The necessary ones make the site work. The others measure which pages help and which ads bring the people who need DM11. Your choice, and you can revisit it from the footer.
DIGITAL EXPOSURE
Digital Exposure is the one-off portrait of what is already exposed about your company outside the perimeter, delivered once. An employee credential in a breach, a domain that looks like yours registered by someone else, your brand used in a scam, data for sale in a closed forum. You start out knowing the size of the problem, with every finding validated and tied to what to do, instead of hearing it from the customer who called asking about an email you never sent.
We examine the assets you authorise us to survey, your domains, your brand, your executives, and the sources within our reach. We do not break into systems, we do not buy criminal access, and we handle the data we find for a security purpose, discarding what does not matter. The snapshot informs the decision, it does not remove content and it does not respond to the incident: that comes afterwards, with whoever does each of those things.
Who runs the survey
An in-house Cyber Intelligence Centre
Coverage of the open internet, Deep Web, Dark Web and closed groups, within what is accessible
An analyst who reads the signal and recommends the action, not only collects it
17 years of governance, risk and compliance
WHAT IT IS
Digital Exposure is not running a tool and sending the list it spits out. What you buy is the reading: someone who tells the real breach from the recycled combolist, who confirms which credential still matters, and who ties the finding to what your business cannot afford to lose. A snapshot is a single pass, with a beginning, a middle and an end: at the end you have the size of the problem, measured, and not an impression. And because exposure regenerates week after week, the snapshot is a great way in and a poor final solution.
Digital Exposure portrays what is already exposed now: a credential, a lookalike domain, your brand in a scam, data for sale. It is there to start out knowing the size of the problem before you decide what to do about it. It does not warn you when something new appears, because it is not a watch: that is CTI, the continuous step that usually comes after the snapshot. A picture from January does not protect you from a leak in March, and saying otherwise would be selling what the snapshot does not deliver.
From outside, we map leaks, domains, your brand and what circulates in closed forums. From inside, we cross the signals in your environment with current threat intelligence: behaviour that matches a campaign under way, an address already flagged, a known technique showing up. Seeing the two together gives the truest portrait of the size of the problem, because what leaks outside often explains what appears inside.
Every finding arrives dated, validated and tied to the asset it threatens, with what to do about it, in a single report. When your company answers to a standard, the same report becomes evidence: control A.5.7 of ISO/IEC 27001:2022 calls for intelligence collected, analysed and used in a decision, and the fourteenth minimum control of the Central Bank of Brazil's cybersecurity resolutions calls for intelligence action with monitoring on the internet, Deep Web, Dark Web and private groups. The snapshot is the artefact that proves that chain at a point in time.
We examine the sources within our reach, and not everything that circulates is accessible. That is why the value is not in a promise of full coverage, it is in the reading of what appears and the action that comes after. By the same honesty, the snapshot does not remove the content, does not reset the leaked password, does not run the forensics of the leak and does not respond to the incident: it informs each of those decisions, which stay with whoever carries them out.
WHEN IT MAKES SENSE
In one of them the requirement arrives from outside, with a deadline. In the other two it comes from inside, almost always after the first scare or before deciding on the watch.
Resolutions CMN 5.274 and BCB 538, of December 2025, with compliance required since March 2026, list fourteen minimum controls, and the fourteenth is intelligence action in the cyber environment. In the ISO/IEC 27001:2022 world, control A.5.7 asks for the same: intelligence collected, analysed and used in a decision. A company that declared the control and never executed it needs the evidence, and the snapshot delivers that artefact at a point in time. When the standard asks for regularity, the snapshot is the start, and the recurring watch is what sustains it.
An employee credential turned up in a breach, or an email the company never sent reached a customer. The one-off incident was contained, and what stayed was the question the snapshot answers all at once: what else has already leaked, what is still circulating, how much of it matters. It is the move from reaction to a map.
Before engaging the continuous follow-up, it makes sense to know the size of what is already exposed. The snapshot measures the problem with judgement and, with the picture in hand, the decision about the recurring watch stops being made in the dark: you know whether CTI needs to cover brand, credentials, the inside, or all of it.
TRANSLATING THE ASK
The size of the work does not come from the number of findings. These are the four ways the ask usually arrives, with what each one means and what genuinely moves the effort.
| What they asked for | What that means | What changes the size |
|---|---|---|
| We want to know what has already leaked about us | The one-off snapshot of what is exposed today: leaked credentials and sessions, lookalike domains, your brand in a scam and what circulates in a closed forum, all validated and dated in a single report. | How many email domains come in, how many executives will be covered, and whether the survey looks only from outside or also from inside. |
| We need to measure the brand's exposure | The portrait of the brand, the domains and the official profiles outside the perimeter, with the misuse, the lookalike domain and the scam that already use your name, at a point in time. | How many brands and domains come in, whether ownership is yours or a partner's, and how many official profiles there are to compare against the fakes. |
| The standard asks for the threat intelligence evidence | The artefact that proves collection, analysis and use at a point in time, for the Central Bank's fourteenth control or A.5.7 of ISO/IEC 27001:2022. The snapshot delivers the evidence; the regularity, when required, comes with CTI. | The evidence format your auditor accepts and the reach of the survey that closes the requirement. |
| We want to see the size before signing up for a watch | The snapshot as sizing: measuring what is already exposed to decide, with judgement, the scope of the recurring watch that will come afterwards. | Whether the snapshot looks from outside, from inside or both, because that, and not the volume of alerts, is what defines the effort of the survey. |
The scoping conversation happens before the proposal, and it is there to separate the one-off snapshot from the recurring watch. Digital Exposure sizes what is already exposed; when what you need is to be warned about what comes next, the service is CTI.
STORIES
We change our clients' names with the same confidentiality that will protect your company later. The names change, the pattern of the problems repeats. Where a client authorises it, we share named references in a conversation.
Manufacturing
A customer received an email in the company's name that no one there had sent. The one-off scare was contained, and the question stayed: what else was already out there?
Digital Exposure answered with a single snapshot: employee credentials still valid in breaches, a lookalike domain registered by someone else, and mentions in a closed forum. All of it validated and dated, with what to do in each case.
The company moved from reaction to a map: it learned the real size of its exposure all at once, prioritized what mattered, and used the snapshot as the starting point to decide on continuous watch.
Certified companies
The company was certified in ISO 27001 and had declared the threat intelligence control without ever really executing it. The next audit would ask for the evidence, and there was none.
We delivered Digital Exposure, the one-off snapshot of what was already exposed: credentials in breaches, lookalike domains, and what circulated about the company outside it. Every finding came out validated, dated, and tied to the control it evidences.
What was a compliance gap became an auditable artifact, the proof that intelligence was collected, analyzed, and used in a decision. From the snapshot on, the company decided to keep continuous watch, with the picture in hand.
HOW WE RUN IT
Each phase ends in something you can check without taking our word for it. That is the point: a report your audit can read is worth more than a screen full of findings nobody opens.
We register the domains, the brands, the official profiles and the executives to cover, and we agree in writing what comes into the survey and what stays out. For the inside, we define access to the telemetry we will cross-reference. Because the snapshot is a single pass, this is where the reach is decided: from outside, from inside, or both.
Assets registered, with brands, domains, profiles and what belongs to third parties
A written scope, with what comes into the survey and what stays out
Agreed access to internal telemetry, when the inside comes in
The snapshot's reach defined: from outside, from inside or both
Delivery milestoneScope and access agreed in writing, with no coverage question left open.
We collect from the sources within reach, the open internet, Deep Web, Dark Web and closed groups, and we validate before any finding enters the report. Validating is what separates a useful finding from noise: deduplicating what repeats, dating what appeared, discarding the recycled combolist that only repackages an old leak, and confirming which credential still matters. Without this phase, the snapshot would be a data dump that moves no decision at all.
Findings collected from accessible sources, with no promise of full coverage
Repetition removed and every finding dated
Recycled combolist discarded, with the reason recorded
Confirmation of which credential is still valid and matters
Delivery milestoneEvery finding dated and classified, with no recycled combolist in the report.
Every validated finding is tied to the asset it threatens and to what your business cannot afford to lose, and prioritised by that, not by the order in which it appeared. When your company answers to a standard, the finding is also tied to the control it evidences, A.5.7 of ISO/IEC 27001:2022 or the fourteenth control of the Central Bank of Brazil's resolutions. It is that tie that turns a finding into evidence and into action.
Every finding tied to the asset and to the business risk
Priority set by impact, not by order of arrival
A tie to the standard's control, when the company answers to one
A recommended action per finding, with the action owner named
Delivery milestoneEvery finding with an owner, a priority and a recommended action.
The snapshot closes in a single report: what is already out there, how much it matters and what to do with each finding, read with your team. It is that reading the standard requires when it calls for the intelligence to be used, and it is also the moment when the next step is decided: if the exposure calls for a continuous watch, the CTI conversation starts with the picture in hand, and not in the dark.
A single report of what is exposed, with what to do on each finding
Priority and action owner recorded per finding
A reading of the report with your team, with the decisions noted
A recommendation on the next step, when the exposure calls for a watch
Delivery milestoneThe report delivered and read, with the decisions and the next step noted.
HOW THE SNAPSHOT RUNS
We do not publish a deadline or a price, because a survey's scope varies widely and a published number becomes a promise. The first conversation already shows which of these factors your company is in, and it is what produces the scoping requirement.
A brand with few domains runs light. A group with several brands, dozens of domains, official profiles across many channels and executives to cover consumes more. Ownership weighs in too: surveying what is yours is straightforward, and what belongs to a partner has to be agreed beforehand.
The external survey covers leaks, domains and brand. The internal one crosses your environment's telemetry with current threats, and requires agreed access. The two together give the truest portrait and are the scope that moves the effort the most, more than the technical part does.
Part of what circulates is in open sources and is quick to cover. Part is in a closed group or a restricted-access forum, and not everything is accessible. The scope says honestly what can be covered, instead of promising what nobody delivers.
FREQUENTLY ASKED
The questions that come up in almost every first meeting, answered without hedging.
It is the same work in two tenses. Digital Exposure is the one-off snapshot: the picture of what is already exposed today, delivered once. CTI is the continuous watch that usually comes afterwards: the warning when something new appears, at the agreed frequency. The snapshot shows the size of the problem and is a great way in; it does not warn you about what comes later, because exposure regenerates and a picture of today does not protect you from tomorrow's leak. That is why the snapshot sizes, and CTI sustains.
No. The tool collects and lists. Digital Exposure reads what the tool brought in: it tells the real breach from the recycled combolist, confirms which credential still matters, ties the finding to your asset and says what to do, in a single report. A raw list nobody interprets is not a portrait, it is noise with a stamp on it. Both control A.5.7 of ISO/IEC 27001:2022 and the fourteenth control of the Central Bank of Brazil's resolutions ask for exactly this: that the intelligence be used in a decision, and not only gathered.
No, and this is where the split matters. Digital Exposure is a single pass: it portrays what is exposed at the moment it is made. The warning about what comes later is CTI, the recurring watch. Taking the snapshot and expecting it to protect you forever is the mistake we avoid by saying it up front: the picture is of today, and tomorrow's exposure calls for a watch.
No. Resetting the leaked credential or the password stays with your IT team, after the report. Our role is to survey early, confirm that the credential still matters and say what to do. By the same division, the snapshot does not remove the content, does not run the forensics of what caused the leak and does not respond to the incident: it informs each of those decisions, which stay with whoever carries them out.
It delivers the evidence at a point in time. Resolutions CMN 5.274 and BCB 538, of December 2025, with compliance required since March 2026, call for intelligence action in the cyber environment, and A.5.7 of ISO/IEC 27001:2022 calls for intelligence collected, analysed and used in a decision. Digital Exposure proves that chain in one survey; when the standard asks for regularity, the snapshot is the start and CTI's recurring report is what sustains the requirement over time.
No, and it is worth being wary of anyone who guarantees it. We examine the sources within our reach, and not everything that circulates is accessible: part is in a closed group, part never shows up anywhere you can see. That is why the value is not in a promise of full coverage, it is in the reading of what appears and the action that comes after. An honest survey says what it covers and what it does not, instead of promising the impossible.
A short conversation defines the scope and measures what is already exposed today. It is there to size the one-off snapshot with judgement and, with the picture in hand, to decide whether the exposure calls for CTI's continuous watch, knowing exactly what you get at each step.