ArgusLeaf

We don't
sell fear.

Every TLS certificate issued on the internet is published to a public log. We read those logs continuously, looking for domains that imitate your brand — and we email you when one appears.

50 Early access slots
24/7 CT log coverage
< 5 min Alert latency (P95)
0 Dashboards to check

The name

Two words, two readings.

Most people will read the first half. People who work with certificates will read both.

Ἄργος Πανόπτης · Argus Panoptes

Argus

The watchman of Greek myth, covered in a hundred eyes. Only some of them slept at any moment, so he was never fully asleep. Certificate logs never stop appending; neither does the thing that reads them.

Merkle tree · leaf node

Leaf

A transparency log is a Merkle tree, and every certificate entered into it is a leaf. When we say we watch the leaves, we mean it literally — one hashed entry at a time.

How it works

Three steps, then email.

  1. You tell us what to watch

    Your brand terms and your real domains. You prove you control the domain with a DNS TXT record — no exceptions, so nobody can subscribe to someone else's threat picture.

  2. We read the logs

    Certificate transparency logs, newly registered domain feeds, and public phishing datasets. We score each name for imitation: character substitutions, homoglyphs, keyword combinations.

  3. You get an email

    A high-confidence match reaches you within minutes. Everything else arrives in a daily digest. At month's end you get a report — including the months where we found nothing, because that's information too.

Full technical explanation →

What we don't do

The short list.

Security companies sell alarm. We publish aggregate research and send warnings. The difference shows up as a list of things we've decided not to build.

  • No dashboard. Nothing to log into, nothing to check. If there's news, it's in your inbox.
  • No upsell. The alerts contain no marketing, no plan comparison, no "contact sales."
  • No public naming. We never publish a domain list, a screenshot, or a company name. Our research is aggregate only.
  • No verdicts. We report suspicion, not guilt. A finding is an automated signal, and we say so in every email.
  • No data resale. What we find about your brand goes to you. It is not a product.
Observatory

The public research arm

Separately from tenant monitoring, we run a sector-wide phishing intelligence engine — scanning all CT traffic, not just watchlists. Aggregate statistics and campaign trends are published openly. No domain names, no company names, no screenshots ever.

Get started

Two ways in.

Apply to have your brand monitored — we're taking the first 50 organisations at no charge. Or if you've already spotted something suspicious, tell us.

Questions? Write to [email protected]