Baseline
An initial inventory of the exposed surface, agreed in writing as the baseline. The team tracks every change from that point on.
SERVICE 02
Continuous monitoring of your published external surface, with a baseline set at the start and every change tracked from there. In-house tooling takes on the repetitive steps and the team validates each alert before it goes out. You get a notification for every confirmed critical finding and a report on how your surface changed.
The remaining sources we watch are part of our method and are not listed here.
Much of what comes in from outside does not arrive through your domain but through a third party in your supply chain. That is why the agreed scope can include the providers your service depends on, watched to the same standard as your own surface.
Every provider enters the scope in writing, and only with whatever authorisation each case calls for.
Monitoring does not replace what you already have deployed: it connects to it. Each deployment is resolved with a bespoke integration, built around the systems your organisation already runs, so their alerts enter the same flow as the rest of the monitoring.
The point is to stop alerts piling up with nobody reviewing them: they come into one flow, someone on the team validates them, and only what is confirmed goes out. The list is not closed. If your environment runs a system that carries signal, it is assessed and agreed in writing before it is integrated.
An initial inventory of the exposed surface, agreed in writing as the baseline. The team tracks every change from that point on.
The team monitors your surface throughout the contracted period. In-house tooling takes on the repetitive steps. CTI coverage extends to forums, marketplaces and the dark web.
The tooling gathers the data. Someone on the team confirms the finding, sets its priority, and only then does the alert go out.
The team reports critical findings as soon as it confirms them. The rest goes into the periodic report, along with how your surface changed.
Continuous monitoring runs on a recurring term. The monitored scope and the reporting frequency are agreed in writing before the work starts.
Your exposed surface and what moves around it. On your side: domains, subdomains and panels that appear, change or disappear against the baseline, internal panels reachable from outside that should not be, files and paths published by mistake, credentials from your organisation leaked elsewhere, and domains registered to look like yours. On the attacker side: phishing campaigns using your brand, forums and channels where access is traded, and the groups active in your sector. We follow how those groups operate so we can reproduce their techniques against the systems we audit before they do, and what we learn from one actor feeds the defence of every other client. The detail of the remaining sources is part of the tooling and is not published.
Monitoring is limited to observing your published surface, with no intrusive testing and no load on your systems. Any active check is agreed in writing, with an execution window and a notification channel.
Tell us which assets you want tested. We reply within 24 hours.