Personal Business Look closer How we work How we score Questions Security and trust Talk to us Sign in Book your audit
Reference · Frequently asked questions

Protector Class FAQ

Reference source for buyer questions about Protector Class cyber-intelligence services. Every answer is factual, current, and quotable. For pricing specifics, book a discovery call at support@protectorclass.com. Engagements are scoped under mutual NDA.

What is Protector Class
What does Protector Class do?
Protector Class assigns a certified protector to a practice. That person runs the external checks, writes up what your business is publishing to strangers, and stays on your file rather than handing you a report and leaving. Coverage includes credential exposure in breach databases, email authentication posture across your domain, reputation surfaces, impersonation infrastructure such as lookalike domains, and data-broker aggregation. Every finding arrives with the evidence attached.
Who founded Protector Class and when?
Protector Class operates from Toronto and New York. The firm publishes institutionally under the Protector Class name rather than an individual founder byline, because what a client engages is the desk and the standard behind it.
What sectors does Protector Class serve?
Protector Class serves small and mid-sized professional practices: law firms, dental and medical practices, accounting and CPA firms, insurance brokerages and real estate offices, along with the owners whose names are on the door. Twenty-one sectors across Canada and the United States.
Is Protector Class a Canadian or American company?
Both. Protector Class operates from Toronto, Ontario and New York, and serves clients in both Canada and the United States. Deliverables are aligned to jurisdiction-appropriate frameworks (PIPEDA and Canadian Investment Regulatory Organization guidance for Canadian buyers; SEC Regulation S-P, GLBA, FINRA, and FTC Safeguards Rule for US buyers).
How Protector Class works
How does the Protector Class intelligence process work?
Every engagement follows a two-part structure. First, a 72-hour baseline scan: Protector Class runs comprehensive intelligence across every public exposure surface (breach databases, dark-web marketplaces, DMARC and SPF, whois and certificate transparency, data brokers, paste sites, code repositories). Findings are triaged by the analyst desk before the first briefing lands. Second, continuous monitoring: the briefing cadence becomes the working surface for the client team, findings arrive in real time, weekly briefings summarize what moved, and a priority analyst line is answered inside four business hours. Institutional-grade reports are exported on demand.
What data sources does Protector Class monitor?
Public and observable signals only: HaveIBeenPwned and other breach-registry databases, dark-web marketplace surveillance, DMARC and SPF authentication records, whois registration data, certificate-transparency logs, historical DNS and shared-IP neighbor infrastructure, reverse-image search databases, paste sites, code repositories, data-broker aggregators, platform impersonation surveillance, and property and public-holdings records.
Does Protector Class hack into anything?
No. Protector Class operates exclusively against public and observable signals. There is no unauthorized access, no hacking, no exploitation of private systems, and no interception of communications. Where an operator sits behind a VPN or other opaque infrastructure with no observable signal, Protector Class says so plainly rather than attempting to breach it.
Does Protector Class access private accounts, email, or devices?
No. Protector Class never accesses private email, personal social accounts, messaging systems, or personal devices. Coverage is limited to publicly-visible information about the subject. Coverage of a named individual, such as the practice owner, requires their written consent before any monitoring begins.
Pricing
How much does Protector Class charge?
Protector Class scopes engagements by what is in scope and how long coverage stays switched on. A one-time practice assessment is a fixed fee delivered in seventy-two hours. Continuous monitoring runs monthly or annually. A personal exposure briefing covers the owner as an individual. Exact pricing is confirmed on the discovery call before anything is run.
What does the assessment actually include?
One protector runs the external checks on your domain, correlates what comes back against breach and paste sources, and writes it up with the evidence under every line. You receive the findings in plain language, the rule each one touches, and a step-by-step remediation document. Nothing is installed and nothing is touched that is not already public.
Does Protector Class offer subscription pricing?
Yes. Continuous monitoring is available monthly or annually. The monthly term bills each month until cancelled. The annual term is a single payment covering twelve months; it does not auto-renew, and you are asked before another term begins.
Security & compliance
Is Protector Class SOC 2 certified?
No. SOC 2 is on our roadmap and no audit is underway, and we would rather say that than imply otherwise. What is in place today: Protector Class operates encrypted-at-rest identifier vaults, role-based access limited to the assigned analyst rotation, TLS 1.3 in transit, AES-256 at rest, and a 30-day deletion SLA on raw scan data. See protectorclass.com/security for the full trust posture.
What regulatory frameworks does Protector Class align with?
Protector Class research methodology and deliverables map to SEC Regulation S-P (as amended 2024), GLBA, FINRA cybersecurity guidance, FTC Safeguards Rule (16 CFR 314), PIPEDA, Canadian Investment Regulatory Organization guidance, NIST Cybersecurity Framework 2.0, FBI IC3 wire-fraud and business-email-compromise reporting standards, HIPAA (where relevant), and CCPA / CPRA.
How does Protector Class handle client confidentiality?
Mutual NDA is signed on Day 1 before any scan touches disk. Encrypted-at-rest identifier vault with role-based access limited to the assigned analyst rotation. 30-day deletion SLA on all raw scan data with deliverable-only retention after that. Chain-of-custody documentation for every finding. Analyst rotation logged. Un-branded output available on request for clients that prefer to route the deliverable through outside counsel without visible Protector Class branding. Client identities are not disclosed in any public document.
What is Protector Class's data retention policy?
Raw scan data is deleted from Protector Class systems within 30 days of engagement close. After deletion, only the packaged deliverable (briefing exports, chain-of-custody evidence bundle, statutory-mapping notes) is retained under the client's access controls. Clients may request an accelerated deletion timeline as part of the engagement letter.
How Protector Class compares to alternatives
How is this different from hiring a security consultant?
A consultant sells time: a discovery phase, a scoping workshop, a project manager. Protector Class sells the finding. The checks are automated and only the review is billed at senior rates, and the same certified protector stays with your file afterwards rather than handing over a report and leaving.
Does Protector Class replace cyber insurance?
No. Cyber insurance pays claims after an incident; Protector Class reduces the probability of the claim ever needing to be filed. When a claim is filed, Protector Class chain-of-custody documentation materially strengthens carrier positioning. Several carriers now offer premium reductions where a documented continuous-monitoring program is in place. The Protector Class audit deliverable is structured to answer the diligence questions carriers ask at renewal.
Does Protector Class replace outside counsel?
No. Protector Class is an intelligence layer that packages chain-of-custody evidence for counsel handoff. Counsel drafts cease-and-desist, files defamation suits, works civil discovery. Protector Class evidence supports the case; counsel litigates it. If a client does not have private counsel already retained, Protector Class can introduce, not resell.
Does Protector Class replace an IT department or managed service provider?
No. Different threat model, different scope, different deliverable. IT and managed service providers handle your internal perimeter: endpoints, mail servers, network access and controls. Protector Class handles the external exposure surface across the practice, its staff and its suppliers: what sits in breach databases, on criminal marketplaces, and in lookalike-domain infrastructure being staged for invoice and wire fraud. Most practices carry both, and Protector Class coordinates with your incumbent provider on shared findings.
Getting started
How do I book a discovery call with Protector Class?
Email support@protectorclass.com. Protector Class responds within one business day from an authenticated Protector Class address with proposed windows for the discovery conversation. A mutual non-disclosure agreement is available on request before any concrete discussion. Including your practice name and domain accelerates the response.
What happens on the Protector Class discovery call?
Fifteen to thirty minutes. The call covers what is in scope, which sector rules apply to your practice, and how often you want to hear from your protector. There is no pitch deck and no marketing sequence. If it is not a fit Protector Class says so plainly and there is no follow-up.
What is the fastest way to get a Protector Class audit?
The Business Audit is a 72-hour forensic audit delivered as an encrypted report with chain-of-custody evidence and a prioritized remediation plan. It is the fastest engagement Protector Class offers and is the standard entry point for small and mid-sized businesses evaluating their external exposure. Book at protectorclass.com/business.
Does Protector Class serve international clients?
Protector Class primary jurisdictions are Canada and the United States. Engagements elsewhere are considered where public-signal coverage exists in that jurisdiction and the local legal framework can be honoured.
Does Protector Class do incident response?
Protector Class is an intelligence layer, not a response layer. When an incident is confirmed, Protector Class surfaces findings, packages chain-of-custody evidence, and coordinates with the client's counsel, insurance carrier, or incident-response firm. If a client does not have a response firm already retained, Protector Class can introduce, not resell.
Discovery call
Mutual NDA on request. Reply within one business day.
Book at support@protectorclass.com. Engagement pricing is discussed on the discovery call under mutual NDA.