entire incident management system in safe, production-synced virtual environments.

See Simulator →
Real-time monitoring & responses

Catch early signals of unexpected system behavior

Identify early signs of potential issues in production by monitoring critical blockchain events in real time. Define alerting rules that matter to your system and detect protocol invariant breaks, balance thresholds, or suspicious address interactions. Trigger automated and previously verified responses to notify relevant stakeholders and mitigate damage across chains.

See Monitor →
Investigation & debugging

Identify and troubleshoot the root cause in minutes

Cut the investigation and troubleshooting time by identifying the exact reason behind production issues. Step through the entire execution flow, analyze state changes and emitted events, and quickly replay production failures with complete, fully decoded context. Isolate the exact issue within minutes, with full observability across your systems.

See Console →
Governance & timelocked actions

Evaluate time-dependent proposals before they execute

Catch unwanted effects of governance proposals by testing entire multi-day voting and timelock workflows in seconds. Advance time inside a virtual environment to evaluate how a proposal will behave when it executes, model first-order liquidations, and identify address exposure.

See Financial Modelling →
Cross-team visibility

Demonstrate actions to non-technical stakeholders

Build trust and confidence with risk, treasury, compliance, and leadership stakeholders by showcasing emergency procedures and expected outcomes. Show human-readable fund flows, position changes, and transaction outcomes, with every step of the response documented and shareable for post-incident reviews, audit, and regulatory reporting.

See Sandbox environments →
Capabilities

Set up the emergency response system end-to-end

Alerting

Real-time alerting across systems

Configure real-time alerting triggers for contracts, balances, invariants, governance state, and external dependencies.

Environment

Production-synced replicas across chains

Test response procedures against the live conditions of every chain you operate on, with full state and external dependency synchronization.

Simulations

Virtual environments for multi-step responses

Verify the compounding effect of complex recovery procedures, parameter changes, and governance actions before production.

Automation

Automated custom responses

Trigger fully customizable onchain actions and downstream workflows the moment specified conditions are met.

Debugging

Decoded transaction tracing & debugging

Step through asset transfers, opcodes, and gas usage breakdowns with decoded insights for unverified and verified contracts.

Integrations

Integrations with your existing stack

Route alerts to Slack, Telegram, Discord, PagerDuty, email, or custom webhooks to initiate emergency responses.

Teams

Respond with operational rigor across teams

Engineering, risk, security, and operations teams across different operating environments use Tenderly to detect, validate, and contain incidents across protocols and chains.

DeFi

Catch invariant breaks, exploit attempts, and fund movements across markets and chains. Validate protocol pause actions, parameter changes, and emergency multisig responses on a production-synced replica. Act fast during active incidents to contain damage before it affects user positions.

Explore DeFi solutions →
Financial Institutions

Minimize and mitigate production risks by implementing verified incident management procedures in line with the operational standards you need. Monitor blockchain activity across your production systems to maintain performance and reliability. Document detection, response, and resolution decisions with a complete audit trail for regulators, leadership, and auditors.

Explore institutional solutions →
Networks

Reduce the risk of production failures on your chain by integrating critical incident management solutions. Enable strategic partners, key protocols, and internal teams to set up and validate proactive security measures before mainnet launch.

Explore network solutions →
Testimonials

DeFi teams run incident responses on Tenderly

"

Tenderly Alerts have become an indispensable part of our monitoring infrastructure. We receive instant notifications and respond proactively to any unusual activity. Tenderly helps us maintain our high security and reliability standards while scaling our protocol operations.

"
Matt Collum
CTO, Maple Finance
"

Virtual TestNets are critical when doing the drills and setting everything up in a consistent, repeatable, and easy way. The purpose of these drills is collaboration, so Virtual TestNets are a key component of our EVM-based drills.

"
Isaac Patka
SEAL Wargames Lead
"

Using Virtual TestNets, we can configure the state based on custom conditions and share it with protocols, L1s, and other teams. This way, we can show exactly what would happen if something went wrong, and the prevention or automated response mechanism.

"
Harrison O
Lead Engineer, zeroShadow