The AI defense layer.
Attackers use AI to find a way in. LeakTrace finds it first and closes it.
Two ways AI is used against you today.
Attackers use AI to write convincing fraud.
Fake invoices, cloned voices and messages that sound like you, tailored from what is public about your business.
How it works
Your free reading shows whether anyone can forge mail in your name.
Attackers use AI to research you.
It reads your website and staff pages to learn who approves payments and who your suppliers are.
Organised fraud groups also run AI built without safety limits.
Your free reading shows what an attacker can see from outside.
Reported losses to business email compromise in the United States in one year: a scam that uses a hijacked or imitated business email account to get a payment sent. 24,768 complaints, 2025.
Source: FBI IC3 2025 Internet Crime Report, 2025. Reported losses only.
There’s only one answer to AI-powered attacks: AI-powered defense.
A forged invoice, the attacker’s AI behind it, six ways in, and each one found, with its fix, and checked again from outside.
Words on screen, no voice. Illustrative firm.
Read the transcript
- Invoice 2217: new bank details. From [email protected]. Paid · $48,200. Your firm never sent it.
- How did they get in? Attacker’s AI agent: Attackers now send AI agents. Find firms to impersonate. 4,000 firms read. Copy of your address: set up. (harbourview-llp-pay.example) Invoice written in the partner’s style. Sent. (Illustration.)
- Copy of your address: set up. (harbourview-llp-pay.example) Mail from it looks like yours.
- Staff emails in leaked lists from hacks.
- A remote-access door, open to the internet.
- A private file, readable online.
- Software with a public weakness.
- Email anyone can fake.
- Six ways in.
- Their AI agents check every door.
- At every firm.
- LeakTrace checks from outside.
- Never your email or files.
- LeakTrace finds each one.
- Hands you the exact fix. Step by step, for whoever runs IT.
- Checks again from outside: closed.
- A copy isn’t yours to switch off.
- LeakTrace watches it, and every new one.
- LeakTrace checks for new copies every hour.
- The AI defense layer. See what’s open at your firm. Enter your website. Results by email. Free. Check my firm · getleaktrace.com
Anything an attacker can see from outside, we can find and close first.
Attacks on businesses like yours still start with something anyone on the internet can see: a mail setting that lets forgeries through, a staff password in a breach database, a look-alike domain, an open sign-in page. Each of those can be found before an attacker uses it.
Every finding, proven.
Each finding we show carries the record behind it and a check anyone can re-run, your insurer included. Human-verified before it reaches you.
Look-alike domains checked
Brand impersonation caught within the hour it goes live, on monitoring.
Certificate records read
New host names on your domain found as they are certificated, re-checked hourly on monitoring.
Firms read from outside
Each read the way an attacker’s tools read it, from public sources, logged into nothing.
Show moreShow less
Every way in, found first and closed.
Agent against agent: attackers point AI at firms, and LeakTrace reads them first. Continuous exposure watch, AI-driven and read from outside, in four stages: Discover, Validate, Close and Monitor. The next machine-speed attack finds the door already shut.
What each AI agent does, and what it can never do Our AI agents work from outside only. They never log in, never install anything, and never touch your internal systems. The one change they can make, to your email records, happens only when you approve it.
1 Discover1 Discover
Discover every way in
Found from outside, the way an attacker’s tools read it. Nothing to install, no access to give.
On a paid assessment, the Discover AI agent reads what your firm shows the public internet with fixed checks, records each finding with its evidence and chooses follow-up checks.
2 Validate2 Validate
Validate every finding
The exact record behind each finding, a check anyone can re-run, and human verification before release. Every paid assessment carries a signed record anyone you hand it to can verify in one step.
Every finding is kept with the record that proves it. A person reads the assessment before release.
3 Close3 Close
Close each opening
Forged email, the opening we find most, closes in one click where we reach your DNS host: staged, re-checked, nothing changed until you confirm. You get the fix for the rest, step by step, and we re-check until it is closed.
On a paid assessment, the Close AI agent gives you the fix for each finding and, for an email record, sets the steps out with your DNS host's own screens where we hold its guide. When you mark a fix done, AI chooses when to re-check, and only a fresh outside read closes it.
4 Monitor4 Monitor
Monitor around the clock
Re-checked every hour, 24/7, with alerts within the hour. You are first to know, before a client, a bank or an insurer.
On monitoring, fixed checks re-check your email settings, look-alike domains and new host names every hour, and everything else every day. The Monitor AI agent puts first the change that needs you, with a plain reason when it has one.
The ways in today, and our answer to each.
We can check three of these seven completely from outside, and three partly. The last one needs someone to look inside your systems, and we tell you that plainly.
- Discover: the setting that lets forged mail through.
- Validate: with the public record behind it, dated and checkable by anyone.
- Close: in one click where we reach your DNS host; the exact record where we cannot.
- Monitor: re-checked every hour.
- Discover: which of your addresses appear, with the source and date of each.
- Monitor: re-checked every day.
- Discover: registered domains made from your name, each one we raise with its public record.
- Validate: only what we observed, and one question: is it yours?
- Close: a takedown request drafted, ready for you to send.
- Monitor: re-checked every hour for new ones.
- Discover: matched to the software your website shows, within a day of being listed.
- Monitor: each new listing, daily.
- Discover: which sign-in pages answer from outside, and which remote-access ports are open on your website’s host.
- Close: forged mail in your name, as above.
- Close: those outside openings, one by one.
Figures are LeakTrace Research, measured across the businesses we have assessed, each with its date. Everything here comes from public sources only.
How they got in this week, and what we watch for you.
South Carolina power company
Uranium Finance
What anyone can see about professional businesses, measured.
-
Nearly9 in 10
dental practices cannot stop a stranger sending email in their name.
LeakTrace index, readings to 8 October 2026 · 88.4%, read from each firm's public mail records →
Show allShow less
-
Nearly9 in 10
dental practices cannot stop a stranger sending email in their name.
LeakTrace index, readings to 8 October 2026 · 88.4%, read from each firm's public mail records → -
Nearly5 in 10
accounting firms have a look-alike of their domain registered and live.
LeakTrace Research · measured 30 Sep 2026 · 46.4%, common misspellings checked in public DNS → -
3 in 10
accounting firms have a shared address such as info@ in monitored breach databases.
LeakTrace Research · measured 30 Sep 2026 · 28.9%, shared addresses checked in monitored breach databases →
Every finding, mapped to the rule you answer to.
A pen test covers what it is scoped to, once. Every assessment runs up to 37 outside checks. We hand you the record your regulator, your insurer and your partners ask for.
Show allShow less
Law
Accounting
Medical
Wealth
Shown for the United States. Only the rules the Rules and Insurance Briefing maps; which one applies depends on your business, and your briefing names it.
All rules we map
Safeguard consumer data. Failures are treated as unfair or deceptive practices.
SEC-registered advisers and broker-dealers: an incident response program, oversight of service providers, and notice to affected customers no later than 30 days after becoming aware.
Tax preparers, mortgage brokers and other financial institutions: multi-factor sign-in, and notice to the FTC within 30 days of a breach of 500 or more people.
Covered clinics: protect patient health information and tell patients within 60 days of discovery.
Notify affected people when personal information is exposed. Timing varies by state.
Anyone holding a Massachusetts resident's data: review the written security program every year.
Safeguards appropriate to the sensitivity of the information. Notify of a breach that creates a real risk of significant harm, and keep a record of every breach for 24 months.
Prompt notice to the Commissioner where harm is a real risk.
Reasonable security arrangements against unauthorized access.
Ontario health custodians: protect patient information and notify the Information and Privacy Commissioner of breaches.
The rules for your country come first. We list a rule only where we can say honestly whether it applies to you.
For those who hold other people’s money and confidences.
Show allShow less
Lawyers
Trust accounts, privileged files and the closing email a forged invoice copies.
For lawyers→ AccountingAccountants
Client portals, tax season and the payment request that looks like yours.
For accountants→ Dental and clinicsDental and clinics
Patient records and booking email.
For dental practices→ Wealth and advisersAdvisers and wealth managers
Client money, and the instructions that move it.
For advisers→ InsuranceInsurance brokerages
Policyholder records, renewals and the address clients trust.
For brokerages→ Real estateReal estate brokerages
Deposits, closing funds and the message that tells a buyer where to send them.
For brokerages→Find the way in first. Then close it.
Not a pen test. We attack nothing, install nothing and need no access. We keep watching from outside, and each finding comes with its evidence and the fix that closes it.
Outside only. Independent, and answerable to you.
We read what you show the public internet, and nothing else. What we find goes to you alone.
Your IT provider keeps your systems running. We read your domain independently and show you what is open, each finding with its evidence.
A penetration test needs access to try to break in. We read only what is already public, and log into nothing.
Your insurer’s scan can feed your premium, and we do not see it. We show you first what anyone can see, so you walk into renewal knowing your own answers.
See your firm the way an attacker’s AI sees it.
Your outside reading: your email setup, your website, look-alike domains, staff passwords in breach databases and your sign-in pages, each with its evidence; the fix steps and an AI security agent on your dashboard come with the assessment. Free, read-only, and sent only to your work email.
A person will read it and reply within one business day from [email protected].
- We check your email setup, website, look-alike domains, breach databases and sign-in pages from outside.
- We validate every finding, with a check you can run.
- You decide what to fix, with the evidence in front of you.
Your firm's own domain, nothing illustrative.
What happens if you go ahead. More at getleaktrace.com/see-it-first/.
Read the transcript
- 72 hours. One domain. Nothing to install.
- Discover. Every way in, found from outside.
- Validate. Proof, not scores. Dated and checkable by anyone.
- Close. Forged email: one click, where we reach your DNS host and you approve it.
- You get the fix for the rest, step by step, and we re-check until it is closed.
- Monitor. On monitoring: re-checked every hour, 24/7. Alerts within the hour.
- Every paid assessment is human-verified before release.
- The AI defense layer for businesses. See it first. getleaktrace.com/see-it-first/
The incidents that reach businesses like yours, and what to check, in one email. Sign up