Personal Business Look closer How we work How we score Questions Security and trust Talk to us Sign in Book your audit
How a check actually runs

You are already publishing this.
Somebody should read it to you.

We check the breach databases, the places stolen data gets traded, what your systems show publicly, the filings that name your practice, and what AI assistants answer when a client asks about you. Then a person goes through it and writes down what actually matters, before anyone else acts on it.

The order it happens in
01

We read the sources

Breach databases, the places stolen data gets traded, your public systems, the filings that carry your practice name, and what AI assistants answer when someone asks about you.

02

A protector goes through it

Machine output is not a finding. A person checks each one, drops what does not hold up, and keeps what has a name and a number attached.

03

You get it in plain language

A briefing written to be read once and acted on, not a console you have to learn.

04

The reading continues

The sources keep moving. Ongoing coverage means you hear about the next one from us.

Why Now

The scanning never stops. Neither does the checking.

Fake emails are written in bulk. Impersonation is cheap. Stolen passwords are indexed within hours of a leak. Target lists assemble themselves. We work at the same speed, with the same class of tooling pointed the other way, ML-driven threat classification. Continuous coverage across every public exposure surface, categorized and alertable in a live dashboard.

The Intelligence Model

From scattered traces
to something you can act on.

Raw exposure data is scattered, unstructured, and overwhelming. Protector Class processes it through an intelligence pipeline that converts noise into verified, prioritized findings.

Scattered traces
Process
Structure
Exposure
Briefing
Live
Monitoring
Remediation
Guidance
Domain
Assessment
Breach
Alerts
Access
What Goes In

Where we look

01
Breach Databases

Records from breaches that have already happened: passwords, personal details, account data.

02
Data Broker Networks

Sites that resell home addresses, employers and relatives to anyone willing to pay a few cents.

03
Where stolen data gets traded

Closed channels where stolen data is listed and traded, and where a target gets put together.

04
Domain Intelligence

Services left open or misconfigured, and forgotten subdomains, all of it indexed by scanners that run without stopping.

What Comes Out

Checked before you see it

→
Confirmed Findings Only

Anything that turns out to be nothing is dropped before you see it. What reaches you is checked and applies to your practice.

→
Severity-Ranked

The things most likely to be used against you come first. Nothing important is buried further down.

→
Action-Paired

Every finding says what to do about it. Not a pile of data, a short list in the order it should be worked.

→
Continuously Updated

Exposure is not a single event. Protector Class monitors continuously and alerts when new findings surface.

The Four Stages

From Raw Exposure
to a briefing on your desk.

Every check runs the same four steps, in the same order, on real data. No shortcuts and nothing invented.

Stage 01
Engagement & Scoping
A call first, under a mutual non-disclosure agreement.

It starts with a conversation. What is in scope, how often you want to hear from us, and how you want it delivered, all agreed before anything runs. We can leave our name off it if you would rather.

A mutual non-disclosure agreement before anything specific is said
Scope set against what your practice actually has
How often and in what form, agreed before we start
We can leave our name off it if you ask
Stage 02
Targeted Reconnaissance
Matched against what your practice actually shows.

Protector Class runs against compromised credential databases, breach repositories, criminal-targeting sources, and publicly exposed infrastructure, matched to the scoped target, not a generic scan.

Breach databases and password dumps
The channels where stolen data is listed and sold
What your domain and systems show publicly
Limited to what you agreed at the start
Stage 03
Analyst-Checked before you see it
Raw Data Becomes Checked before you see it.

Not all exposure data is equal. Protector Class processes raw findings through AI-assisted analysis and human analyst verification, eliminating noise, confirming relevance, and establishing severity before anything reaches you.

Anything that turns out to be nothing is dropped
A person checks anything serious
Ordered by what is most likely to be used
What someone would actually do with each one
Stage 04
Delivery, and what happens after
An encrypted briefing inside seventy-two hours.

What survives checking arrives as a written briefing: where each thing came from, how bad it is, and what to do about it. Continuous monitoring runs for the retained duration; new signals surface on discovery.

Encrypted, inside seventy-two hours
One thing to do per finding, in order
Watching continues for as long as you keep it on
You hear about something new when we find it, not at the next cycle
Deliverables

What lands on your desk.

One way of working. Three ways to take it.

A personal check

A written briefing covering what breaches you appear in, which brokers hold your details, which passwords are out, and where that is being tracators, with a prioritized remediation plan for every finding.

Ongoing cover (monthly or yearly)

For those retained on ongoing coverage. Protector Class continues monitoring your profile after the initial briefing, surfacing new signals as they appear and alerting when your identity surfaces in new sources.

A look at your practice

A full look at what your practice shows publicly: staff passwords that are out, weak points in your systems, and where any of it is being trars, and a full remediation roadmap for your security team.

After the Assessment

Every assessment ends with a step-by-step document your own IT person can work straight from. If you want us to keep watching afterwards, that is Business Monitoring: continuous re-scanning, breach-event alerting, and bundled Executive Protection (personal-exposure removal across US and Canadian data broker sites).

Choose Your Path

Which one fits your practice?

For Individuals
Protector Class Domain Audit

Automated. Submit your email, run a Domain Audit, receive your complete exposure briefing, all in one session. No human involvement required.

Breach database & credential audit
What the data brokers are holding
A check of where stolen data gets traded
What to do, in order
For Organizations
Protector Class Business

We run the whole thing for you: your domain, the passwords that are out, the weak points in your systems, criminal-targeting indicators, and deliver a complete remediation roadmap.

A look at your domain and its subdomains
Staff passwords found in breaches
Weak points in what you have exposed
Full remediation roadmap

Your exposure profile
already exists. We find it first.

Pick where you want to start.