This week
Business
Individual
Partners
Intelligence
How we work
Sign in Check my firm
Attacker’s-eye view · Evidence-grade · Human-verified

The AI defense layer for the world’s businesses.

AI agent swarms now read every business from outside, at machine speed. We read yours first, prove each way in with evidence anyone can re-run, and close it before it is used.

Use your work email at that domain. We send one confirmation link there, and your reading goes to that address only.

Read-only, from outside Proof for every finding Every assessment human-verified Continuous exposure watch
Reading · your-firm.comIllustrative
Ways in open
3
Each with its proof
Open: 3Closed: 0
Email sent in your nameDelivered
Discover_dmarc · p=none
Addresses in breach databases3 found
Validatesource and date on each address
Website software1 open
Closeexact fix written, re-checked until closed
Look-alike domainsMonitored
Monitorre-read every hour
Illustrative firm · last re-checked 17:38 UTCHuman-verified

There’s only one answer to AI-powered attacks: AI-powered defense.

See one finding

One finding, read from outside, proven, human-verified and closed.

Captions available, no sound. Illustrative firm.

Read the transcript
  1. There's only one answer to AI-powered attacks. AI-powered defense.
  2. AI agent swarms read businesses from outside. We read yours first.
  3. What a score-only rating hands you: 62/100 · Grade C · “Improve your email security.” No record behind it. Nothing to re-run. No one signed it. A grade to trust, not a fix. What we hand you: A stranger can send email as harbor-legal.example, and nothing stops it.
  4. Proof, not scores. Every finding carries its record. Re-run it from any terminal. So can your insurer.
  5. Human-verified · inside 72 hours. Every release written to the evidence log.
  6. Re-checked from outside. Forged email: one click, where we reach your DNS host. The exact fix for everything else.
  7. Re-checked every hour, 24/7. Alerts within the hour.
  8. The AI defense layer for the world’s businesses. Proof, not scores. Check my firm · getleaktrace.com
The good news

Anything an attacker can see from outside, we can find and close first.

Attacks on firms like yours still start with something anyone on the internet can see: an email setting that lets forged mail through, a staff password in a breach database, a look-alike domain, an open sign-in page. Each of those can be found from outside before an attacker uses it.

24/7 Monitored day and nightRe-checked every hour on monitoring
1 h First to knowAlerts within the hour on hourly checks

Figures are LeakTrace Research, measured across the firms we have assessed, each with the date it was measured. Read the studies.

How the AI defense layer works

Every way into your firm, found first, proven and closed.

Continuous exposure watch, AI-driven and read from outside, in four stages: Discover, Validate, Close and Monitor. The next machine-speed attack finds the door already shut.

4 steps · click each

Discover every way in

Every way into your firm, discovered from outside the way an attacker’s tools read it. Nothing to install, no access to give.

6Exposure classes watched, from forged email to AI answers
HourlyEmail settings, look-alikes and new host names re-checked, on monitoring
What we monitor
Email impersonationEvery gap that lets a stranger send email as your firm, from SPF and DMARC to DKIM, MTA-STS and more, found and closed
Brand impersonationLook-alike domains caught within the hour they go live, with a takedown drafted
Attack surface discoveryEvery new system exposed on your domain, found as it appears
Exploited vulnerabilitiesFlaws attackers are actively using, matched to your website’s software within a day
Credential exposureYour firm’s addresses in breach data, flagged before the passwords are reused
AI impersonationNumbers and login pages that are not yours, handed to your clients by AI assistants, traced and closed

Validate every finding

The exact record behind each finding, a check anyone can re-run, and human verification before release. Every paid assessment carries a signed record anyone you hand it to can verify in one step.

100%Of paid assessments human-verified before release
72 hFrom confirmation to an approved assessment
Verify a record
Evidence for every findingThe exact record, header or listing behind it
Signed assessment recordDated, and verifiable by anyone you hand it to
Tamper-evident recordEvery approval, alert and DNS change hash-chained and verified daily
Anti-impersonation checkAnyone can confirm in one step that a message really came from us

Close each opening

Forged email, the opening we find most, closes in one click where we reach your DNS host: staged, re-checked, nothing changed until you confirm. Your IT provider gets the exact fix for the rest, re-checked until it is closed.

1 clickProtects your firm against forged email in its name, where we reach your DNS host
Pre-filledThe outside questions on your cyber application
How it works
One-click email fixWhere we can reach your DNS host; the exact records where we cannot
Takedown request draftedFor each live look-alike, for you to send
Patch before it is usedNewly exploited flaws matched to your software, with the fix
Insurance questions pre-filledThe outside questions on your cyber application, with the evidence

Monitor around the clock

Re-checked every hour, 24/7, with alerts within the hour. You are first to know, before a client, a bank or an insurer.

1 hAlerts within the hour on hourly checks, by email, Slack or Teams
24/7Monitored day and night; the same day for daily checks
For firms
Alerts within the hourThe way in, in plain words, within the hour on hourly checks and the same day on daily ones
Slack or TeamsAlerts where your partners already talk, or by email
Board-ready summaryBoard-ready exposure summary, every month
Peer benchmarkYour exposure ranked against firms in your sector, where 30 or more are measured
The ways in that matter most

How firms are hit today, and our answer to each.

We can check three of these seven completely from outside, and three partly. The last one needs someone to look inside your systems, and we tell you that plainly.

The way inOur figureWhat we doCoverage
Email forged in your nameFake invoices and changed bank details, sent as you.
8 in 10professional firms cannot stop a stranger sending email in their name.LeakTrace Research · Measured 19 Sep 2026
  • Discover: the setting that lets forged mail through.
  • Validate: with the record, re-run from any terminal.
  • Close: in one click where we reach your DNS host; the exact record where we cannot.
  • Monitor: re-checked every hour.
CoveredFrom outside, end to end.
Stolen or reused passwordsA firm address in a breach database, and a password used again.
2 in 10professional firms have a shared address such as info@ in monitored breach databases.LeakTrace Research · Measured 30 Sep 2026
  • Discover: which firm addresses appear, with the source and date of each.
  • Monitor: re-checked every day.
Covered
Look-alike domains used to impersonate youA name one letter off yours, registered and live.
4 in 10professional firms have a look-alike of their domain registered and live.LeakTrace Research · Measured 30 Sep 2026
  • Discover: each one found and named.
  • Close: a takedown request drafted, ready for you to send.
  • Monitor: watched every hour.
Covered
Known flaws attackers are exploiting nowNewly listed flaws in the software a website runs.
1,734Actively exploited flaws we watch forCounted from our own records
  • Discover: matched to the software your website shows, within a day of being listed.
  • Monitor: every new listing, every day.
PartlyYour website only.
Exposed sign-in pages and remote accessPortals, admin pages and remote-access ports anyone can reach.
  • Discover: which sign-in pages answer from outside, and which remote-access ports are open on your website’s host.
PartlyWe cannot see from outside whether multi-factor sign-in is switched on. Your IT provider can, and we tell you to ask them.
AI-written phishing and impersonationEmails that AI tailors to the person who receives them.
  • Close: email forged in your name, as above.
  • Validate: what AI assistants tell clients about your phone number and client login, checked against your own site; each wrong answer traced to its source, with the correction.
PartlyA convincing email sent from some other address goes straight to your people, and no setting of yours can block it. We tell you that plainly.
RansomwareIt usually gets in through one of the openings above.
  • Close: those outside openings, one by one.
Not visible from outsideWe cannot see your backups or internal systems from outside, and we tell you so.

Figures are LeakTrace Research, measured across the firms we have assessed, each with its date. Everything here is read from outside, from public sources only.

The rules you answer to

Every finding, mapped to the rule you answer to.

A pen test covers what it is scoped to, once. Every assessment runs up to 37 outside checks, with email settings, look-alikes and new host names re-checked every hour on monitoring. We hand you the record your regulator, your insurer and your partners ask for.

Law

FindingEmail forged in your name
The rule it touchesABA Model Rule 1.6 and FTC Act Section 5The duty to protect client information; your state bar adopts its own version.
What we hand youThe dated record, the fix (one click where we reach your DNS host) and the outside re-check that proves it closed.
FindingFirm addresses in breach databases
The rule it touchesABA Model Rule 1.6 and state breach notification lawsNotice when personal information is exposed; timing varies by state.
What we hand youWhich addresses, the source and date of each, and the record to keep: each password reset and multi-factor sign-in confirmed, dated.
FindingInsurer asks: Does your domain enforce DMARC at quarantine or reject?
The rule it touchesYour cyber insurance applicationThe insurer makes its own decision; the answer comes from the record.
What we hand youThe answer pre-filled from the evidence, with the record behind it.

Accounting

FindingFirm addresses in breach databases
The rule it touchesFTC Safeguards Rule, 16 CFR 314.4Multi-factor sign-in for anyone accessing customer information.
What we hand youWhich addresses, the source and date of each, and the record to keep: each password reset and multi-factor sign-in confirmed, dated.
FindingEmail forged in your name
The rule it touchesFTC Safeguards Rule, 16 CFR 314.4A security program that safeguards customer information.
What we hand youThe dated record, the fix (one click where we reach your DNS host) and the outside re-check that proves it closed.
FindingInsurer asks: Are staff email addresses clear of known breach data?
The rule it touchesYour cyber insurance applicationThe insurer makes its own decision; the answer comes from the record.
What we hand youThe answer pre-filled from the evidence, with the record behind it.

Medical

FindingEmail forged in your name
The rule it touchesHIPAA Security Rule, 45 CFR 164.308Administrative safeguards for patient health information.
What we hand youThe dated record, the fix (one click where we reach your DNS host) and the outside re-check that proves it closed.
FindingStaff addresses in breach databases
The rule it touchesHIPAA, 45 CFR 164.404Tell patients of a breach within 60 days of discovery.
What we hand youWhich addresses, the source and date of each, and the record to keep: each password reset and multi-factor sign-in confirmed, dated.
FindingInsurer asks: Do you require multi-factor sign-in for email and remote access?
The rule it touchesYour cyber insurance applicationWe cannot see this from outside, and we tell you so.
What we hand youWhat we did see that bears on it, so the answer you give is your own.

Wealth

FindingEmail forged in your name
The rule it touchesRegulation S-P, for SEC-registered advisers, and FTC Safeguards Rule, where it applies to your firmWritten policies and procedures to safeguard customer records and information, including an incident response program reasonably designed to detect, respond to, and recover from unauthorized access to or use of customer information.
What we hand youThe dated record, the fix (one click where we reach your DNS host) and the outside re-check that proves it closed.
FindingA look-alike of your domain, registered and live
The rule it touchesRegulation S-P, for SEC-registered advisers, and FTC Safeguards Rule, where it applies to your firmAn incident response program reasonably designed to detect, respond to, and recover from unauthorized access to or use of customer information.
What we hand youEach one named, with a takedown request drafted with the evidence.
FindingInsurer asks: Do you keep internet-facing software patched and up to date?
The rule it touchesYour cyber insurance applicationThe insurer makes its own decision; the answer comes from the record.
What we hand youThe answer pre-filled from the evidence, with the record behind it.

Shown for the United States. Only the rules the Rules and Insurance Briefing maps; which one applies depends on your firm, and your briefing names it.

All rules we map
FTC Act Section 5US

Safeguard consumer data. Failures are treated as unfair or deceptive practices.

SEC Regulation S-PUS

SEC-registered advisers and broker-dealers: an incident response program, oversight of service providers, and notice to affected customers no later than 30 days after becoming aware.

FTC Safeguards RuleUS

Tax preparers, mortgage brokers and other financial institutions: multi-factor sign-in, and notice to the FTC within 30 days of a breach of 500 or more people.

HIPAAUS

Covered clinics: protect patient health information and tell patients within 60 days of discovery.

State breach notification lawsUS

Notify affected people when personal information is exposed. Timing varies by state.

201 CMR 17.03US

Anyone holding a Massachusetts resident's data: review the written security program every year.

PIPEDACA

Safeguards appropriate to the sensitivity of the information. Notify of a breach that creates a real risk of significant harm, and keep a record of every breach for 24 months.

Alberta PIPACA

Prompt notice to the Commissioner where harm is a real risk.

BC PIPACA

Reasonable security arrangements against unauthorized access.

PHIPACA

Ontario health custodians: protect patient information and notify the Information and Privacy Commissioner of breaches.

The rules for your country come first. We list a rule only where we can say honestly whether it applies to you.

The difference

Proof, not scores.

Every finding we show carries the record behind it and a check anyone can re-run, your insurer included. Human-verified before it reaches you.

Counted from our own records as of 6 Oct 2026, 17:38 UTC, refreshed hourly. Illustrative items are labelled.
196.2K

Look-alike domains checked

Brand impersonation caught within the hour it goes live, on monitoring.

186.1K

Certificate records read

New host names on your domain found as they are certificated, re-checked hourly on monitoring.

2,621

Firms read from outside

Each read the way an attacker’s tools read it, from public sources, logged into nothing.

1 clickTo protect your name against forged email, where we can reach your DNS host
Newest on the exploited list
Citrix NetScalerAdded 4 Oct · Citrix NetScaler Improper Restriction o…
Zammad GmbH ZammadAdded 2 Oct · Zammad GmbH Zammad Session Fixation Vul…
Zammad GmbH ZammadAdded 2 Oct · Zammad GmbH Zammad Improper Privilege M…
1 dayTo match a newly exploited flaw to the software a monitored firm’s site shows
5,257Public disclosures indexed, each with the way in. Updated daily
2,601Firms whose addresses were checked against monitored breach databases
72 hFrom confirmation to a human-verified assessment
Illustrative
001$ dig TXT _dmarc.your-firm.com
002;; ANSWER: 0
003$ dig TXT your-firm.com
004"v=spf1 include:mail ~all"
005$ dig +short MX your-firm.com
0Log-ins to any client system. Every check is a public lookup, like this one.
The latest · 6 Oct 2026

How they got in this week, and what we watch for you.

United StatesPublic source2 Oct 2026SecurityWeek

US think tanks and universities

How they got in
Email made to look like it came from a trusted sender.
What we watch
Whether anyone can send email that passes as your domain.
DenmarkPublic source3 Oct 2026BleepingComputer

Technical University of Denmark

How they got in
Stolen or reused passwords.
What we watch
Your firm's addresses in monitored breach databases.
CanadaPublic source2 Oct 2026Global News

Kingston Police

How they got in
Stolen or reused passwords.
What we watch
Your firm's addresses in monitored breach databases.
LeakTrace Research

What anyone can see about professional businesses, measured.

See the research
  1. 9 in 10

    dental practices cannot stop a stranger sending email in their name.

    LeakTrace Research · measured 19 Sep 2026 · 88.8%, read from each firm's public mail records
  2. Nearly5 in 10

    accounting firms have a look-alike of their domain registered and live.

    LeakTrace Research · measured 30 Sep 2026 · 46.4%, common misspellings checked in public DNS
  3. 3 in 10

    accounting firms have a shared address such as info@ in monitored breach databases.

    LeakTrace Research · measured 30 Sep 2026 · 28.9%, shared addresses checked in monitored breach databases
What forged email already costs
$3,046,598,558

Reported losses to business email fraud in the United States in one year. 24,768 complaints, 2025.

Source: FBI IC3 2025 Internet Crime Report, business email compromise, 2025. Reported losses only.

Who it is for

For the firms that hold other people’s money and confidences.

Independence

Outside only. Independent, and answerable to you.

We read what your firm shows to the public internet, and nothing else. What we find goes to you alone.

Your IT provider keeps your systems running. We hand them an independent list, each finding with its evidence and the change that closes it.

A penetration test needs access to try to break in. We read only what is already public, and log into nothing.

Your insurer’s scan feeds your premium. We show you the same outside view first, so you walk into renewal knowing the answers.

Access neededNone
Log-ins to your systemsNone
Mutual NDAAvailable on request
Questions
Nothing of yours. We read what your firm shows to the public internet, the way an attacker’s tools would.

See your firm the way an attacker’s AI sees it.

Your outside reading: your email setup, your website, look-alike domains, staff passwords in breach databases, your sign-in pages and what AI assistants say about you, each with the evidence and the fix. Free, read-only, and sent only to your work email.

What we readPublic sources only
Who sees itYou alone
Delivery72 hours from confirmation
Mutual NDAAvailable on request

A person reads every request. We reply within one business day from [email protected]. Privacy

The incidents that reach firms like yours, and what to check, in one email. Sign up