First, The Diagnosis
"We've never been hacked" is not the same as "we're not exposed."
Most exposure doesn't come from someone breaking into you. It comes from everywhere your people and data already are. Here's where it actually leaks from:
Other companies' breaches
A service your staff used got breached, and their work email and password are now in a database criminals search.
Password reuse
One reused password from a personal site becomes the key to your email, systems and client data.
Infostealer malware
A single infected laptop quietly ships every saved login — yours and your clients' — to a marketplace.
Leaked client & company data
Records, financials, IDs and documents surface for sale — a POPIA problem the moment they involve personal information.
If any of that has happened — and for most businesses, some of it has — it's sitting out there right now, whether or not you can see it. The only real question is whether you find it, or an attacker does.
Done Safely, Done Lawfully
We gather the intelligence. We never touch the crime.
This matters, so we're explicit: we monitor through established breach-intelligence and dark-web monitoring platforms and data sources — lawfully. We do not engage criminals, negotiate with them, or purchase stolen data. You get the intelligence about your exposure, handled responsibly by a security team — not a vigilante poking around criminal markets on your behalf.
Three Ways To Handle It
Start with the diagnosis. Scale to the cover you need.
You don't have to commit to everything at once. Most businesses start by simply finding out what's already out there, then choose how much ongoing cover they want.
Exposure Report
A one-off snapshot of what's already leaked.
- A search across breach and dark-web sources for your domain, people and data
- A plain-language report of what's exposed and how serious it is
- Immediate priority actions (what to change today)
Continuous Monitoring
Because new leaks appear all the time.
- Everything in the report, kept live
- Real-time alerts the moment new exposure appears
- Monitoring of executives and high-risk accounts
- A monthly plain-language exposure summary
Managed Exposure + Response
Monitoring, plus someone to act when it matters.
- Everything in continuous monitoring
- We act on findings — containment and remediation
- Breach response & POPIA 72-hour handling
- Tied into your wider security posture
Our recommendation: almost everyone should begin with the Exposure Report — it's the diagnosis, and it usually surprises people. If it turns up real exposure (it often does), Continuous Monitoring is the sensible home for most businesses; the managed tier is for those who want us to act on findings, not just flag them.
Where This Gets You
From "we hope we're fine" to "we know, and we're covered."
The destination isn't a report. It's a state of mind you can defend: you know exactly what's exposed, you're told the instant anything new appears, and there's a plan ready to run — so the day a leak surfaces, it's a handled task instead of a ransom note and a scramble. That's also the difference between a POPIA breach you managed and one that manages you.
Common Questions
Straight answers.
Is this legal, and is it safe?
Yes. We use established, lawful breach-intelligence and dark-web monitoring platforms and data sources. We never engage criminals, negotiate, or buy stolen data — we gather intelligence about your exposure and handle it responsibly. It's a security service, not vigilantism.
We use strong security already — do we still need this?
Yes, because most exposure isn't about your defences. It comes from breaches of other companies your staff used, reused passwords, and malware on devices — none of which your firewall sees. Monitoring is how you catch what prevention can't.
What do you actually monitor for?
Leaked credentials (staff and executive), your domain and email addresses, exposed client and company data, and mentions that indicate a breach or a planned attack — scoped to your business, its people and, where relevant, key clients.
What happens if you find something serious?
You're alerted immediately with clear priority actions. On the managed tier we act on it — containment, remediation and, if personal information is involved, the POPIA 72-hour reporting process — through our breach response service.