Business
Individual
Partners
Intelligence
How we work
Sign in Check my firm
IT providers · The outside watch for your firm

Hand every client the outside view, proved. Your team closes it.

Each client you look after shows the internet its mail settings, look-alike domains and sign-in pages. We read every one from outside first, prove each finding with the check your engineers can re-run, and hand over the exact fix, re-checked until it is closed.

Attackers now use AI to read a firm from outside the way a search engine does: the website, directories, search results and what AI assistants say. Every finding we hand you is human-verified before your assessment is released.

Outside reads onlyNot a pen testHuman-verified72 hours to your documents
Rules that apply to youMapped per finding
FTC Act Section 5
Unfair or deceptive security practices
State breach notification laws
Notice to affected residents
Also in Canada
PIPEDA Principle 4.7, PIPEDA s. 10.1 and 10.3, Quebec Law 25
Each finding mapped to the rule it touches in the Rules and Insurance Briefing, so you can show your regulator what you checked and fixed.
Rules that apply to IT providers

The reporting deadlines that apply to IT providers.

US, every state
Varies by state
State breach notification laws

Notify affected residents when certain personal information is breached. Timing and content vary by state.

Canada, federal
As soon as feasible
PIPEDA

Report a breach that creates a real risk of significant harm to the Privacy Commissioner, and tell the people affected.

Quebec
Promptly
Quebec Law 25

Notify the Commission d'accès à l'information and the people concerned of an incident that risks serious injury, and keep a register of every confidentiality incident.

Your deadline
Varies by state
State breach notification laws

A summary of published rules, not legal advice. The Rules and Insurance Briefing names the rules that apply to your firm.

With your clients

Your clients trust you with every system they run. An opening on a client domain you look after is the one they hold against you, so see it before they do.

01 · This week in IT providers · 5 Oct 2026

What attackers used this week, and what we check for it.

2 Oct 2026 · SecurityWeek
Universities and private organizations in US

An Iranian national linked to the Mabna Institute was extradited to the US for participating in massive cyber intrusions targeting hundreds of organizations. The …

3 Oct 2026 · BleepingComputer
Technical University of Denmark
How they got in
Stolen or reused passwords.
What we check
Your firm's addresses in monitored breach databases.
2 Oct 2026 · SecurityWeek
US think tanks and universities
How they got in
Email made to look like it came from a trusted sender.
What we check
Whether anyone can send email that passes as your domain.
02 · What you receive

Human-verified. The full outside watch on your firm, the proof for every finding, and the fix.

1
Owner Summary and Action Brief
For the owner
2
Technical Evidence and Findings
For your IT provider
3
Rules and Insurance Briefing
Statutory mapping
4
Signed Assessment Record
Dated attestation
A 10-minute walkthroughWith the person who reviewed and signed your assessment.
The first month of monitoringYour domain and firm addresses watched 24/7: email settings, look-alikes and new host names re-checked every hour, with an alert within the hour to a named contact; the rest daily.

We close it: forged-email protection in one click where we can reach your DNS host, the exact records to paste where we can’t, the exact fix for everything else, re-checked until closed. Your evidence pack: an owner summary, the technical evidence for your IT provider, a rules and insurance briefing, and a signed assessment record. It doubles as your insurance renewal evidence pack: the insurer’s questions pre-filled from the evidence, forged-email protection in one click where we reach your DNS host, and, where your firm has a forged-email finding, a personal video of it to forward to the partners and the broker.

03 · Check my firm

See what is open before anyone else does.

We read your firm from outside, find every way in first, and prove each one with a check anyone can re-run. No access, nothing tested, no obligation.

What we readPublic sources only
Who sees itYou alone
Delivery72 hours from confirmation
Mutual NDAAvailable on request
Outside reading requestPrivate
Problem: Enter your firm's name.
Problem: Enter your name.
Problem: Enter a full email address, like [email protected].
Problem: That does not look like a website. Try yourfirm.com.

A person reads every request. We reply within one business day from [email protected]. Privacy