·
3 min read
Brand protection takedown SLAs explained, with our own published response times
What a brand protection SLA can and can't promise, why vendor numbers rarely compare, and ChainPatrol's own published response times by stage.

ChainPatrol
A brand protection vendor can honestly commit to the parts of a takedown it controls: how fast it detects, blocks and files. It can't honestly guarantee how fast a platform, host or registrar acts, because those are outside its control. The useful question isn't "what's your takedown SLA?" but "what's your time to file, and how do you report the cases that stay live?" Below are our own published response times, by stage.
Here's how to read vendor SLAs, why their numbers rarely compare, and what we commit to.
Four clocks, not one
Clock | Starts | Stops | Who controls it |
|---|---|---|---|
Time to detect | The fake appears | The vendor finds it | The vendor |
Time to block | The site is confirmed as phishing | Wallets and browsers show a warning | The vendor and its blocklist partners |
Time to file | Detection, or your approval | The report is submitted | The vendor |
Time to takedown | The report is submitted | The platform, host or registrar acts | The platform, host or registrar |
When a vendor quotes a single takedown time, ask which clock it measures, what kinds of cases it covers, and whether it's a median or a best case. Vendors measure different clocks on different case mixes, so headline numbers rarely compare.
Our published response times
Stage | ChainPatrol | Notes |
|---|---|---|
Wallet warning | About 5–10 minutes | Confirmed phishing and drainer sites; 20+ wallets |
Browser blocking | About 1–3 hours | Confirmed phishing and drainer sites |
We report every case's status monthly, including the ones still live and why, so you never have to rely on an average. See a sample monthly report.
What a fair SLA looks like
Commitments on the clocks the vendor controls: detect, block and file.
Medians reported per platform, with the period and case counts.
A monthly list of cases still live, with the reason for each.
A follow-up commitment: how often stalled cases are re-filed or escalated.
Red flags
A guaranteed takedown time across all platforms.
A takedown percentage with no definition of what counts as a case.
Reports that count what was found and removed, but never what's still live.
Frequently asked questions
Can any vendor guarantee a takedown time?
Not honestly. Platforms, hosts and registrars decide when to act. A vendor can guarantee how fast it detects, blocks and files.
Why do vendors' takedown numbers differ so much?
They measure different clocks, on different kinds of cases, sometimes as medians and sometimes as best cases.
What should we ask for in a contract?
Commitments on time to block and time to file, monthly reporting of open cases with reasons, and a defined follow-up cadence.
See our reporting on your own brand: book a demo, or start with a free scan.
Fakes of your brand already out there?
ChainPatrol finds them, blocks the links in wallets and browsers, and files the takedowns for you.
More from The Impersonation Institute
What a letter of authorization is, and why takedowns wait for it
A letter of authorization lets a vendor file takedowns for you. What goes in one, why platforms ask for it, and how to keep it from slowing you down.

Nikita Varabei
Takedown timelines
Blocking vs takedown: what each one actually stops
Blocking warns people off a scam site in minutes to hours. A takedown removes it at the source in days to weeks. What each stops, and why you need both.

Nikita Varabei
Takedown timelines
Why some phishing takedowns take weeks
Most phishing takedowns finish in days. Slow ones sit with unresponsive hosts and registrars or behind proxies. Why it happens and what to do meanwhile.

Nikita Varabei
Takedown timelines



