Observatory
Aggregate statistics from our full CT-log scan — published openly. No domain names, no company names, no screenshots.
About
In addition to tenant-specific monitoring (Watch), we run a continuous sector-wide scan we call Observatory. Where Watch is private — your data stays yours — Observatory processes all certificate transparency traffic and publishes the aggregate picture.
Your brand terms. Your domains. Alerts go only to you. Data is never shared or published.
All CT traffic. All sectors. Published as aggregate trend statistics. No individual names, ever.
We publish this data freely because the threat landscape should be visible to everyone, not only organisations that can afford a threat intelligence subscription.
Output
Our publication policy is strict: we publish numbers and trends, never individual domains, company names, or screenshots.
A published finding looks like: "Banking sector: 847 high-confidence matches this week, up 23% week-on-week." Not: "bank-login-secure.com targeted FirstBank."
This protects both the potential victims (no public list to amplify) and the alleged operators (no accusation without due process).
Status
Observatory data is currently in its baseline-collection phase. We're building 90 days of data before publishing trend reports — a shorter window would produce misleading spikes that are just collection artefacts, not real changes in attacker behaviour.
Expected first publication: Q4 2026.
Want early access to Observatory data? Write to [email protected] with your research affiliation.
Collaborate
We're interested in collaborating with researchers studying phishing infrastructure, certificate abuse, and brand protection.
If you're affiliated with a university or non-profit security research organisation, write to us. We can provide: