This week
Business
Individual
Partners
Intelligence
How we work
Sign in Check my firm
AI-driven · Evidence-grade exposure management

Attackers read your firm from outside. We read it first.

AI lets anyone find a forgeable email domain, a look-alike or an exposed login in minutes. LeakTrace watches every way into your firm the internet can see, proves every finding and closes it before it is used.

One public DNS lookup, read-only. Nothing you type is kept.

Read-only, from outside Proof for every finding Every assessment approved by a person Continuous exposure watch
The outside watch · LiveUpdated hourly
Look-alike domains checked
191.4K
And counting
Certificate records read184.7K
Actively exploited flaws watched1,734
Public disclosures indexed5,252
Firms read from outside2,557
Counted from our own records, 4 Oct, 17:45 UTCRead-only
The difference

Proof, not scores.

Every finding we show carries the record behind it and a check anyone can re-run, your insurer included. A person signs off before it reaches you.

Finding 01 · harbor-legal.exampleIllustrative · fictional firm
Finding
High

A stranger can send email as harbor-legal.example, and nothing stops it.

A forged payment request in the firm’s name could reach its clients’ inboxes.

EvidenceThe record, read from outside
Record: _dmarc.harbor-legal.example · TXT
$ dig TXT _dmarc.harbor-legal.example +short
"v=DMARC1; p=none"
Observed: p=none asks receiving servers to take no action, so mail forged in the firm’s name is not stopped.

Re-run it from any terminal. So can your insurer.

Sign-off
Approved by a personWithin 72 hours

Every paid assessment is read and approved by a person before it is released to the firm.

Fix
Switched on in one click"v=DMARC1; p=reject"Re-checked from outside

Where we can reach the firm’s DNS host. Where we cannot, the exact record to publish, re-checked until it is closed.

  1. 01Proof, not scoresEvery finding carries its record and a check anyone can re-run.
  2. 02A person signs offEvery paid assessment approved by a person before release, inside 72 hours.
  3. 03We close itForged email closed in one click where we reach your DNS host; the exact fix for the rest.
  4. 04First to knowRe-checked every hour, 24/7, on monitoring, with alerts within the hour.
  5. 05IndependentPaid by no one who sells the fixes, so every finding is there because it is true.

A new AI world is here

The good news

The ways in are knowable, and closable.

Attacks on firms like yours still start from what the internet can see, and every one of those openings can be found from outside first.

24/7 Watched day and nightRe-checked every hour on monitoring
1 h Told firstAlerts within the hour on hourly checks

Figures are LeakTrace Research, measured across the firms we have assessed, each with the date it was measured. Read the studies.

Why LeakTrace

Preemptive, not after the fact. Every way into your firm, found first, proven and closed.

See the outside watch
191.4K

Look-alike domains checked

Brand impersonation caught within the hour it goes live, on monitoring.

184.7K

Certificate records read

New host names on your domain found as they are certificated, re-checked hourly on monitoring.

2,557

Firms read from outside

Each read the way an attacker’s tools read it, from public sources, logged into nothing.

Counted from our own records as of 4 Oct 2026, 17:45 UTC, refreshed hourly.

Illustrative · fictional firm

One morning on the watch. Found, told, proven, closed.

What a partner sees on a fictional firm, harbor-legal.example, as the watch finds a way in and closes it.

  1. 01Exposure Discovery
  2. 02Early Warning
  3. 03Validated Evidence
  4. 04One-Click Remediation

Introducing the outside watch

Continuous exposure watch, AI-driven and read from outside, in four stages: Exposure Discovery, Early Warning, Validated Evidence and One-Click Remediation. The next machine-speed attack finds the door already shut.

Watch every way in

Every way into your firm, read from outside the way an attacker’s tools read it. Nothing to install, no access to give.

6Exposure classes watched, from forged email to AI answers
HourlyEmail settings, look-alikes and new host names re-checked, on monitoring
What we monitor
Email impersonationEvery gap that lets a stranger send email as your firm, found and closed
Brand impersonationLook-alike domains caught within the hour they go live, with a takedown drafted
Attack surface discoveryEvery new system exposed on your domain, found as it appears
Exploited vulnerabilitiesFlaws attackers are actively using, matched to your website’s software within a day
Credential exposureYour firm’s addresses in breach data, flagged before the passwords are reused
AI reputationWhat AI assistants tell clients about your firm, and every wrong answer flagged

Tell you first

You hear it from us, before a client, a bank or an insurer does.

1 hAlerts within the hour on hourly checks, by email, Slack or Teams
24/7Watched day and night; the same day for daily checks
For firms
Alerts within the hourThe way in, in plain words, within the hour on hourly checks and the same day on daily ones
Slack or TeamsAlerts where your partners already talk, or by email
Board-ready summaryBoard-ready exposure summary, every month
Peer benchmarkYour exposure ranked against firms in your sector, where 30 or more are measured

Prove every finding

The exact record behind each finding, and a signed assessment record anyone you hand it to can verify in one step.

100%Of paid assessments approved by a person before release
72 hFrom confirmation to an approved assessment
Verify a record
Evidence for every findingThe exact record, header or listing behind it
Signed assessment recordDated, and verifiable by anyone you hand it to
Tamper-evident recordEvery approval, alert and DNS change hash-chained and verified daily
Anti-impersonation checkAnyone can confirm in one step that a message really came from us

Close the way in

Forged email, the opening we find most, closes in one click: staged, re-checked, nothing changed until you confirm. Your IT provider gets the exact fix for the rest.

1 clickProtects your firm against forged email in its name
1,734Actively exploited flaws watched for, matched to your website’s software on monitoring
How it works
One-click email fixWhere we can reach your DNS host; the exact records where we cannot
Takedown request draftedFor each live look-alike, for you to send
Patch before it is usedNewly exploited flaws matched to your software, with the fix
Insurance questions pre-filledThe outside questions on your cyber application, with the evidence

So you see it first, at speed and scale.

Patch before it is used against you. Take down a look-alike before it sends its first invoice. Close the way in before anyone walks through it.

Counted from our own records as of 4 Oct 2026, 17:45 UTC. Illustrative items are labelled.
1 clickTo protect your name against forged email, where we can reach your DNS host
Newest on the exploited list
Citrix NetScalerAdded 4 Oct · Citrix NetScaler Improper Restriction o…
Zammad GmbH ZammadAdded 2 Oct · Zammad GmbH Zammad Session Fixation Vul…
Zammad GmbH ZammadAdded 2 Oct · Zammad GmbH Zammad Improper Privilege M…
1 dayTo match a newly exploited flaw to the software a monitored firm’s site shows
5,252Public disclosures indexed, each with the way in. Updated daily
2,538Firms whose addresses were checked against monitored breach databases
72 hFrom confirmation to an assessment a person has approved
Illustrative
001$ dig TXT _dmarc.your-firm.com
002;; ANSWER: 0
003$ dig TXT your-firm.com
004"v=spf1 include:mail ~all"
005$ dig +short MX your-firm.com
0Log-ins to any client system. Every check is a public lookup, like this one.

Built for the AI era. Enterprise-grade, for firms of every size.

AI reputation

What AI assistants tell your clients about you

We ask an AI assistant what it says about your firm, check the phone number it gives against the pages it cites, and flag a wrong answer.

One click

Forged-email protection, switched on

From outside, where we can reach your DNS host. Staged, re-checked, nothing changed until you confirm.

Within a day

Exploited flaws matched to your website

Newly listed, actively exploited flaws matched to the software your site shows.

Verified daily

A tamper-evident record

Every approval, alert and DNS change hash-chained, and the chain verified every day.

Every look-alike

A takedown request, drafted

For every live look-alike of your domain, ready for you to send.

Pre-filled

Your insurance questions, answered

The outside questions on your cyber application, pre-filled with the evidence behind each answer.

15 seconds

A personal video of your own finding

Where your firm has a forged-email finding, it is on screen, its proof re-run the day the video is made.

What forged email already costs
$3,046,598,558

Reported losses to business email fraud in the United States in one year. 24,768 complaints, 2025.

Source: FBI IC3 2025 Internet Crime Report, business email compromise, 2025. Reported losses only.

The latest · 4 Oct 2026

How they got in this week, and what we watch for you.

Public source2 Oct 2026SecurityWeek

Universities and private organizations in US

An Iranian national linked to the Mabna Institute was extradited to the US for participating in massive cyber intrusions targeting hundreds of organizations. The campaign affected 144 US universities, dozens of companies, and federal...

Public source3 Oct 2026BleepingComputer

Technical University of Denmark

How they got in
Stolen or reused passwords.
What we watch
Your firm's addresses in monitored breach databases.
Public source2 Oct 2026SecurityWeek

US think tanks and universities

How they got in
Email made to look like it came from a trusted sender.
What we watch
Whether anyone can send email that passes as your domain.

Every finding mapped to the rule you answer to

FTC Act Section 5US

Safeguard consumer data. Failures are treated as unfair or deceptive practices.

FTC Safeguards RuleUS

Tax preparers, mortgage brokers and other financial institutions: multi-factor sign-in, and notice to the FTC within 30 days of a breach of 500 or more people.

HIPAAUS

Covered clinics: protect patient health information and tell patients within 60 days of discovery.

State breach notification lawsUS

Notify affected people when personal information is exposed. Timing varies by state.

201 CMR 17.03US

Anyone holding a Massachusetts resident's data: review the written security program every year.

PIPEDACA

Safeguards appropriate to the sensitivity of the information. Notify of a breach that creates a real risk of significant harm, and keep a record of every breach for 24 months.

Alberta PIPACA

Prompt notice to the Commissioner where harm is a real risk.

BC PIPACA

Reasonable security arrangements against unauthorized access.

PHIPACA

Ontario health custodians: protect patient information and notify the Information and Privacy Commissioner of breaches.

Your country’s rules first. Only the rules the Rules and Insurance Briefing maps, each listed only where its applicability can be stated honestly.

Independence

Outside only. Independent, and answerable to you.

We read what your firm shows to the public internet, and nothing else. What we find goes to you alone.

Your IT provider keeps your systems running. We hand them an independent list, each finding with its evidence and the change that closes it.

A penetration test needs access to try to break in. We read only what is already public, and log into nothing.

Your insurer’s scan feeds your premium. We show you the same outside view first, so you walk into renewal knowing the answers.

Access neededNone
Log-ins to your systemsNone
Mutual NDAAvailable on request
Questions
Nothing of yours. We read what your firm shows to the public internet, the way an attacker’s tools would.

The incidents that reach firms like yours, and what to check, in one email.

One email when a briefing is published. Unsubscribe in one click. Privacy

See what your firm looks like from outside.

Your outside reading: every way in we can see, found before anyone uses it. Free, read-only, sent only to you.

What we readPublic sources only
Who sees itYou alone
Delivery72 hours from confirmation
Mutual NDAAvailable on request

A person reads every request. We reply within one business day from [email protected]. Privacy