Threat intelligence about your organization · from public sources only
Everyone covers the industry. We cover you.
Somewhere, someone outside is looking at your organization and can see things you can't — what you depend on, what's exposed, what's being said about you. We show you that same view. The brief is written for its reader — one version for the person who answers for the organization, another for your security team. Everything behind the brief is a question away. Ask in plain language for a report, a threat model, a dependency map, or a search across everything on record.
Public sources only · your surface · the third parties operating on your behalf · the storylines about you · every item traced to its source and dated
Who it's for
Built for organizations that answer for more than they operate.
A headquarters and its branches. A system and its campuses. An authority and the offices that run its process. A group and its subsidiaries. If one of many can put your name in a headline — and its systems aren't yours to run — this is written for you.
Alongside what you already have
Everyone adjacent stops one rung down. Keep your feeds, your ratings, your information-sharing partners. They answer different questions.
| Category | What it watches | What it hands you | Tells you what it does to your mission, and by when? |
|---|---|---|---|
| Asset-discovery tools (EASM) | Your hosts, certificates, DNS | A findings queue | No |
| Security-ratings vendors | An outside-in look, scored | A letter grade | No |
| Threat-intelligence feeds | Actor chatter, indicators | Industry reporting | No |
| Vendor-risk suites (TPRM) | Questionnaires, bundled history | A vendor score | No |
| Breach-filing alerts | Regulatory filings for a watchlist | The filing, dated | No |
| Ciphren | Everything publicly visible about your units and the vendors acting for them | What it does to your mission, on a date, and what to do about it | Yes |
how we’re categorized
Closest to external asset monitoring (EASM), third-party risk (TPRM), and threat intelligence. We do the work those names describe — as one standing watch, about you alone: collection, analysis, and the brief.How we count. System figures are measured from a live deployment — counts, not estimates. Analyst-equivalents are a model: a tool-assisted analyst on an 8-hour day, at conservative desk rates — about 3 minutes per source-relevance decision, 12 per incident triaged, 5 per infrastructure finding, 20 per entity resolved. Raw extraction is excluded, so the figure understates. On an ordinary maintenance day for one deployment that is roughly 61 analyst-hours. Figures are per deployment and rounded.
Why
Someone outside is looking at your organization and can see things you can't.
Not because anyone is careless — because no one inside a building can see it from outside. Everything we observe, an adversary can observe too — and the other side no longer does it by hand. A machine can now assemble a map of your exposure in hours, not months. The question is whose hands it's in first. Ours puts it in yours — what the map enables, handed to a person as a lead, not a verdict.
A quiet week and an unwatched week read identically. One of them should worry you.
- The ransomware headline with your name on it.Most of them start with a known, already-exploited weakness on a public system. We tell you which of yours those are before anyone else does.
how we see it
a public component matched against CISA's Known Exploited Vulnerabilities catalog - An email from your own address, to your own staff, that you never sent.Which of your domains can be forged, and which of the people you publish are reachable enough to be phished or phoned. Roles you publish, never profiles.
how we see it
domains without SPF or DMARC, cross-referenced with published roles - One vendor's bad day becoming half your organization's.How many of your units sit on the same vendor, provider, or certificate — what a single outage or supplier breach reaches at once.
how we see it
where your units and vendors are hosted; concentration by provider - The thing nobody told security about.A system that appeared, a provider that changed, a vendor whose standing slipped — reported as soon as it's seen, and reported when nothing moved.
how we see it
each organization against its own previous collection
What
One current map of what's visible about you. A brief that says what to decide. And answers when you ask.
The brief comes to you. Everything behind it is a question away. Ask in plain language for a report, a threat model, a dependency map, or a search across everything on record. And your standing questions stay watched — when an answer changes, the brief says so.
- Your surface, as an outsider sees it.Every system of yours reachable from the internet — subdomains, addresses, technologies, certificates, hosting — and the findings on each, by severity. Counted once, always dated.
- Your third parties, mapped to your units.Which vendors are exposed on your behalf, which units each one serves, and where too many units rest on one vendor. A vendor that no public record lists as yours is shown anyway — flagged as unconfirmed, not dropped.
- Incidents you can interrogate.Source named and linked, confidence graded rather than asserted, three dates kept apart: happened, discovered, published.
- Narrative tracking.The storylines about you, followed for spread and targeting — active, dormant, or concluded — so you hear the question before it's asked. We track the story. We never rule on whether it's true.
- Ask it anything.Ask in plain language for a report, a threat model, a dependency map, or a search across everything on record. The answer returns as a finished product — every figure quoted from the collection, sourced and dated. Saved, refined, and exported with its handling level on every page.
Executive Brief
Why you can trust it
Intelligence you can't interrogate is just someone else's opinion, delivered confidently.
- Public sources only — boundary stated.What anyone with a browser could see, with browser-equivalent requests. Nothing behind a login, nothing purchased, no data brokers. We never send your systems anything a visitor's browser wouldn't.
- People appear only in their public roles.As your organization publishes them. No profiles of private individuals, no tracking of anyone's speech. Narratives are about the organization, never the speaker.
- We show our work — including the misses.How we know, how sure we are, and when we learned it, kept apart. What we couldn't match, and what stayed quiet, are published alongside what we found.
- Leads for a human, not verdicts from a machine.The system writes the brief and organizes itself; people calibrate it, and can override or retract a mistake. The decision stays yours. Strictly nonpartisan — we never take a side.
DNSSEC not enabled on a public-facing domain
Your view is yours alone — nothing is shared across customer deployments · comparisons are anonymized — an index of how you stand, never another customer's details · we collect on our own initiative — nothing you provide enters the shared map · the memory is the point — kept for the life of the map; people only while their role is public · US-hosted — region and dedicated deployment on request
What it asks of you
You don't build it. You don't staff it. You decide who reads what — and ask it the rest.
- Ask 1 — noneNothing to disclose to start.The picture is assembled from the outside before you've told us anything. No data-sharing agreement to begin.
- Ask 2 — noneNothing to install, nothing to staff.No agents, no sensors, nothing new to run. Collection, analysis and the brief happen on our side. You receive the result — and can ask it what you'd ask an analyst.
- The one decisionWho reads what.Per role and handling level, on your existing sign-on — with per-unit export and a tamper-evident audit log.
Every item carries a handling level — how sensitive it is, and how far it may be shared. You decide who holds which level; the brief each person sees follows from that.
What changed
Every brief: what moved since the last collection — and what was watched and stayed quiet.
Thirty minutes, then thirty days
We'll show you your own organization.
The call is not a tour of your organization — that view doesn't exist yet, and won't until you ask for it. It's thirty minutes on what you'd want watched: which units, which third parties, which storylines. The pilot builds the view. If it names something you weren't tracking, you'll know inside thirty days. If it doesn't, you've spent one call.
- The call. Thirty minutes on what you'd want watched, and what a pilot would return.
- The packet. Security review, architecture, hosting and retention terms, pilot agreement — and pricing, set by the size and scope of your organization — before anything else is asked of you.
- The pilot. Thirty days: your own ecosystem on screen, judged by you against your own scorecard. And against the only honest alternative — what the same standing watch would take your own people by hand. The figures above say what that costs.
Ciphren was founded by Douglas Winzell after a career building intelligence and security capability for the Marine Corps and across the Department of Defense. Ciphren exists to give organizations outside that world the same standing watch.
One email: your organization, and what you'd want watched — a vendor you'd like us to check, a unit, a past event — or nothing yet.
Email start@ciphren.comStraight to the Ciphren team — no mailing lists, no trackers. We reply within two business days.