Threat Scan

See Your Organisationthe way an attacker does.

Eight automated checks against your domain. No systems accessed, no credentials required, no obligation.

8Automated checks
Under 60sTypical scan time
SPF, TLSDMARC, certificate, headers, trackers
$1,500Full assessment, from — ex GST

Passive only — no systems, networks or accounts are accessed at any point.

www.
Passive only — no systems accessed, no active scanning, no credentials required

Confidential — no obligation. We will send you a complete evidenced report on every gap identified and exactly how to address it.
Please complete all required fields.
✓  Thank you — your detailed gap report is on its way. We will be in touch within 24 hours.
How It Works

Three Steps. One Outcome.

01

You Provide a Domain

Enter your primary domain and contact details. We identify all associated entities, subdomains, and publicly visible infrastructure before we begin.

02

We Assess

Our structured 5-phase passive assessment framework is applied across your entire external footprint. No systems accessed. No credentials required.

03

You Receive a Report

A structured professional report — risk register, framework mapping, APP compliance assessment, and a Board-level executive summary — delivered within 5–7 business days.

Methodology

Five Phases. Every Engagement.

01

Reconnaissance

Corporate entity mapping, subsidiary identification, domain and subdomain enumeration, and email security record analysis across all associated entities.

02

Infrastructure Analysis

Passive infrastructure review, certificate analysis, SSL/TLS configuration audit, and technology stack fingerprinting across all public-facing systems.

03

Breach Intelligence

Domain breach exposure analysis, credential scanning, public repository secret detection, historical footprint review, and paste site monitoring.

04

Compliance Review

Privacy policy assessment against Australian Privacy Principles (APP 1–13), cross-border disclosure review, and third-party vendor risk identification.

05

Reporting & Remediation

All findings consolidated into a structured risk register, mapped to ASD Essential Eight, NIST CSF 2.0, ISO 27001, APRA CPS 234, and the Privacy Act. Board-level executive summary and prioritised remediation roadmap.

Open Source Intelligence — OSINT — is the practice of gathering information exclusively from publicly available sources. No systems are accessed. No credentials are required. Everything surfaced in this scan is already visible to anyone who knows where to look.

Domain registrars, certificate transparency logs, DNS records, breach databases, government registries, paste sites, social networks and search engine indexes all contain information about your organisation — published, indexed and accessible right now. Passive OSINT is the discipline of systematically collecting and analysing that information to understand what is exposed.

This scan covers five intelligence categories: infrastructure and hosting, breach and credential exposure, technology stack and known vulnerabilities, Privacy Act compliance posture, and corporate entity intelligence. Each finding above is sourced from publicly available data only.

Assessed Against the Obligation
You Actually Carry

Every engagement is the same passive methodology. What changes is the framework the findings are mapped to, and the audience the report is written for.

AI Governance
AI Governance Assessment

Find the AI you are running, not the AI you declared — exposed model endpoints, MCP servers and shadow deployments, mapped to ISO/IEC 42001.

View Assessment →
APRA CPS 234
CPS 234 Assessment

Independent external exposure evidence mapped clause by clause to the APRA prudential standard — for your Board and internal audit function.

View Assessment →
ASD Essential Eight
Essential Eight Assessment

Externally verified evidence against the mitigation strategies that can honestly be assessed from outside — and an explicit statement of those that cannot.

View Assessment →
Privacy Act & APPs
Privacy Act & APP 11 Assessment

What your organisation exposes, mapped to the Australian Privacy Principles — including tracking, consent sequencing and overseas disclosure.

View Assessment →
Supply Chain
Third-Party Risk Assessment

What your suppliers actually expose, observed from outside without their cooperation. Evidence rather than questionnaires.

View Assessment →
AML/CTF Tranche 2
Tranche 2 Cyber Assessment

For law firms, accountants, conveyancers and agencies now holding seven years of client identity documents under obligations that commenced 1 July 2026.

View Assessment →
SOCI Act
SOCI Assessment

Independent external evidence for your CIRMP across the cyber and supply chain hazard vectors.

View Assessment →
Assessments
AI Governance CPS 234 Essential Eight Privacy Act & APP 11 Third-Party Risk Tranche 2 Cyber SOCI / Critical Infrastructure Obligation Tool →
Intelligence
All briefings Romania land registry Tranche 2 commenced ASD advisories, 2026
Practice
GRC Partnerships Pricing Privacy
Start
Threat Scan Enquire Sample report