The product
What you receive.
A standing watch with three outputs: the brief, written for its reader; the map behind it, sourced and dated; and answers when you ask. What follows is what arrives during a pilot.
What arrives
The brief
The Executive Brief is written for the person who answers for the organization. Your security team works the same map in its own views — Asset Findings, Infrastructure Intel, Investigations. Alongside it, the weekly brief: what moved this week against the questions you care about — the system writes it, and people calibrate it. Every printed brief carries its handling mark, who it was for, who prepared it, and the collection date.
What changed
The since-last-collection panel: exactly what moved, each line with its source and the date it was observed.
Vendor dependencies
Dependency mapping reaches one to two hops: your units' vendors, and those vendors' own providers. Never deeper, and never a claim past what the map holds.
The storylines about you
Narrative tracking follows the storylines about you — for spread and targeting — so you hear the question before it's asked. We track the story; we never rule on whether it's true.
The questions you care about
You bring standing questions; the watch holds them. On screen they are Priority Intelligence Requirements: each question a traffic light, each light backed by what was actually seen. The weekly brief reports against them.
Ask it anything
Ask in plain language; the portal answers three ways.
A plain-language question, returned as a reasoned model: what the threat reaches, through which dependency, to which mission outcome — every node sourced and dated.
Everything public with your name on it — your hosts, your records, and the public record itself.
One map — people in public roles, units, vendors, storylines — every item sourced, graded, and dated.
Written for the person who answers — with everything behind it a question away.
What stands behind it
Collection — the standing watch
Collection watches the hosts you list the way any visitor could — and reads the public record the same way. On a fixed interval it gathers, compares each pass with the last, and notes what changed.
On your hosts
On the public record
And we watch the regulators and registries behind your oversight, your funding, and your accreditation — a set configured to your organization. Ask us which ones yours would include.
Every request is
Never
Seen as a visitor sees it
Pages are observed even where simple tools are turned away.
Human-reviewed
Credentials or keys left in public pages go through a person before they reach you.
No false chases
Version checks correct for backported fixes, so your team isn't chased for a patched weakness.
One rule sits under everything above: we collect as if you'll read it about yourself — because you will. The exact contractual scope language is available word for word — just ask.
The map
Everything the watch observes lands on one map: people in public roles, units, vendors, domains, storylines. The connections land there too: who works where, who governs or certifies what, who supplies whom, who owns whom. That's how a vendor is followed through its name changes and owners.
One organization at the centre, everything with your name on it around it — each node and tie sourced and dated. The map holds far more than one screen shows.
Who reads what
Two roles — analyst and admin — and four handling levels, enforced on every query, in the portal and through the API; tokens inherit them.
Your identity provider, connected at install. And a tamper-evident audit log — hash-chained, verified on demand — recording every login, search, view, print and export.
It starts with thirty minutes on what you'd want watched.
Start with thirty minutes