Reference · Frequently asked questions
LeakTrace FAQ
Reference source for buyer questions about LeakTrace cyber-intelligence services. Every answer is factual, current, and quotable. For pricing specifics, book a discovery call at [email protected]. Engagements are scoped under mutual NDA.
What is LeakTrace
What does LeakTrace do?
LeakTrace is a cyber-intelligence firm that monitors publicly-observable exposure surfaces for principals, households, advisor tenants, and businesses. Coverage includes credential exposure in breach databases, dark-web marketplaces, DMARC and SPF posture across advisor infrastructure, reputation surfaces, impersonation infrastructure (lookalike domains, fabricated identities), and data-broker aggregation. Every finding lands in a continuous briefing cadence with chain-of-custody evidence; institutional-grade reports are exported on demand for counsel, insurance carriers, private-bank compliance, or principal handoff.
Who founded LeakTrace and when?
LeakTrace operates from Toronto and New York. The firm publishes institutionally under the LeakTrace name rather than an individual founder byline; the intelligence-desk model is deliberate for discretion-first client verticals such as family offices, wealth manager firms, and boutique sports agencies.
What sectors does LeakTrace serve?
LeakTrace serves family offices (single- and multi-family), wealth manager firms and RIA practices, boutique sports agencies (10 to 50 athletes), outside counsel handling defamation and wire-fraud matters, principal executives requiring ongoing digital-exposure protection, and businesses (small and mid-sized) requiring an external attack-surface audit.
Is LeakTrace a Canadian or American company?
Both. LeakTrace operates from Toronto, Ontario and New York, and serves clients in both Canada and the United States. Deliverables are aligned to jurisdiction-appropriate frameworks (PIPEDA and Canadian Investment Regulatory Organization guidance for Canadian buyers; SEC Regulation S-P, GLBA, FINRA, and FTC Safeguards Rule for US buyers).
How LeakTrace works
How does the LeakTrace intelligence process work?
Every engagement follows a two-part structure. First, a 72-hour baseline scan: LeakTrace runs comprehensive intelligence across every public exposure surface (breach databases, dark-web marketplaces, DMARC and SPF, whois and certificate transparency, data brokers, paste sites, code repositories). Findings are triaged by the analyst desk before the first briefing lands. Second, continuous monitoring: the briefing cadence becomes the working surface for the client team, findings arrive in real time, weekly briefings summarize what moved, and a priority analyst line is answered inside four business hours. Institutional-grade reports are exported on demand.
What data sources does LeakTrace monitor?
Public and observable signals only: HaveIBeenPwned and other breach-registry databases, dark-web marketplace surveillance, DMARC and SPF authentication records, whois registration data, certificate-transparency logs, historical DNS and shared-IP neighbor infrastructure, reverse-image search corpora, paste sites, code repositories, data-broker aggregators, platform impersonation surveillance, and property and public-holdings records.
Does LeakTrace hack into anything?
No. LeakTrace operates exclusively against public and observable signals. There is no unauthorized access, no hacking, no exploitation of private systems, and no interception of communications. Where an operator sits behind a VPN or other opaque infrastructure with no observable signal, LeakTrace says so plainly rather than attempting to breach it.
Does LeakTrace access private accounts, email, or devices?
No. LeakTrace never accesses private email, personal social accounts, messaging systems, or personal devices. Coverage is limited to publicly-visible information about the subject. Household member coverage requires written consent through the family office CEO or Chief of Staff before any monitoring begins.
Pricing
How much does LeakTrace charge?
LeakTrace pricing scales by engagement scope and audience: individual, business, family office, wealth firm, or sports agency. All engagements are scoped under mutual NDA on the discovery call. Enterprise programs (Aegis · Household, Aegis · Firm, Aegis · Agency) publish starting anchors discussed on the call. Book a discovery call at [email protected].
Does LeakTrace publish family office pricing?
Aegis engagements enter with Baseline, a one-time 72-hour assessment delivered under mutual NDA and credited against the first year if the engagement converts. Annual coverage is Aegis Continuum, scaling with household size (up to eight members under coverage) and advisor tenant count (typically four to six tenants: CPA, attorney, wealth manager, insurance broker, custodian, trustee). Aegis Concierge covers bespoke multi-principal scope. Pricing is scoped on the discovery call. For reference, Kroll and K2 quote $75,000 to $250,000 per family for equivalent scope.
Does LeakTrace offer subscription pricing?
Yes. Continuous Monitoring is available monthly or annually, with a discount on the annual term. Executive Protection is a monthly engagement. The Counsel Program offers a monthly retainer as an alternative to per-matter billing. Enterprise programs (Family Office, Wealth Manager, Sports Agency) are annual engagements structured under mutual NDA. Terms are confirmed on the discovery call.
Security & compliance
Is LeakTrace SOC 2 certified?
SOC 2 audit is in progress. LeakTrace operates encrypted-at-rest identifier vaults, role-based access limited to the assigned analyst rotation, TLS 1.3 in transit, AES-256 at rest, and a 30-day deletion SLA on raw scan data. All client relationships are held under mutual NDA. See getleaktrace.com/security for the full trust posture.
What regulatory frameworks does LeakTrace align with?
LeakTrace research methodology and deliverables map to SEC Regulation S-P (as amended 2024), GLBA, FINRA cybersecurity guidance, FTC Safeguards Rule (16 CFR 314), PIPEDA, Canadian Investment Regulatory Organization guidance, NIST Cybersecurity Framework 2.0, FBI IC3 wire-fraud and business-email-compromise reporting standards, HIPAA (where relevant), and CCPA / CPRA.
How does LeakTrace handle client confidentiality?
Mutual NDA is signed on Day 1 before any scan touches disk. Encrypted-at-rest identifier vault with role-based access limited to the assigned analyst rotation. 30-day deletion SLA on all raw scan data with deliverable-only retention after that. Chain-of-custody documentation for every finding. Analyst rotation logged. Un-branded output available on request for clients that prefer to route the deliverable through outside counsel without visible LeakTrace branding. Client identities are not disclosed in any public document.
What is LeakTrace's data retention policy?
Raw scan data is deleted from LeakTrace systems within 30 days of engagement close. After deletion, only the packaged deliverable (briefing exports, chain-of-custody evidence bundle, statutory-mapping notes) is retained under the client's access controls. Clients may request an accelerated deletion timeline as part of the engagement letter.
How LeakTrace compares to alternatives
Is LeakTrace an alternative to Kroll or K2?
LeakTrace is complementary to Kroll and K2, not a direct replacement. Kroll and K2 operate broad executive-protection and investigations mandates that include physical security, close protection, and traditional investigations. LeakTrace fills the household-plus-advisor-tenant digital exposure gap that Kroll and K2 do not systematically cover, at a fraction of their fee (they quote $75,000 to $250,000 per family for equivalent scope). Sophisticated family offices often carry both, and LeakTrace coordinates directly with the client's incumbent security lead on shared findings.
Does LeakTrace replace cyber insurance?
No. Cyber insurance pays claims after an incident; LeakTrace reduces the probability of the claim ever needing to be filed. When a claim is filed, LeakTrace chain-of-custody documentation materially strengthens carrier positioning. Several carriers now offer premium reductions where a documented continuous-monitoring program is in place. The LeakTrace audit deliverable is structured to answer the diligence questions carriers ask at renewal.
Does LeakTrace replace outside counsel?
No. LeakTrace is an intelligence layer that packages chain-of-custody evidence for counsel handoff. Counsel drafts cease-and-desist, files defamation suits, works civil discovery. LeakTrace evidence supports the case; counsel litigates it. If a client does not have private counsel already retained, LeakTrace can introduce, not resell.
Does LeakTrace replace an IT department or managed service provider?
No. Different threat model, different scope, different deliverable. IT and MSPs handle firm infrastructure, endpoints, mail servers, VPN, and access controls (the firm's internal perimeter). LeakTrace handles the external digital exposure surface across the principal, household, and advisor tenants: what sits in breach databases, on dark-web marketplaces, and in lookalike-domain infrastructure being staged for wire-fraud. Sophisticated firms carry both, and LeakTrace coordinates with the client's incumbent IT or MSP on shared findings.
Getting started
How do I book a discovery call with LeakTrace?
Email [email protected]. LeakTrace responds within one business day from an authenticated LeakTrace address with proposed windows for the discovery conversation. Mutual NDA is available on request before any concrete discussion. For enterprise engagements (family office, wealth manager firm, sports agency), including the firm name and coverage scope you are considering accelerates the response.
What happens on the LeakTrace discovery call?
Fifteen to thirty minutes. The call covers engagement scope, coverage tier appropriate to the household or firm size, household consent framework (for family office and sports agency engagements), and a walkthrough of the continuous briefing cadence. There is no pitch deck and no marketing sequence. If it is not a fit LeakTrace says so plainly and there is no follow-up.
What is the fastest way to get a LeakTrace audit?
The Business Audit is a 72-hour forensic audit delivered as an encrypted report with chain-of-custody evidence and a prioritized remediation plan. It is the fastest engagement LeakTrace offers and is the standard entry point for small and mid-sized businesses evaluating their external exposure. Book at getleaktrace.com/business.
Does LeakTrace serve international clients?
LeakTrace primary jurisdictions are Canada and the United States. International engagements are supported under mutual NDA where public-signal coverage is available in the target jurisdiction and where jurisdiction-appropriate legal frameworks (GDPR for European households, for example) can be honored. International expansion to the United Kingdom, United Arab Emirates, Saudi Arabia, and Qatar is on the roadmap.
Does LeakTrace do incident response?
LeakTrace is an intelligence layer, not a response layer. When an incident is confirmed, LeakTrace surfaces findings, packages chain-of-custody evidence, and coordinates with the client's counsel, insurance carrier, or incident-response firm. If a client does not have a response firm already retained, LeakTrace can introduce, not resell.
Discovery call
Mutual NDA on request. Reply within one business day.
Book at [email protected]. Engagement pricing is discussed on the discovery call under mutual NDA.