Every TLS certificate issued on the internet is published to a public log. We read those logs continuously, looking for domains that imitate your brand — and we email you when one appears.
The name
Most people will read the first half. People who work with certificates will read both.
The watchman of Greek myth, covered in a hundred eyes. Only some of them slept at any moment, so he was never fully asleep. Certificate logs never stop appending; neither does the thing that reads them.
A transparency log is a Merkle tree, and every certificate entered into it is a leaf. When we say we watch the leaves, we mean it literally — one hashed entry at a time.
How it works
Your brand terms and your real domains. You prove you control the domain with a DNS TXT record — no exceptions, so nobody can subscribe to someone else's threat picture.
Certificate transparency logs, newly registered domain feeds, and public phishing datasets. We score each name for imitation: character substitutions, homoglyphs, keyword combinations.
A high-confidence match reaches you within minutes. Everything else arrives in a daily digest. At month's end you get a report — including the months where we found nothing, because that's information too.
What we don't do
Security companies sell alarm. We publish aggregate research and send warnings. The difference shows up as a list of things we've decided not to build.
Separately from tenant monitoring, we run a sector-wide phishing intelligence engine — scanning all CT traffic, not just watchlists. Aggregate statistics and campaign trends are published openly. No domain names, no company names, no screenshots ever.
Get started
Apply to have your brand monitored — we're taking the first 50 organisations at no charge. Or if you've already spotted something suspicious, tell us.
Questions? Write to [email protected]