Back to Membership
Digital Shield · $399/mo

You have 312 passwords.
Most are reused. Some are
already on the dark web.

One breach away from a financial account. Sentinel Digital Shield is the foundation tier — a complete individual security overhaul, deployed properly and maintained permanently. For the solo exec, the founder, the physician who knows their exposure is real and doesn't want to think about it again.

02

Who this tier is built for

Digital Shield is for individuals with serious financial exposure and a small or no household footprint. Not for families — that's Family Guard. Not for those with estate complexity — that's Estate Protection. This tier is for one person who needs the foundation built correctly.

The typical Digital Shield client

Solo founder or CEO — runs a company, has a wire transfer authority, travels internationally, and has never audited the 400 passwords in their browser.

Private equity or hedge fund professional — access to sensitive deal data, trading accounts, and wire instructions. SMS 2FA on everything. Their phone number has already been SIM-swapped once.

Physician or attorney in private practice — HIPAA or client-privilege obligations, personal financial accounts tied to the same email as work, and no time to manage any of it.

High-net-worth individual without kids at home — significant brokerage, crypto, and real estate assets; no IT department; has heard enough breach stories to know they need this but doesn't know where to start.

03

What you think you have — and what's actually exposed

Most people in this bracket have done something. iCloud Keychain is on. Chrome remembers passwords. There's a text message code when you log into the bank. That's not protection — that's the minimum viable illusion of it.

The real risk isn't someone guessing your password. It's that your email was in a breach three years ago, that password is still on your Fidelity account, and the 2FA is SMS — which means a $25 SIM swap is between a stranger and your brokerage.

Surface What you have What's actually exposed
Passwords iCloud Keychain / Chrome autofill Reused across financial accounts; breach corpus presence means attackers already have them
Two-factor auth SMS codes on most accounts SIM swap vector — your carrier can be socially engineered in a 10-minute call for $25
Email account Strong password, maybe 2FA Master key to everything — recovery address for every financial account, no hardware key
Crypto / brokerage App-based 2FA or SMS No cold storage, exchange is the custodian, no hardware wallet, seed phrase unprotected
Recovery plan None If your phone is wiped or account is locked, recovery path is undefined — or worse, it goes through your email
The compounding problem

Each weakness amplifies the others. A reused password plus SMS 2FA plus no recovery plan isn't three small risks — it's one catastrophic chain. Digital Shield severs every link in that chain.

04

Five deliverables. The foundation, built properly.

Not a checklist you print and ignore. Five structured outputs delivered in the first 30 days, then maintained and updated quarterly for as long as you're a member.

  • 01
    Full password inventory + 1Password deployment

    We audit every account you have — browser vaults, iCloud Keychain, spreadsheets, Post-its, memory. Every credential is migrated into a properly configured 1Password vault. Reused passwords identified and rotated. Weak passwords replaced. Browser autofill disabled across all devices. You end Week 1 with a clean, complete vault and no credential debt remaining.

  • 02
    Hardware 2FA (YubiKey) on financial, email, and crypto accounts

    SMS 2FA removed from every account that supports hardware keys. YubiKey configured and deployed on your primary email, brokerage accounts, crypto exchanges, and any account with wire transfer authority. Backup key registered and stored securely. The SIM swap vector — the most common way high-value individuals get cleaned out — is eliminated entirely.

  • 03
    Breach monitoring — HIBP + dark web

    Your email addresses, phone numbers, and usernames enrolled in real-time breach monitoring across Have I Been Pwned and dark web corpus feeds. When your credentials appear in a breach, we get the alert first and act — not just notify. Historical breach exposure reviewed at setup; any credential that's already compromised is rotated before deployment is complete.

  • 04
    Crypto wallet hardening + cold storage migration (if applicable)

    For clients with material crypto holdings: exchange security reviewed, hardware wallet (Ledger or Trezor) configured, and assets migrated to cold storage where appropriate. Seed phrase security audit — most people store it in a note on their phone, which is catastrophically wrong. We fix that. Exchange accounts get hardware 2FA and withdrawal whitelist configuration. If you don't have crypto, this slot is repurposed for additional financial account hardening.

  • 05
    Emergency recovery playbook — stored encrypted

    A documented, tested recovery procedure for every scenario: lost phone, locked account, stolen device, death or incapacity. Stored encrypted in your vault with physical backup for the most critical access points. Your attorney or executor gets a sealed envelope if you want one. Most people have never thought through "what happens if my phone is wiped at customs" — after Digital Shield, you have an answer for every scenario.

05

What the first 30 days look like

Onboarding is structured, not open-ended. Four weeks, each with a defined output. You don't need to be available for all of it — most of the work happens on our side. You review, approve, and confirm at each stage.

Week 1
Audit — The Full Picture

45-minute intake call. We map every account, device, and service. Run your email addresses against breach databases. Identify the highest-risk exposures. You receive a written Digital Risk Report at the end of Week 1 — a complete inventory of what you have, what's exposed, and what we're fixing. This is the same report our assessment prospects see; as a member, yours is real and personalized.

Week 2
Hardening — Passwords + 2FA

1Password vault built and populated. All credentials migrated from browsers and iCloud Keychain. Reused and breached passwords rotated. YubiKey shipped and configured on primary email, brokerage, and crypto accounts. SMS 2FA removed and replaced with hardware keys wherever possible. Browser autofill disabled. By end of Week 2, the credential layer is clean.

Week 3
Deployment — Crypto + Breach Monitoring

Cold storage migration completed for crypto holdings. Hardware wallet configured, seed phrase secured, exchange accounts hardened. Breach monitoring enrolled and active. Device hardening reviewed — encryption confirmed on, stale apps removed, OS updates current. Any remaining gaps from the Week 1 audit are closed this week.

Week 4
Handover — Recovery Playbook + Quarterly Cadence

Emergency recovery playbook written, tested, and stored encrypted. Physical backup prepared. You review and sign off on every system we've built. Quarterly review cadence established — we check in every 90 days to update credentials for account changes, review any breach alerts, and keep the system current. You don't need to think about this again until we do.

See the full day-by-day breakdown: First 30 Days →

06

What Digital Shield is not

Honest scope matters. We'd rather tell you this tier isn't right for you before you subscribe than after.

  • Not for families with children at home. Kids' devices, parental controls, and household-wide coverage require Family Guard ($799/mo). Digital Shield covers one person's surface.
  • Not for estate complexity or digital asset inheritance. Crypto custody architecture, digital estate documents, and legacy planning require Estate Protection ($1,599/mo).
  • Not antivirus software. We don't install endpoint monitoring agents. We're not a managed detection and response (MDR) product. We are a human-run service that builds your security foundation and maintains it.
  • Not a one-time fix. The monthly retainer is not optional. Security decays. Passwords need rotation when accounts change. Breach monitoring requires a human to act on alerts. Quarterly reviews catch what changes between buildouts. This is a membership, not a project.
  • Not a VPN reseller. We don't sell or recommend VPNs as a security measure for this client profile. If you need one for specific use cases, we'll tell you which and why — but it's not part of the core deliverable set.
Not sure which tier fits?

Book a private briefing. Twenty minutes. We'll tell you honestly which tier matches your situation — or whether you need something different entirely.

07

Membership pricing

Digital Shield is the entry tier — the right starting point for individuals who have serious exposure and want it resolved by someone who does this full-time. Not a subscription to software. A membership with a dedicated person.

Monthly
$399
per month

Full individual coverage. Cancel anytime. Onboarding begins within 3 business days of subscription.

Start membership — $399/mo → Book a private briefing →

Prefer annual? $3,990/yr — 2 months free →

Or request a security assessment first: Schedule a consultation →

Prefer a quick conversation? Book a 15-min concierge call →

Wondering what happens after setup? See the monthly cadence →

08

Honest answers

How is this different from just buying 1Password myself?

1Password is software. It does nothing until a human sets it up correctly, migrates your credentials, audits for reuse and breach exposure, and builds a recovery plan for what happens when you lose access. Most people who buy 1Password never fully migrate their passwords, never disable browser autofill, and never remove SMS 2FA. We do the work. The software is the tool; we're the person who uses it properly.

Do you store my passwords?

No. Your vault lives in your 1Password account — you are the account owner and the only one with the master password. We have access during setup to migrate and configure, and we document what exists in your signed-off audit report. After handover, you hold every key. We don't retain credential access after each quarterly review is complete.

I already use a password manager. Does that change what I need?

Maybe. If you're already using 1Password or Bitwarden with strong unique passwords everywhere, hardware 2FA on critical accounts, and a documented recovery plan — you may be in better shape than most. Book a briefing and we'll tell you honestly whether there's a gap worth closing or whether you don't need us. We don't take clients who don't need us.

Can I cancel anytime?

Yes. Monthly memberships can be cancelled before the next billing cycle. Annual memberships are non-refundable after the first 14 days (the buildout work is done in the first 30 days; the value is delivered). When you cancel, your vault stays with you — it's your 1Password account. We don't delete anything on your behalf.

What happens at the quarterly review?

A 20-minute check-in. We review any breach alerts since the last review, rotate credentials for any accounts that have changed (new job, new bank, etc.), confirm your YubiKey and backup key are still working, and update your recovery playbook if anything has changed. Most quarters nothing critical surfaces — but we've caught live breach exposure at quarterly reviews for two different clients. That's the point.

Why hardware keys instead of an authenticator app?

Authenticator apps (Google Authenticator, Authy) are better than SMS but still vulnerable to phishing — a convincing fake login page can capture the 6-digit code in real time. A hardware key (YubiKey) is phishing-resistant by design: it only responds to the legitimate domain it was registered on, so a fake page gets nothing. For accounts with wire transfer authority or large balances, phishing-resistant 2FA is not optional.

Learn more