Start with thirty minutes

Threat intelligence about your organization · from public sources only

Everyone covers the industry. We cover you.

Somewhere, someone outside is looking at your organization and can see things you can't — what you depend on, what's exposed, what's being said about you. We show you that same view. The brief is written for its reader — one version for the person who answers for the organization, another for your security team. Everything behind the brief is a question away. Ask in plain language for a report, a threat model, a dependency map, or a search across everything on record.

Public sources only · your surface · the third parties operating on your behalf · the storylines about you · every item traced to its source and dated

Who it's for

Built for organizations that answer for more than they operate.

A headquarters and its branches. A system and its campuses. An authority and the offices that run its process. A group and its subsidiaries. If one of many can put your name in a headline — and its systems aren't yours to run — this is written for you.

Alongside what you already have

Everyone adjacent stops one rung down. Keep your feeds, your ratings, your information-sharing partners. They answer different questions.

CategoryWhat it watchesWhat it hands youTells you what it does to your mission, and by when?
Asset-discovery tools (EASM)Your hosts, certificates, DNSA findings queueNo
Security-ratings vendorsAn outside-in look, scoredA letter gradeNo
Threat-intelligence feedsActor chatter, indicatorsIndustry reportingNo
Vendor-risk suites (TPRM)Questionnaires, bundled historyA vendor scoreNo
Breach-filing alertsRegulatory filings for a watchlistThe filing, datedNo
CiphrenEverything publicly visible about your units and the vendors acting for themWhat it does to your mission, on a date, and what to do about itYes
how we’re categorizedClosest to external asset monitoring (EASM), third-party risk (TPRM), and threat intelligence. We do the work those names describe — as one standing watch, about you alone: collection, analysis, and the brief.
Four
live deployments · in production since 2026 · identifying details withheld
~20 analyst-years
what building this map by hand would take · the system built the first pass in under 24 hours — before anyone else's did · how we count
~8 analysts
what keeping one deployment current by hand would take, every day · the system does — your headcount doesn't change · how we count

How we count. System figures are measured from a live deployment — counts, not estimates. Analyst-equivalents are a model: a tool-assisted analyst on an 8-hour day, at conservative desk rates — about 3 minutes per source-relevance decision, 12 per incident triaged, 5 per infrastructure finding, 20 per entity resolved. Raw extraction is excluded, so the figure understates. On an ordinary maintenance day for one deployment that is roughly 61 analyst-hours. Figures are per deployment and rounded.

What we watch · across all deploymentsCounts read off the product · rounded
~110
organizations we collect for
60+
operating units they answer for
4,000+
incidents on record, each with its source
12
hosting providers they depend on
What the map holds around them, by kind
people, in public roles~4,700 people — holders of published roles, never profiles~4,700 organizations & agencies~4,600 organizations, agencies and offices~4,600 internet-facing hosts~3,700 hosts, each counted once~3,700 technologies & services~1,400 technologies, software versions and services~1,400 storylines, over time~200 narrative arcs — active, dormant or concluded~200
people as their organizations publish them — never profiles of private individuals · every item carries its source and its date
Counts across all deployments, rounded. People appear only in their public roles. Identifying details withheld.
Not a mockup — what the standing map holds today, across all deployments. Rounded; the product shows the exact counts.

Why

Someone outside is looking at your organization and can see things you can't.

Not because anyone is careless — because no one inside a building can see it from outside. Everything we observe, an adversary can observe too — and the other side no longer does it by hand. A machine can now assemble a map of your exposure in hours, not months. The question is whose hands it's in first. Ours puts it in yours — what the map enables, handed to a person as a lead, not a verdict.

A quiet week and an unwatched week read identically. One of them should worry you.

  • The ransomware headline with your name on it.Most of them start with a known, already-exploited weakness on a public system. We tell you which of yours those are before anyone else does.
    how we see ita public component matched against CISA's Known Exploited Vulnerabilities catalog
  • An email from your own address, to your own staff, that you never sent.Which of your domains can be forged, and which of the people you publish are reachable enough to be phished or phoned. Roles you publish, never profiles.
    how we see itdomains without SPF or DMARC, cross-referenced with published roles
  • One vendor's bad day becoming half your organization's.How many of your units sit on the same vendor, provider, or certificate — what a single outage or supplier breach reaches at once.
    how we see itwhere your units and vendors are hosted; concentration by provider
  • The thing nobody told security about.A system that appeared, a provider that changed, a vendor whose standing slipped — reported as soon as it's seen, and reported when nothing moved.
    how we see iteach organization against its own previous collection
Exposure at a glance · one organizationProduct view · rebuilt from the portal · illustrative, rounded values
Already being exploited
~40of ~1,200 findings
~1,200 findings on public hosts ~40 confirmed as already exploited in real attacks — on CISA's Known Exploited Vulnerabilities list
The brief leads with what is already being exploited — not with what scores highest.
Domains without DMARC
~14of ~45 domains
with DMARC~31 domains with SPF and DMARC without~14 domains an attacker can send mail as 9 carry a published role
Nine domains can be forged and have someone reachable to forge them at.
Units per hosting provider
~55%on one provider
Provider ████9 units9 Provider ████4 units4 Provider ████2 units2 Provider ████1 unit1
One outage at the top provider reaches nine of sixteen units at once.
Subdomains · last 6 collections
+6since collection 4
subdomains observed, per collection collection 5: +6 subdomains collection 6: unchanged +6 3 weeks agolatest
Six names appeared on one unit's domain in a single collection. Nobody had told security.
The four blind spots as numbers: how many findings are confirmed-exploited, how many domains can be forged, how much of you sits on one provider, and what moved. Rounded on purpose — the product shows exact counts, with their date.

What

One current map of what's visible about you. A brief that says what to decide. And answers when you ask.

The brief comes to you. Everything behind it is a question away. Ask in plain language for a report, a threat model, a dependency map, or a search across everything on record. And your standing questions stay watched — when an answer changes, the brief says so.

  • Your surface, as an outsider sees it.Every system of yours reachable from the internet — subdomains, addresses, technologies, certificates, hosting — and the findings on each, by severity. Counted once, always dated.
  • Your third parties, mapped to your units.Which vendors are exposed on your behalf, which units each one serves, and where too many units rest on one vendor. A vendor that no public record lists as yours is shown anyway — flagged as unconfirmed, not dropped.
  • Incidents you can interrogate.Source named and linked, confidence graded rather than asserted, three dates kept apart: happened, discovered, published.
  • Narrative tracking.The storylines about you, followed for spread and targeting — active, dormant, or concluded — so you hear the question before it's asked. We track the story. We never rule on whether it's true.
  • Ask it anything.Ask in plain language for a report, a threat model, a dependency map, or a search across everything on record. The answer returns as a finished product — every figure quoted from the collection, sourced and dated. Saved, refined, and exported with its handling level on every page.
Third-party dependencies · vendors × unitsProduct view · rebuilt from the portal · illustrative
units →████████████████████████ Vendor ████████ 6 of 8 units Vendor ████████ 3 of 8 Vendor ████████ 2 of 8 · unmatched Vendor ████████ 5 of 8 Vendor ████████ 1 of 8 43332333vendors per unit
serves the unit — the vendor most of you depend onserves the unitserves the unit · in no public record
Which vendors are exposed on behalf of which of your units. One vendor carries six of eight; one appears in no public record — shown, not hidden. Illustrative.
Executive Brief · weeklyProduct view · rebuilt from the portal · not customer data
████████ · Office of the ████████

Executive Brief

audience: executive · plain languagecadence: weeklyalso issued: security team · technical
show the brief on
Normal operationsConfidence: high

Nothing new on your perimeter this week. One vendor advisory touches your units.

1 action needs your decision today.
  1. 1. Forward the vendor advisory████████ published a software update; it applies in ██ of your units.
Watched and quiet: ██ organizations · ██ sources · all threat categories · your own surface.
latest collection yesterday · median organization collected ~3 days ago · about nine in ten findings re-observed within a week
The brief in the executive profile — written for its reader; the security team's version carries the technical detail. Toggle between a quiet week and a week with a finding: either way, what to decide, what was watched and stayed quiet, and how old every number is. Identifying details withheld.

Why you can trust it

Intelligence you can't interrogate is just someone else's opinion, delivered confidently.

  • Public sources only — boundary stated.What anyone with a browser could see, with browser-equivalent requests. Nothing behind a login, nothing purchased, no data brokers. We never send your systems anything a visitor's browser wouldn't.
  • People appear only in their public roles.As your organization publishes them. No profiles of private individuals, no tracking of anyone's speech. Narratives are about the organization, never the speaker.
  • We show our work — including the misses.How we know, how sure we are, and when we learned it, kept apart. What we couldn't match, and what stayed quiet, are published alongside what we found.
  • Leads for a human, not verdicts from a machine.The system writes the brief and organizes itself; people calibrate it, and can override or retract a mistake. The decision stays yours. Strictly nonpartisan — we never take a side.
Finding · detailProduct view · rebuilt from the portal · illustrative

DNSSEC not enabled on a public-facing domain

◆ Corroborated source: public DNS record ↗ checked against: registrar record unit · ████████ credibility: source-declared
Happened · Jul 2present in the record
Discovered · Jul 3the collection that first saw it
Published · Jul 3reached the brief
Corroborated is corroborated. Single-source is labelled. Nothing reaches you ungraded. Most of any outside view rests on a single public record, so we tell you which items those are rather than drawing every meter full.
How we know, how sure we are, when we learned it — on one item, and honestly across all of them. Illustrative values.

Your view is yours alone — nothing is shared across customer deployments · comparisons are anonymized — an index of how you stand, never another customer's details · we collect on our own initiative — nothing you provide enters the shared map · the memory is the point — kept for the life of the map; people only while their role is public · US-hosted — region and dedicated deployment on request


What it asks of you

You don't build it. You don't staff it. You decide who reads what — and ask it the rest.

  • Ask 1 — noneNothing to disclose to start.The picture is assembled from the outside before you've told us anything. No data-sharing agreement to begin.
  • Ask 2 — noneNothing to install, nothing to staff.No agents, no sensors, nothing new to run. Collection, analysis and the brief happen on our side. You receive the result — and can ask it what you'd ask an analyst.
  • The one decisionWho reads what.Per role and handling level, on your existing sign-on — with per-unit export and a tamper-evident audit log.

Every item carries a handling level — how sensitive it is, and how far it may be shared. You decide who holds which level; the brief each person sees follows from that.

The one decision · who reads whatProduct view · rebuilt from the portal · not customer data · try it
What this person reads
Viewing as cleared to · on your existing sign-on
TLP:RED
Vendor-side critical: end-of-life software version observed on a vendor host serving two of your units
TLP:AMBER
Expired certificate on a public portal of one of your units
TLP:AMBER
Narrative gaining ground — service reliability, tracked across 3 units
TLP:GREEN
Vendor advisory: software update, 5 units affected
TLP:GREEN
New subdomain observed on one of your domains
TLP:CLEAR
Authority registry snapshot refreshed
Change the clearance; the list is what that person sees. The levels follow the Traffic Light Protocol, a sharing convention security teams already use.

What changed

Every brief: what moved since the last collection — and what was watched and stayed quiet.

Executive Brief · since last collectionProduct view · rebuilt from the portal · not customer data
30-Day ActivityDaily incident volume · hatched days were not yet watched
unwatched — collection had not begun 2 incidents5374169532846317524631 unwatchedcollection begins9today
Since Last CollectionEach organization against its own previous collection
~40 organizations vs their previous collection3 changed cloud footprint
████████ (operating unit)Aug 17 → Aug 24 · 2 domainssource ↗
subdomains +6+ Cloudflare
Vendor ████████serves 5 units · Aug 16 → Aug 23source ↗
findings +3− Akamaiposture: stable → watch
████████ (operating unit)Aug 18 → Aug 25source ↗
subdomains −2
A number that moved — a perimeter that grew, a provider that appeared, a vendor whose posture band changed — each line with its source and the date it was observed.

Thirty minutes, then thirty days

We'll show you your own organization.

The call is not a tour of your organization — that view doesn't exist yet, and won't until you ask for it. It's thirty minutes on what you'd want watched: which units, which third parties, which storylines. The pilot builds the view. If it names something you weren't tracking, you'll know inside thirty days. If it doesn't, you've spent one call.

  • The call. Thirty minutes on what you'd want watched, and what a pilot would return.
  • The packet. Security review, architecture, hosting and retention terms, pilot agreement — and pricing, set by the size and scope of your organization — before anything else is asked of you.
  • The pilot. Thirty days: your own ecosystem on screen, judged by you against your own scorecard. And against the only honest alternative — what the same standing watch would take your own people by hand. The figures above say what that costs.

Ciphren was founded by Douglas Winzell after a career building intelligence and security capability for the Marine Corps and across the Department of Defense. Ciphren exists to give organizations outside that world the same standing watch.

Reach us

One email: your organization, and what you'd want watched — a vendor you'd like us to check, a unit, a past event — or nothing yet.

Email start@ciphren.com

Straight to the Ciphren team — no mailing lists, no trackers. We reply within two business days.