What LeakTrace is.
LeakTrace is a threat intelligence firm serving the professional advisors, brokers, insurers, and firms whose clients require independent verification of cyber exposure. We are not a software vendor. We do not sell tooling. We publish findings, not features.
Every engagement produces a briefing that documents a client's external attack surface, credential exposure, vendor relationships, and public-record aggregation surface. The briefing is drawn from monitored breach databases, DNS and certificate transparency records, corporate registry filings, paste-site monitoring, and public-record aggregators. No engagement requires access to a client's internal systems.
How we operate.
What every engagement covers.
The LeakTrace forensic audit runs against thirty-six discrete external attack surface categories. The categories below summarize what is examined in every engagement. Additional depth is added when a client's vertical or exposure profile requires it.
| Domain | What we examine |
|---|---|
| Credential | Breach database inclusion, password recovery quality, credential reuse patterns across personal and business accounts |
| Domain | Registrar posture, DNS configuration, mail infrastructure, certificate transparency observations, visually confusable domain registrations |
| Public identity | Corporate registry filings, principal disclosure, address aggregation, philanthropic and directorship exposure |
| Portal | Publicly reachable client portals, authentication baselines, unauthenticated metadata disclosure, session and rate-limit configuration |
| Vendor | Vendor relationships observable through DNS and public disclosure, vendor-side breach inclusion, vendor policy adherence |
| Household | For high-value principals, correlation across public records, staff exposure, property management infrastructure, philanthropic vehicle posture |
Every finding is delivered with a source citation, a severity assessment, a remediation recommendation, and a monitoring baseline. Remediation is not billed separately from the engagement; the audit and the recommended actions are delivered together.
Regulatory posture per jurisdiction.
Findings are framed against the regulatory obligations that apply to the client's vertical and jurisdiction. This is not a legal opinion. It is a mapping between observed exposure and the applicable regulatory expectations, prepared to support the client's counsel in the remediation and, when required, notification process.
Anonymized engagement records.
Every case file in the LeakTrace library is drawn from a real forensic engagement. Anonymization is by vertical and region only. Client identity, engagement dates, and geographic detail below province or state are excluded from the public versions. Full-detail case files are available under nondisclosure for referrals from qualified introduction relationships.
Current public library covers dental practice (Ontario, insurance renewal), law firm (United States, wire-fraud precursor), medical clinic (Ontario, provincial reporting threshold), wealth advisory firm (Canada, enhanced due diligence), single-family office (Canada, principal correlation graph), and sports agency (United States, athlete and business manager coordination).
Read the case files at getleaktrace.com/case-studies/.
Sector visibility across the North American attack surface.
The LeakTrace research library covers twenty-one sectors of the North American small-business and mid-market attack surface. Briefings are published under the LeakTrace name, without individual bylines, and address structural exposure patterns rather than individual incidents.
The library serves two purposes. For clients and advisors, it provides sector-specific context that informs the interpretation of an individual client's findings. For the industry, it establishes LeakTrace's position on the exposure patterns that matter in each vertical.
Read the library at getleaktrace.com/research/.
How introductions work.
Most LeakTrace engagements originate through introductions from insurance brokers, wealth advisors, health-law counsel, or family office consultants. The introduction path preserves the advisor's judgment as the primary trust vehicle. LeakTrace serves as the technical execution behind the introduction, not as a competing relationship with the advisor's client.
For insurance brokers. LeakTrace conducts pre-binding forensic audits when an underwriter requires independent verification of a client's cyber posture. The broker retains the primary relationship. LeakTrace delivers findings, and the broker's cyber counsel or the underwriter uses those findings to complete the binding process.
For wealth advisors. LeakTrace conducts advisor-level and household-level exposure audits when a custodian's enhanced due diligence requirements exceed what the firm's internal compliance program can independently verify. Findings are formatted for regulatory filing use in coordination with the firm's counsel.
For counsel. LeakTrace conducts forensic audits as part of the file when a client's compliance review or governance intake indicates exposure that has not been quantified. Findings are reviewed with counsel before any regulatory notification is drafted or filed.
For family office consultants. LeakTrace conducts principal-focused exposure audits covering the principal, household, and philanthropic vehicle surfaces. Consultants use the findings as the anchor for household security baseline work with the family office.
Contact and firm information.
Toronto, Ontario M5R 2A5
Canada
New York, New York 10003
United States