The product

What you receive.

A standing watch with three outputs: the brief, written for its reader; the map behind it, sourced and dated; and answers when you ask. What follows is what arrives during a pilot.

What arrives

The brief

TLP:AMBER
Executive Brief
Prepared for ████████████
Prepared by ██████ · Collection as of Sep 12, 2026
TLP:AMBERpage 1 of 6
The brief — what to decide, written for its reader.
TLP:AMBER
Critical Findings — ██████
Prepared for ████████████
Prepared by ██████ · Collection as of Sep 12, 2026
TLP:AMBERpage 1 of 3
The findings brief — any unit's page, printed and attributed.
TLP:RED
Threat Model — ██████
Prepared for ████████████
Analysis run Sep 14 · Collection as of Sep 12
TLP:REDpage 1 of 11
The Deep Reasoning brief — a question, returned as a document.

The Executive Brief is written for the person who answers for the organization. Your security team works the same map in its own views — Asset Findings, Infrastructure Intel, Investigations. Alongside it, the weekly brief: what moved this week against the questions you care about — the system writes it, and people calibrate it. Every printed brief carries its handling mark, who it was for, who prepared it, and the collection date.

What changed

Since last collection · what movedProduct view · rebuilt from the portal · illustrative
████████ (a branch)Sep 7 → Sep 14findings +3subdomains +6 · new provider
Vendor ██████serves several unitsposture → watchsource ↗
████████ (a branch)Sep 8 → Sep 15quietwatched — no change

The since-last-collection panel: exactly what moved, each line with its source and the date it was observed.

Vendor dependencies

Your unit
hop 1
Its vendor
hop 2
That vendor's provider
never deeper

Dependency mapping reaches one to two hops: your units' vendors, and those vendors' own providers. Never deeper, and never a claim past what the map holds.

The storylines about you

Narrative tracking · the storylines about youProduct view · rebuilt from the portal · illustrative
ACTIVE██████████████ — spreading, and aimed at one unitfollowed for spread and targeting
DORMANT████████████ — has resurfaced before; quiet nowstill watched
CONCLUDED████████ — ran its course; kept on recordthe memory is the point

Narrative tracking follows the storylines about you — for spread and targeting — so you hear the question before it's asked. We track the story; we never rule on whether it's true.

The questions you care about

Standing questions · watched against everything collectedProduct view · rebuilt from the portal · illustrative
GREEN · WATCHING
Has a vendor we depend on shipped a known-exploited weakness?
every answer sourced and dated
AMBER · WATCHING
Is new policy changing what compliance asks of us?
every answer sourced and dated
RED · WATCHING
Is a storyline circulating that names us, a unit, or a vendor?
every answer sourced and dated

You bring standing questions; the watch holds them. On screen they are Priority Intelligence Requirements: each question a traffic light, each light backed by what was actually seen. The weekly brief reports against them.

Ask it anything

Ask in plain language; the portal answers three ways.

Semantic Searcheverything on record, with synthesis on demand.
Deep Analyst Modethe analyst agent works the question across the collection.
Deep Reasoninga mission returns a saved investigation and a printed, attributed brief — the Strategic Threat Modeler runs scenarios alongside.
Ask · a Deep Reasoning missionProduct view · rebuilt from a Deep Reasoning brief · illustrative
What could reach us through our vendors before a major deadline?
THREAT
Notice spoofing / phishing
Unauthenticated mail path on the member-facing domain
Coordinated doubt campaign
Pre-seeded doubt about member records
THE ORGANIZATION
A high-exposure branch
████████ · depends on the shared portal
The headquarters
Owns the portal and the domain estate
SYSTEMS & VENDORS
The member portal
No SPF, no DMARC — sender identity spoofable · source ↗
The domain estate
Most domains missing sender authentication
The public web app
Known library weaknesses, exploited elsewhere
MISSION OUTCOMES
Service to those who depend on it
The people the branch exists to serve
Public confidence
The integrity narrative around the service
CriticalHighInfoSubject– – threat vector— reaches a mission outcome

A plain-language question, returned as a reasoned model: what the threat reaches, through which dependency, to which mission outcome — every node sourced and dated.

We watch

Everything public with your name on it — your hosts, your records, and the public record itself.

We map

One map — people in public roles, units, vendors, storylines — every item sourced, graded, and dated.

We brief

Written for the person who answers — with everything behind it a question away.

What stands behind it

Collection — the standing watch

Collection watches the hosts you list the way any visitor could — and reads the public record the same way. On a fixed interval it gathers, compares each pass with the last, and notes what changed.

On your hosts

Public pagesEach site's pages and the files they load
DNS & certificatesRecords, subdomains, Certificate Transparency logs
TLS & hostingConfiguration, and which cloud providers host them
RegistriesWho owns the address space, and who the entity is
AdvisoriesNVD, the CISA Known Exploited Vulnerabilities catalog, OSV

On the public record

PressWire services, national and local outlets, trade and advocacy press — from all sides, on purpose
Public postsWhat a search surfaces and a logged-out visitor can read
Official webYour own public sites, and those of the units you answer for
The reference recordStatutes, court records, standards, and public registries

And we watch the regulators and registries behind your oversight, your funding, and your accreditation — a set configured to your organization. Ask us which ones yours would include.

Every request is

An unauthenticated read — the page requests a browser makes
Observed as a real browser renders it, not only raw source
Paced so it never burdens or disrupts a service
Recorded with where and when we read it

Never

A credential sent or tested, or any sign-in
A vulnerability confirmed by triggering it
An account we hold, a post, a follow, a message
A login wall or paywall bypassed — that's a dead end, not content
A third-party system accessed on your behalf
A private detail kept — people appear only in their public roles

Seen as a visitor sees it

Pages are observed even where simple tools are turned away.

Human-reviewed

Credentials or keys left in public pages go through a person before they reach you.

No false chases

Version checks correct for backported fixes, so your team isn't chased for a patched weakness.

One rule sits under everything above: we collect as if you'll read it about yourself — because you will. The exact contractual scope language is available word for word — just ask.

The map

Everything the watch observes lands on one map: people in public roles, units, vendors, domains, storylines. The connections land there too: who works where, who governs or certifies what, who supplies whom, who owns whom. That's how a vendor is followed through its name changes and owners.

The map · one organization at the centreProduct view · rebuilt from the portal · illustrative
a unitthe office itselfa vendora domaina person in a public rolea storyline
Subject — you and yoursEntity on the mapIncident— an intelligence tie

One organization at the centre, everything with your name on it around it — each node and tie sourced and dated. The map holds far more than one screen shows.

Who reads what

Two roles — analyst and admin — and four handling levels, enforced on every query, in the portal and through the API; tokens inherit them.

TLP:CLEARTLP:GREENTLP:AMBERTLP:RED

Your identity provider, connected at install. And a tamper-evident audit log — hash-chained, verified on demand — recording every login, search, view, print and export.

It starts with thirty minutes on what you'd want watched.

Start with thirty minutes