Skip to content
Architecture6 min read

Read and attest: capping the blast radius of your own vendor

The question nobody asks their monitoring vendor: what happens on the day the vendor is the one that gets breached?

Every monitoring vendor asks you to trust it with visibility. Few will say what happens when the vendor itself is compromised, and a security supplier is a concentration of exactly the access an attacker wants.

The invariant

Fuga Labs is read and attest, never custody and execute. It never holds customer keys, funds, admin roles or unilateral authority. Not in Exposure Map breakers, which are protocol-owned modules. Not in AI Agent Guardrails, which never takes custody of agent funds. Not in Live Detection, whose response contracts execute only through a guardian module the customer deploys.

Why it is architectural rather than aspirational

A policy saying we will not misuse access is worth what a policy is worth on the day of the breach. An architecture that never holds the access is worth the same that day as any other.

If Fuga Labs were fully compromised tomorrow, the attacker would inherit observation and the ability to publish signed attestations that expire. They would not inherit the ability to move anything you own. Your guardian module would still be yours, still revocable by you, and still free to ignore an attestation it does not like.

What that buys you at the negotiating table

A vendor risk assessment that ends in a bounded answer rather than a trust exercise. The blast radius of a total compromise is a defined, small set, and it is small because of the architecture rather than our intentions.

The next breach is already being dug.

Every engagement is scoped to your protocol by the team, and pricing follows that scope.