Know when your control surface changes.

A protocol’s risk isn’t fixed. Implementations get upgraded, roles get granted, admin keys rotate. Continuous Monitoring tracks the control surface over time and alerts you when something shifts, before it becomes an incident.

Continuous · Beta

A point-in-time audit ages the moment state changes.

An audit describes a protocol as it was. But upgrades ship, roles change, and authority drifts. Without continuous visibility, the first sign of a dangerous change is often the incident itself.

An implementation is upgraded and no one outside the team notices what changed.
A new admin role or key is granted, quietly expanding who can act.
Bytecode changes in a way that a source-level review would have flagged.
A timelock or guardian configuration is altered, shortening the window users have to react.
Authority drifts across many small changes that never get reviewed together.

What we monitor

We watch the surfaces that determine what a protocol can become, and alert the moment they move.

Implementation diffs
What actually changed between one implementation and the next, across upgrades.
Admin & role events
Grants, revocations, and ownership transfers as they happen on-chain.
Bytecode changes
Detection of deployed-code changes, including proxy implementation swaps.
Control-surface alerts
Notification the moment a governance, timelock, or admin configuration shifts.

How monitoring works

We establish a baseline from your control-plane state, then watch it continuously and alert on meaningful change.

01
Baseline
Capture the current control surface, implementations, roles, and configurations.
02
Watch
Track the relevant contracts and events continuously across supported chains.
03
Detect
Flag implementation diffs, role changes, bytecode changes, and configuration shifts.
04
Alert
Notify your team with context on what changed and why it matters.

What you get

Change alerts
Timely notification when a monitored control surface changes, with context.
Implementation diffs
A clear view of what changed between implementations across upgrades.
Event monitoring
Ongoing tracking of admin, role, and ownership events on your contracts.
Posture reporting
Visibility into how your control surface moves over time.

Continuous Monitoring is in beta and pairs naturally with a Governance Audit, the audit sets the baseline, monitoring keeps it current.

Why Themis

Anchored to your authority model
Monitoring is tied to the control surface a Governance Audit establishes, not a generic watchlist.
Change you can act on
Alerts come with context (what changed and why it matters), not just a raw event feed.
Assurance over time
The same lifecycle philosophy behind Continuous Agent Validation, applied to protocols.

Questions we get asked

Do we need an audit first?

Not strictly, but a Governance Audit sets a clean baseline and makes alerts far more meaningful. Many teams pair the two.

Which chains are supported?

The major EVM chains we cover for governance analysis (Ethereum, Arbitrum, Optimism, Base, and Polygon), with more on request.

How do alerts reach us?

We agree the channels during onboarding. Alerts include context on what changed and its risk implication.

This is marked beta, what does that mean?

The service is live and in active development. We onboard monitoring engagements directly so we can tailor coverage to your protocol.

Want to know the moment control shifts?

Tell us which contracts to watch. We’ll set a baseline and alert your team when the control surface changes.