What your practice looks like from the outside.
We check what your domain publishes to anyone who asks, write down what we find in plain language, and put a name and a phone number beside it. No login, no software to install, nothing touched that is not already public. One certified protector stays with your file.
A staff password from a 2021 breach, still working on ✓ HUMAN-VERIFIED
Your mail domain accepts invoices sent in the name of ✓ HUMAN-VERIFIED
A booking system version number, published to anyone who asks since ✓ HUMAN-VERIFIED
Sample · Compiled from your own domain in 72 hours
Built for practices across law, dental, medical and accounting.
External Attack Surface Management, credential intelligence and business email compromise monitoring. The same class of tooling enterprise security teams run, pointed at your business.
Signals collected from search indexes, service fingerprinting and breach-pattern matching, verified by language models, scored continuously. The score moves the moment your exposure does.
Nothing serious reaches you unread. One certified protector stays with your file, reads every finding, and walks you through it in plain language.
Their own address, in a file somebody else already has.
Before anything about the owner personally is looked at.
They get inside an inbox, watch the finance traffic, and wait. The FBI put the 2025 total at $3.05 billion, and reporting is voluntary.
One standard. Three ways in.
Every engagement runs the same checks and the same review by a certified protector. The only thing that changes is how much of it stays switched on.
What your practice shows a stranger
One protector runs the checks on your domain, then reads the findings back to you in plain language with the evidence under every line. Nothing installed, nothing touched that is not already public.
Continuous coverage
Daily rescan, alerting the moment something new is exposed, and a trend line you can show a partner or an insurer. For practices whose staff, systems and suppliers keep changing.
The owner, not just the practice
A separate check on the person whose name is on the door. Credentials in breach files, data-broker listings and impersonation attempts that follow the individual rather than the domain.
Nothing installed. Nothing touched. Done in three days.
Domain fingerprinting
Full enumeration of your external attack surface: DNS, certificates, exposed services and the infrastructure identifiers attackers see first.
Source correlation
Multi-source correlation across the same layers attacker tooling operates on: criminal marketplaces, breach repositories and paste archives.
Risk quantification
Findings are classified by severity and mapped to the statutory framework that applies to your sector.
Intelligence delivery
Executive summary, technical evidence, statutory mapping and a prioritised remediation roadmap. Checked by a person.
Continuous surveillance
Daily rescans, threshold-based alerting on new exposure, and longitudinal trend analysis.
What practices ask first
01Do you touch our systems?
No. Every assessment is read-only and external. We correlate publicly available and breach-sourced data and analyse what your infrastructure already publishes. No intrusive testing, no agents, no access to your network.
02Why does this cost less than a security consultant?
Because the checks are automated and only the review is billed at senior rates. What you are not paying for is a discovery phase, a scoping workshop and a project manager, none of which change what is exposed.
03What happens to what you find?
Retained encrypted, disclosed only to you, and destroyed on request. A mutual NDA is signed before we discuss anything specific about your exposure.
04How long does it take?
Seventy-two hours from the moment scope is agreed. A consultancy will usually quote six to eight weeks for comparable work.
05Can we do this without an IT department?
Yes. The list is written for whoever actually runs your systems, not for a specialist. Practices with no security staff are exactly who it is built for.
06What if you find nothing much?
You get that in writing, dated and signed. That document answers carrier applications, client diligence questionnaires and counterparty requests on its own.
You cannot defend what you have never seen. See it first.
Twenty minutes, and you will know where you stand.
Under a mutual non-disclosure agreement, so the conversation can be specific instead of general. We agree what is in scope and put a date on it. If a practice your size does not need us, you will hear that on the call rather than in a proposal three weeks later.