LeakTrace Business  ·  Assessment-Driven  ·  Managed Intelligence

What Anyone Can See
About Your Business.

We show you what anyone can already see about your business from outside, and the fix for each item. Read-only, from public sources, reviewed by a person before release.

This is not a compliance checkbox. Every finding shows how anyone can check it, with a step-by-step fix your IT provider can follow.

Reconnaissance that once took a skilled team weeks now runs on a laptop and a common subscription tool. What your firm shows from outside is visible to anyone who looks.
Method
Read-only
From public sources, from outside
Review
By a person
Before anything is released
Delivery
72 hours
From confirmation
You receive
3 + 1
Three documents and a signed summary
Findings mapped against published rules and guidance:
FTC Safeguards Rule SEC Regulation S-P IRS Circular 230 GLBA HIPAA Security Rule CCPA / CPRA NIST CSF 2.0 PCI DSS
Why Now

Criminals now work at AI speed. Your outside view is what they read first.

Cybercriminals now use AI to generate phishing emails in bulk, spoof invoices with plausible signatures, spin up lookalike domains, and personalize spear-phishing at scale. A firm without its own security team rarely sees that view the way an attacker does. LeakTrace reads it from public sources, a person reviews every finding, and you receive three documents and a signed summary inside 72 hours of confirmation, with the first 30 days of daily re-checks included.

DNS
Free · 15 seconds
Can your domain be spoofed for wire fraud?
Instant DMARC + SPF + DKIM posture check. No signup.
→
$
Free · Sector-filtered
What does one incident cost in your sector?
FBI IC3 + IBM published data. Filter by industry.
→
Your industry · Tuned landing page
This week · 29 Sep 2026

What attackers used this week, and what we check for it.

177 organisations were listed on criminal leak sites in the last 7 days, by 43 different groups. Of these, 46 were in the United States and 5 in Canada.

Source: public ransomware leak-site listings
28 Sep 2026DataBreaches.net

Telecommunications companies

A former U.S. Army soldier was sentenced to 70 months in prison for hacking into the databases of at least 10 organizations, including telecommunications companies, and attempting to extort over $1 million. The threat …

How they got in
Stolen or reused passwords.
What we check
Staff addresses present in monitored breach databases.
28 Sep 2026CBC

Health P.E.I.

Health P.E.I. announced that personal information belonging to approximately 234,000 individuals was compromised in a data breach. The incident occurred through service provider Maximus Canada, where an unauthorized person accessed a...

How they got in
A supplier or vendor that was compromised first.
What we check
The outside services your domain depends on.
28 Sep 2026TechCrunch

A grandfather fooled by a cloned voice

An individual was scammed into paying a ransom after receiving a phone call featuring an AI-generated deepfake voice impersonating his brother. The caller claimed the brother had been kidnapped, leading the victim to pay …

How they got in
A cloned voice or video of a real person.
What we check
Public audio, video and accounts using a principal's name.
Breach Reference

Recent disclosed breaches your peers were hit by

Public breach reference. If your business connects to any of these vendors, suppliers, or platforms, review your exposure below.

The Threat Reality

What Gets Read
Before Anyone Notices

The scouting, credential checks, infrastructure mapping and staff profiling happen from outside, long before any alert fires.

Scenario 01
One Employee. One Reused Password. Your Entire System.

One employee reuses a password from an old breach. An attacker tests it at 3am. It works. They're in your email system, reading client files, forwarding invoices, before anyone notices anything unusual.

$4.44M Global average cost of a data breach. IBM Cost of a Data Breach Report, 2025
Scenario 02
A Fake Email From Your CFO. A Wire Transfer. Gone.

Your CFO is on LinkedIn. Your domain is publicly registered. An AI tool drafts a convincing spoofed email in under a minute. No hacking involved, just your publicly available information, used against you.

$3.05BLost to Business Email Compromise in 2025. FBI Internet Crime Report
Scenario 03
The Ransomware Was Planned Six Months Ago.

By the time ransomware appears, the attacker has been inside for months, mapping your infrastructure, confirming your backups, and sizing the ransom demand before making a move.

The AI Threat Shift

The Threat Has Changed.
Most Defenses Have Not.

The tools your business relies on, spam filters, employee training, perimeter firewalls, were designed for a threat landscape that no longer exists. AI has fundamentally changed how attacks are constructed. Most defenses haven't been updated to match.

LeakTrace was built for the current threat landscape, not the one from 2019.
AI-generated phishing now reads like legitimate communication, with none of the spelling mistakes staff were trained to spot.
AI voice cloning enables live executive impersonation using audio harvested from public sources. Phone verification is no longer reliable.
Automated scanning tools probe internet-connected systems at scale, around the clock. The question is whether you know what they are finding before an attacker acts on it.
33%
Year-over-year increase in internet crime losses, 2023 to 2024
FBI IC3, Internet Crime Report 2024
The Assessment

The LeakTrace
Business Assessment

We read your domain the way an attacker would. Every finding is documented, scored, and paired with a specific action, and every finding carries the command or public source that proves it, so anyone can re-run it. Leadership gets plain language. Your IT contact gets technical detail.

Assessment Category
What Attackers Find
LeakTrace Delivers
Domain & Subdomain Exposure
Public DNS records, certificates, and services visible from outside
Outside view of your domain with a fix priority for each item
Employee Credential Exposure
Staff addresses present in monitored breach databases
Per-address list of breach records with reset steps
Infrastructure Vulnerabilities
Services and admin panels visible in public internet indexes, outdated software, misconfigurations
Severity-ranked vulnerability list with remediation steps
Ransomware & Business Email Compromise Risk
Executive name mapping, domain spoofing vectors, Business Email Compromise attack surface
BEC risk score with domain hardening recommendations
Client-Side Secret Exposure
Hardcoded API keys in JavaScript, exposed configuration files, public source repositories
Identified secrets with rotation sequence and pipeline-level prevention
Forgotten Asset Discovery
Subdomain takeover risk, dangling DNS records, public cloud storage, Certificate Transparency log analysis
Full forgotten-asset inventory with DNS hygiene plan
Outdated Front-End Libraries
JavaScript libraries with documented CVEs, end-of-life frameworks, missing integrity controls
Per-library upgrade path your IT provider can follow
Remediation Roadmap
All findings across every category, ranked by exploitation risk
Prioritized action plan, one step per finding, plain language
What You Receive
Three Documents and a Signed Summary. Delivered Inside 72 Hours of Confirmation.

No jargon in the Owner Summary and Action Brief. Shareable with leadership, your insurer, or your regulator. The first 30 days of daily re-checks are included.

LeakTrace is independent. We sell no remediation or implementation, so we have no stake in what we find.

Owner Summary and Action Brief (executive brief), in plain language
0-100 risk score from our proprietary scoring model, with severity breakdown
Technical Evidence and Findings (for your IT provider), with a step-by-step fix for every finding
Rules and Insurance Briefing (statutory mapping)
Signed Assessment Record (dated attestation)
Optional walkthrough with the analyst who ran it. We do not perform the fixes.
Your Private Dashboard

After delivery you receive access to a private dashboard with your documents and findings. For the first 30 days your domain is re-checked daily from outside, with an alert the day something changes.

Delivered inside 72 hours of confirmation. That window is a commitment.
Request Your Assessment
The Record

A Completed Assessment
Is Evidence.
Use It As Such.

A dated, signed record that you looked at your outside view and acted on what it showed answers the security question a client, an insurer or a regulator asks.

In law, medicine, accounting and finance, clients ask how their data is protected. The Signed Assessment Record is written for the person you answer to.
Signed Assessment Record
Dated attestation

The signed summary delivered with every audit, alongside the three documents. It states what was assessed, when, from which public sources, and what was found. It is the one document written to leave the building.

Dated and signed by LeakTrace
States what was read, and from where
Reviewed by a person before release
A point-in-time record, not a certification
Who This Is For

Built For Organizations
Where Data Is The Asset

If your business holds client data, financial records, health information, or privileged communications, your exposure profile is a target. LeakTrace works across every professional services vertical.

Law Firms

Privileged client communications are your liability. One breach, a leaked file, a spoofed email, an exposed login, and you're explaining it to the Law Society and your clients simultaneously.

Medical & Health Clinics

A PIPEDA or HIPAA violation triggers mandatory disclosure, potential fines, and the kind of press coverage that follows a practice for years.

Accounting & Tax Practices

You hold banking credentials, SINs, financial statements, and CRA correspondence for dozens of clients. That concentration of data is what makes a practice worth targeting.

Real Estate Brokerages

One spoofed email redirecting closing funds is enough. The transaction looks normal until the money is gone. Your domain and your people can be mapped from public records.

Financial Advisors & Wealth Managers

Securities regulators scrutinise cybersecurity practices as part of advisor oversight. A breach does not just cost money, it puts your license to operate at risk.

Insurance & Risk Advisory

You hold client risk profiles and financial information. Regulators expect you to demonstrate the same security practices you recommend to your clients. LeakTrace gives you documented proof.

Published Research

Findings from our monitoring pipeline

LeakTrace publishes quarterly threat intelligence based on real observations across owner-run firms in North America. Free to read. Journalist inquiries welcome.

Service Areas
Programs for the professional-services and adjacent sectors we specialize in.
Broker Programs
Insurance brokers & MGAs. Business brokers & M&A advisors.
Wealth & Private Client
Wealth advisors and private banking relationship managers.
Talent Representation
Sports agents, entertainment agencies, athlete talent representation firms.
Legal Counsel
Litigation counsel, breach response, pre-notification threat intelligence.
Cyber Insurance
Carriers, MGAs and wholesalers writing cyber liability for owner-run firms.
Executive Protection
High net worth individuals, corporate principals, public-figure households.

Client identities remain confidential.

Standing Guarantee
If the full audit surfaces no findings beyond what this preview already shows, your audit is refunded in full.

The preview is the private brief we send you before you order. This is a standing guarantee, not a limited-time offer. The terms are written into our refund policy.

Request an Assessment

What Is Already
Out There About
Your Organization?

Assessment requests are reviewed and confirmed within one business day. All communications are confidential. An NDA is available before any work begins.

No scan without your consent. Submitting this form does not trigger any automated activity on your domain. We confirm scope and authorisation before anything starts.
Strictly confidential. Your request, domain details, and all findings are treated as confidential. An NDA is available before any work begins. We respond within one business day.
Request a Business Assessment

Tell us about your organization. We will review and respond within one business day.

By submitting you agree to our Privacy Policy and Terms of Service. We will never share your information with third parties.

Request Received

Our assessment team will review your request and follow up within one business day to confirm scope and next steps.

No automated activity will be run on your domain until you authorise it.