ArgusLeaf

About

A different scan.

In addition to tenant-specific monitoring (Watch), we run a continuous sector-wide scan we call Observatory. Where Watch is private — your data stays yours — Observatory processes all certificate transparency traffic and publishes the aggregate picture.

Watch (private)

Your brand terms. Your domains. Alerts go only to you. Data is never shared or published.

Observatory (public)

All CT traffic. All sectors. Published as aggregate trend statistics. No individual names, ever.

We publish this data freely because the threat landscape should be visible to everyone, not only organisations that can afford a threat intelligence subscription.

Output

Aggregates only.

Our publication policy is strict: we publish numbers and trends, never individual domains, company names, or screenshots.

A published finding looks like: "Banking sector: 847 high-confidence matches this week, up 23% week-on-week." Not: "bank-login-secure.com targeted FirstBank."

This protects both the potential victims (no public list to amplify) and the alleged operators (no accusation without due process).

Status

In calibration

Not yet publishing.

Observatory data is currently in its baseline-collection phase. We're building 90 days of data before publishing trend reports — a shorter window would produce misleading spikes that are just collection artefacts, not real changes in attacker behaviour.

Expected first publication: Q4 2026.

Want early access to Observatory data? Write to [email protected] with your research affiliation.

Collaborate

Academic and institutional access.

We're interested in collaborating with researchers studying phishing infrastructure, certificate abuse, and brand protection.

If you're affiliated with a university or non-profit security research organisation, write to us. We can provide:

  • Pre-publication aggregate data
  • Access to our scoring methodology and calibration data
  • Co-authorship discussion for papers that use our data

[email protected]