Eight automated checks against your domain. No systems accessed, no credentials required, no obligation.
Passive only — no systems, networks or accounts are accessed at any point.
Enter your primary domain and contact details. We identify all associated entities, subdomains, and publicly visible infrastructure before we begin.
Our structured 5-phase passive assessment framework is applied across your entire external footprint. No systems accessed. No credentials required.
A structured professional report — risk register, framework mapping, APP compliance assessment, and a Board-level executive summary — delivered within 5–7 business days.
Corporate entity mapping, subsidiary identification, domain and subdomain enumeration, and email security record analysis across all associated entities.
Passive infrastructure review, certificate analysis, SSL/TLS configuration audit, and technology stack fingerprinting across all public-facing systems.
Domain breach exposure analysis, credential scanning, public repository secret detection, historical footprint review, and paste site monitoring.
Privacy policy assessment against Australian Privacy Principles (APP 1–13), cross-border disclosure review, and third-party vendor risk identification.
All findings consolidated into a structured risk register, mapped to ASD Essential Eight, NIST CSF 2.0, ISO 27001, APRA CPS 234, and the Privacy Act. Board-level executive summary and prioritised remediation roadmap.
Open Source Intelligence — OSINT — is the practice of gathering information exclusively from publicly available sources. No systems are accessed. No credentials are required. Everything surfaced in this scan is already visible to anyone who knows where to look.
Domain registrars, certificate transparency logs, DNS records, breach databases, government registries, paste sites, social networks and search engine indexes all contain information about your organisation — published, indexed and accessible right now. Passive OSINT is the discipline of systematically collecting and analysing that information to understand what is exposed.
This scan covers five intelligence categories: infrastructure and hosting, breach and credential exposure, technology stack and known vulnerabilities, Privacy Act compliance posture, and corporate entity intelligence. Each finding above is sourced from publicly available data only.
Every engagement is the same passive methodology. What changes is the framework the findings are mapped to, and the audience the report is written for.
Find the AI you are running, not the AI you declared — exposed model endpoints, MCP servers and shadow deployments, mapped to ISO/IEC 42001.
Independent external exposure evidence mapped clause by clause to the APRA prudential standard — for your Board and internal audit function.
Externally verified evidence against the mitigation strategies that can honestly be assessed from outside — and an explicit statement of those that cannot.
What your organisation exposes, mapped to the Australian Privacy Principles — including tracking, consent sequencing and overseas disclosure.
What your suppliers actually expose, observed from outside without their cooperation. Evidence rather than questionnaires.
For law firms, accountants, conveyancers and agencies now holding seven years of client identity documents under obligations that commenced 1 July 2026.
Independent external evidence for your CIRMP across the cyber and supply chain hazard vectors.