Proposal
Digital Exposure
The one-off portrait of what is already exposed about your company beyond the perimeter: leaked credentials and sessions, a lookalike domain registered by someone else, your brand used in a scam, data on sale in a closed forum. We deliver it once, with every finding validated, dated, and tied to what to do. It is the entry point to continuous intelligence: you start by knowing the size of the problem, instead of hearing it from a customer who called.
No price appears on this page. Scope does: what we do, how we run it, who runs it and what is not included. The people who read your request are the ones who will look after you, and they come back with the proposal and with time to talk it through.
Digital Exposure
Start by knowing the size of what is already exposed.
How we run it
What this work consists of
It is a snapshot, not a watch. In a single pass, we gather what has already leaked and is circulating today about your company outside it and deliver the validated portrait: every finding dated, confirmed, and tied to an action, without the raw list any tool spits out. It serves to size the problem before you decide what to do about it.
You can look from two sides. From the outside, we map leaks, lookalike domains, brand, and what circulates in closed forums. From the inside, we cross your environment's signals with current threat intelligence. Seeing both together gives the truest portrait, because what leaks outside usually explains what shows up inside.
On your side, you point us to domains, brands, official profiles, and executives to cover; for the inside view, we need access to the telemetry we will cross-reference. The result comes in a single report: what is already out there, how much it matters, and what to do with each finding. Exposure regenerates week after week, so this is a snapshot of today, and the continuous watch is CTI.
How we conduct it, stage by stage
One-off assessment
A single pass over the accessible sources to build the portrait of what is already exposed: credentials, domains, brand, and what circulates in closed forums, all validated and dated before it becomes a report.
What is not included
- Watching over time: the snapshot is of today, and the recurring follow-up is Continuous CTI
- Taking down the content found, which depends on the platform and can come in as separate support
- Forensic investigation of what caused the leak, which is its own service
- Rotating leaked credentials or resetting passwords, which stays with your IT team after the report
- Legal action against whoever published, which stays with your legal team
- A guarantee that every leak will be found: we examine the sources within our reach, and not everything that circulates is accessible
Usually comes together with
Not a bundle, and it changes nothing you have already chosen. It is what tends to come up next, in the experience of companies that have been through this.