Continuous intelligence coverage for principals, households, and family offices.
A client-facing intelligence platform used by Chiefs of Staff, General Counsel, and family-office principals to see everything an adversary can see about the principal, the family, the professional network, and the entity structure. Analyst-verified. Weekly cadence. Critical alerts on discovery.
Request an initial assessment Engagement structure →Continuous coverage
Automated scans across breach databases, public search, social platforms, and firm infrastructure — every day, per principal and per household member under coverage.
Analyst-verified findings
Nothing client-facing bypasses human review. Every finding is triaged, classified, and given a plain-English attacker narrative + recommended action by the intel desk before it appears on the dashboard.
Weekly briefing
Friday morning digest to the Chief of Staff, General Counsel, or principal. Summarizes what changed, what needs decision, and what the analyst desk is monitoring. Nothing shouty.
Same-day critical alerts
Severity 4-5 findings fire an alert to the routing you specify — CoS, counsel, or principal — within hours of analyst verification. Comprehensive tier: 4h response. Concierge: 1h.
One page. Not a hundred alerts.
Every Friday, the Chief of Staff opens the dashboard and sees a narrative — this week for the principal — before any raw data. What requires attention. What decisions are queued. What the analyst desk is monitoring quietly.
Below the narrative: recommended actions with an owner tag on each (Client · Counsel · Analyst desk · Firm IT). Then the coverage matrix. Then the finding log if you want the depth.
See a sample brief →2 findings require attention.
- 1 critical finding — immediate action recommended.
- 1 high-severity finding — review with counsel within one business day.
- Reputation profile stable — no negative press this cycle.
- Standing coverage: 14 monitored signals across principal, household, counsel, and firm.
The full coverage picture.
Below: who we cover (4 rings — principal, household, adjacent professionals, entity), the 8 intelligence surfaces we monitor, and how the 32 cells intersect.
Who we cover
Every finding attaches to a specific ring so the dashboard filters by whose exposure it represents. Rings are additive: comprehensive tier covers all four; baseline tier covers principal ring only.
The full matrix
32 intelligence cells total. 20 live in MVP. Roadmap categories ship over the next 90 days as we build alongside first-cohort feedback.
| Ring → Surface ↓ | Principal | Inner ring | Outer ring | Entity |
|---|---|---|---|---|
| Digital Identity | Breach credentials · PII · government IDs · financial account exposure | Household breach exposure · shared credential risk | Adjacent professional credential exposure | Firm email breach records · executive team credentials |
| Reputation | Media coverage · sentiment · journalist activity · Google indexed pages | Family reputation exposure · media mentions | Counterparty reputation risk | Firm reputation · brand coverage · press mentions |
| Social Presence | Reddit · X · Instagram · LinkedIn mentions · deleted content archival | Kids' social media privacy audit · spouse professional exposure | Not covered | Firm social presence · employee posts about firm |
| Brand + Impersonation | Fake profiles impersonating principal · deepfake / voice-clone content | Family-member impersonation attempts | Not covered | Typosquat domains · fraudulent LinkedIn pages · spoofed emails |
| Physical Exposure | Address indexing · movement patterns from geo-tagged content · travel exposure | Family address exposure · home security posture | Not covered | Property records exposure · office location intel |
| Relational Exposure | Network graph mapping · counterparty exposure via transitive attack | Household staff exposure · family relationship graph | Professional counterparty breach cascade tracking | Vendor / third-party breach cascade to firm |
| Financial Signals | Financial media mentions · dark-web financial data broker sales | Not covered | Not covered | Short-seller campaigns · SEC filing anomaly · investor sentiment |
| Predictive Threats | 90-day threat modeling · emerging attack campaign warnings | Not covered | Not covered | Firm-specific adversary tracking · industry pattern detection |
What each surface actually covers
Credential exposure across breach databases (LinkedIn 2012, Adobe 2013, National Public Data 2024, etc.), password reuse detection, government-issued identifier exposure, financial account exposure, API key or token exposure in public code repositories.
Google-indexed pages mentioning the principal or firm, media coverage sentiment analysis over rolling 90-day windows, journalist and outlet tracking, comparative benchmarking against peer principals.
Mentions across Reddit, X, Instagram, LinkedIn, TikTok. Deleted content archival — posts that were removed still preserved. Coordinated behavior detection. Bot network identification.
Typosquat domains registered against firm or family names. Fake LinkedIn profiles impersonating executives. Fraudulent social accounts. Spoofed email infrastructure. Deepfake and voice-clone content detection.
DNS configuration and record integrity, SSL certificate hygiene, DMARC/SPF/DKIM email authentication, subdomain enumeration and takeover risk, code repository exposure, cloud bucket exposure, exposed configuration endpoints, WordPress REST user enumeration, vulnerable JavaScript library detection, SaaS vendor fingerprinting.
Publicly indexed home and office addresses, property records including deed history and assessed values, vehicle registration where public, travel indicators derivable from geo-tagged social content, movement pattern reconstruction from public sightings.
Network graph mapping of professional and personal relationships derivable from public sources. Counterparty exposure tracking — when your accountant, lawyer, wealth advisor, or personal trainer is breached, the exposure cascades to you. Adjacent professional risk profiling.
Short-seller campaigns targeting the principal or firm, hostile investor coverage, dark-web sales of financial data brokers, SEC filing anomalies for family office affiliates, coordinated narrative attacks.
Given the principal's profile, current world events, and active adversary campaigns, what is likely to happen in the next 90 days? Threat modeling that combines profile intelligence, world-state monitoring, and adversary tracking. The differentiator from reactive tools.