See what an attacker already knows about you.
Before they use it.

We map what is already public about your business: what is reachable, what is exposed, and what someone could learn before they ever touch anything. Nothing is probed and nothing is scanned. You get a ranked list of what to close first, in plain English.

Ask for a reviewSee what we findNo cost for the first look.

Part of the wider AI and automation work. See everything we do

What we find

Six things, all of them already public. No traffic reaches your systems.

Passive review

The things already sitting in the open.

This is the homework someone does before they try anything. Doing it first, on purpose, is the cheapest security work available to a small business.

Footprint

Everything facing the internet in your name

Domains, subdomains and services, including the forgotten test site or old booking page nobody remembers putting up. You cannot look after what you do not know you own.

Software

Versions with publicly known holes

Where a site or mail server runs software with a published vulnerability at the exact version you are on. This is the most common way small business sites get defaced, and the version is usually sitting in the page source.

Credentials

Staff logins already leaked

Emails and passwords caught in past third-party breaches and circulating online, ready to be tried against your accounts. Almost always a surprise, and almost always still valid somewhere.

Email

Whether your domain can be spoofed

The records that stop someone sending a fake invoice in your name. Missing them means a customer receiving that invoice has no way to tell it is not from you.

Exposure

What was meant to be private and is not

Documents, logins and dashboards reachable by anyone who looks, plus whatever search engines have already indexed and cached.

People

The material a convincing scam would use

The staff and social footprint someone would draw on to write a phishing email that sounds like it came from inside the business.

How it works

Three steps. Nothing to schedule, nothing to approve, nothing that can break.

The process

Looking, not touching.

Active testing has its place and we do it, but only once it is scoped and authorised in writing. The first pass is entirely passive, which is why it can happen this week without a change window or any risk to a system that is running fine.

Passive review · what we look atNo probing
Domains & subdomainsWhat is actually reachable, including what you forgot
Email addressesStaff addresses already public and scrapeable
Credential leaksYour addresses appearing in known breach corpora
Exposed servicesLogins, panels and ports facing the open internet
DNS & mail recordsSPF, DKIM and DMARC, and whether you can be spoofed
Staff footprintWhat social and job posts reveal about your stack
Method

Everything above is gathered from public sources only. Nothing is probed, scanned or touched, so there is no risk to anything you run.

01We look, without touching anything

Everything comes from public sources: search engines, public records, breach databases and what your own site publishes about itself. No traffic reaches your systems, so there is nothing to schedule, nothing to approve, and nothing that can break.

02You get a ranked list, not a report to file

A short list of what is actually exposed, in the order worth doing something about, in plain English. Not a compliance checklist and not a hundred pages of severity ratings you have to interpret.

03You decide what happens next

Fix it yourself, hand it to whoever looks after your systems, or ask us. If there is nothing worth reporting we will tell you that, which is a perfectly good outcome.

Going further

Optional, scoped, and never assumed. The first review stands on its own.

Beyond the first pass

When you want more than a look.

None of this is bundled in or assumed. It is here so you know where it can go if the first review turns up something worth chasing.

01Go deeper, with permission

Active testing of a site or app: actually trying the doors rather than noting they look unlocked. Scoped and authorised in writing first, always.

02Fix what we found

Not just a list handed over. Patching, hardening and reconfiguring the things that matter, either directly or alongside whoever already looks after your systems.

03Keep watching

Ongoing checks for new exposure, fresh credential leaks and changes to your footprint, so something is caught while it is cheap rather than after it bites.

Find out what is already public about you.

Tell us your domain and we will take a look. If there is nothing worth reporting we will say so, and it costs you nothing either way.

Passive review · no obligation

Prefer email? [email protected]