Frequently asked questions
What security leaders ask when they evaluate digital risk and leak intelligence — answered directly.
Does this require installing agents on employee devices?
No. The platform operates entirely externally, monitoring dark-web sources and correlating them with your organisational identifiers. Nothing is installed on endpoints; coverage extends to personal and unmanaged devices because we monitor data that leaves those devices, not the devices themselves.
How quickly will we receive alerts after credentials appear?
Ingestion pipelines process new stealer logs continuously. For major markets and Telegram channels, alert latency is typically under 2 hours from publication. Less active sources are processed within 24 hours.
Can we monitor third-party vendors and supply chain partners?
Yes. You can add any email domain or identifier to your monitored asset list — including critical vendors, managed service providers, and supply chain partners. Coverage is not limited to your own infrastructure.
How do you obtain dark-web data without legal exposure?
Research and collection operate in compliance with applicable law in every jurisdiction. We do not purchase stolen data; methodology relies on technical observation and indexing of publicly accessible dark-web sources, consistent with established threat-intelligence industry practice.
What does onboarding look like?
Onboarding typically takes less than one business day. You provide monitored domains and additional identifiers. We configure alert preferences and integration endpoints. Your first dark-web scan runs immediately after activation, with historical coverage up to 24 months by default.
How does integration work with our existing SIEM?
We offer native connectors for Splunk, Microsoft Sentinel, IBM QRadar, and Elastic SIEM, plus a fully documented REST API and Syslog output for custom integrations. Alerts arrive as structured, fully enriched events ready for correlation and automated playbook execution.