Start with thirty minutes

Threat intelligence about your organization · from public sources only

Everyone covers the industry. We cover you.

Somewhere, someone outside is looking at your organization and can see things you can't — what you depend on, what's exposed, what's being said about you. We show you that same view in a brief written for its reader — plain language for the person who answers for the organization, the detail for your security team — weekly or daily, your choice. Nothing to install.

Public sources only · your surface · the third parties operating on your behalf · the storylines about you · every item traced to its source and dated

Who it's for

Built for organizations that answer for more than they operate.

A headquarters and its branches. A system and its campuses. An authority and the offices that run its process. A group and its subsidiaries. If one of many can put your name in a headline — and its systems aren't yours to run — this is written for you.

Alongside what you already have

Keep your feeds, your ratings, your information-sharing partners — they cover ground we don't. Three things they don't do:

  • Roll it up across units you don't control, as one picture.
  • Write it for the person who answers — and separately for the team that fixes.
  • Report silence as a result, so a quiet week and an unwatched week never read the same.
Three
live deployments · in production since 2026 · identifying details withheld
~20 analyst-years
what building this map by hand would take · the system built the first pass in under 24 hours — before anyone else's did
~10 analysts
what keeping it current by hand would take, every day · the system does — your headcount doesn't change · method on request
What we watch · three live deploymentsCounts read off the product · rounded
~110
organizations we collect for
60+
operating units they answer for
16
third parties operating on their behalf
13,000+
findings on record, each dated
4,000+
incidents on record, each with its source
12
hosting providers they depend on
What the map holds around them, by kind
people, in public roles~4,700 people — holders of published roles, never profiles~4,700 organizations & agencies~4,600 organizations, agencies and offices~4,600 internet-facing hosts~3,700 hosts, each counted once~3,700 technologies & services~1,400 technologies, software versions and services~1,400 storylines, over time~200 narrative arcs — active, dormant or concluded~200
people as their organizations publish them — never profiles of private individuals · every item carries its source and its date
Counts from three live deployments, rounded. People appear only in their public roles. Identifying details withheld.
Not a mockup — what the standing map holds today, across three deployments. Rounded; the product shows the exact counts.

Why

Someone outside is looking at your organization and can see things you can't.

Not because anyone is careless — because no one inside a building can see it from outside. Everything we observe, an adversary can observe too — and the other side no longer does it by hand. A map of your exposure can now be assembled by machine in hours, not months. The question is whose hands it's in first. Ours puts it in yours: what it enables, handed to a person as a lead, not a verdict.

A quiet week and an unwatched week read identically. One of them should worry you — so each brief says which it was.

  • The ransomware headline with your name on it.Most of them start with a known, already-exploited weakness on a public system. We tell you which of yours those are before anyone else does.
    how we see ita public component matched against CISA's Known Exploited Vulnerabilities catalog
  • An email from your own address, to your own staff, that you never sent.Which of your domains can be forged, and which of the people you publish are reachable enough to be phished or phoned. Roles you publish, never profiles.
    how we see itdomains without SPF or DMARC, cross-referenced with published roles
  • One vendor's bad day becoming half your organization's.How many of your units sit on the same vendor, provider, or certificate — what a single outage or supplier breach reaches at once.
    how we see itwhere your units and vendors are hosted; concentration by provider
  • The thing nobody told security about.A system that appeared, a provider that changed, a vendor whose standing slipped — reported as soon as it's seen, and reported when nothing moved.
    how we see iteach organization against its own previous collection
Exposure at a glance · one organizationProduct view · rebuilt from the portal · illustrative, rounded values
Already being exploited
~40of ~1,200 findings
~1,200 findings on public hosts ~40 confirmed as already exploited in real attacks — on CISA's Known Exploited Vulnerabilities list
Three in a hundred change the decision regardless of score. Those are the ones the brief leads with.
Domains without DMARC
~14of ~45 domains
with DMARC~31 domains with SPF and DMARC without~14 domains an attacker can send mail as 9 carry a published role
Nine domains can be forged and have someone reachable to forge them at.
Units per hosting provider
~55%on one provider
Provider ████9 units9 Provider ████4 units4 Provider ████2 units2 Provider ████1 unit1
One outage at the top provider reaches nine of sixteen units at once.
Subdomains · last 6 collections
+6since collection 4
subdomains observed, per collection collection 5: +6 subdomains collection 6: unchanged +6 3 weeks agolatest
Six names appeared on one unit's domain in a single collection. Nobody had told security.
The four blind spots as numbers: how many findings are confirmed-exploited, how many domains can be forged, how much of you sits on one provider, and what moved. Rounded on purpose — the product shows exact counts, with their date.

What

One current map of what's visible about you — and a brief, on your cadence, saying what to decide.

The brief comes to you. Everything behind it is there when you want it — ask for a report or a threat model, search, or open any view; almost anything is two clicks away.

  • Your surface, as an outsider sees it.Every system of yours reachable from the internet — subdomains, addresses, technologies, certificates, hosting — and the findings on each, by severity. Counted once, always dated.
  • Your third parties, mapped to your units.Which vendors are exposed on your behalf, serving which of your units, and where too many units rest on one vendor. A vendor that no public record lists as yours is shown anyway — flagged as unconfirmed, not dropped.
  • Incidents you can interrogate.Source named and linked, confidence graded rather than asserted, three dates kept apart: happened, discovered, published.
  • Narrative tracking.The storylines about you, followed for spread and targeting — active, dormant, or concluded — so you hear the question before it's asked. We track the story. We never rule on whether it's true.
Third-party dependencies · vendors × unitsProduct view · rebuilt from the portal · illustrative
units →████████████████████████ Vendor ████████ 6 of 8 units Vendor ████████ 3 of 8 Vendor ████████ 2 of 8 · unmatched Vendor ████████ 5 of 8 Vendor ████████ 1 of 8 43332333vendors per unit
serves the unit — the vendor most of you depend onserves the unitserves the unit · in no public record
Which vendors are exposed on behalf of which of your units. One vendor carries six of eight; one appears in no public record — shown, not hidden. Illustrative.
Executive Brief · weeklyProduct view · rebuilt from the portal · not customer data
████████ · Office of the ████████

Executive Brief

audience: executive · plain languagecadence: weeklyalso issued: security team · technical
show the brief on
Normal operationsConfidence: high

Nothing new on your perimeter this week. One vendor advisory touches your units.

1 action needs your decision today.
  1. 1. Forward the vendor advisory████████ published a software update; it applies in ██ of your units.
Watched and quiet: ██ organizations · ██ sources · all threat categories · your own surface.
latest collection yesterday · median organization collected ~3 days ago · about nine in ten findings re-observed within a week
The brief in the executive profile — no technical terms; the security team's version carries them. Toggle between a quiet week and a week with a finding: either way, what to decide, what was watched and stayed quiet, and how old every number is. Identifying details withheld.

Why you can trust it

Intelligence you can't interrogate is just someone else's opinion, delivered confidently.

  • Public sources only — boundary stated.What anyone with a browser could see, with browser-equivalent requests. Nothing behind a login, nothing purchased, no data brokers. We never send your systems anything a visitor's browser wouldn't.
  • People appear only in their public roles.As your organization publishes them. No profiles of private individuals, no tracking of anyone's speech. Narratives are about the organization, never the speaker.
  • We show our work — including the misses.How we know, how sure we are, and when we learned it, kept apart. What we couldn't match, and what stayed quiet, are published alongside what we found.
  • Leads for a human, not verdicts from a machine.The system writes the brief and organizes itself; people calibrate it, and can override or retract a mistake. The decision stays yours. Strictly nonpartisan — never positions, campaigns, or causes.
Finding · detailProduct view · rebuilt from the portal · illustrative

DNSSEC not enabled on a public-facing domain

◆ Corroborated source: public DNS record ↗ checked against: registrar record unit · ████████ credibility: source-declared
Happened · Jul 2present in the record
Discovered · Jul 3the collection that first saw it
Published · Jul 3reached the brief
What the brief leads with · ~2,300 items graded
Corroborated · ~12% Single-source · ~81% Unverified · ~7%
◆ corroborated ~12%○ single-source ~81%△ unverified ~7%
Every item carries its own grade, and the brief leads with what is corroborated. Most of any outside view rests on a single public record — so we tell you which items those are, rather than drawing every meter full. Nothing reaches your brief ungraded.
How we know, how sure we are, when we learned it — on one item, and honestly across all of them. Illustrative values.

Your view is yours alone — nothing is shared across customer deployments · comparisons are anonymized — an index of how you stand, never another customer's details · we collect on our own initiative — nothing you provide enters the shared map · the memory is the point — kept for the life of the map; people only while their role is public · US-hosted — region and dedicated deployment on request


What it asks of you

You don't build it. You don't run it. You just decide who reads it.

  • Ask 1 — noneNothing to disclose to start.The picture is assembled from the outside before you've told us anything. No data-sharing agreement to begin.
  • Ask 2 — noneNothing to install, nothing to run.No agents, no sensors, no queue to triage. Collection, analysis and the brief happen on our side; you receive the result.
  • The one decisionWho reads what — and which version.Executive or technical, weekly or daily, per role and handling level, on your existing sign-on — with per-unit export and an audit log that can't be quietly edited.

Every item carries a handling level — how sensitive it is, and how far it may be shared. You decide who holds which level; the brief each person sees follows from that.

The one decision · who reads whatProduct view · rebuilt from the portal · not customer data · try it
What this person reads
Viewing as cleared to · on your existing sign-on
TLP:RED
Vendor-side critical: end-of-life software version observed on a vendor host serving two of your units
TLP:AMBER
Expired certificate on a public portal of one of your units
TLP:AMBER
Narrative gaining ground — service reliability, tracked across 3 units
TLP:GREEN
Vendor advisory: software update, 5 units affected
TLP:GREEN
New subdomain observed on one of your domains
TLP:CLEAR
Authority registry snapshot refreshed
Change the clearance; the list is what that person sees. The levels follow the Traffic Light Protocol, a sharing convention security teams already use.

What changed

Every brief: what moved since the last collection — and what was watched and stayed quiet.

Executive Brief · since last collectionProduct view · rebuilt from the portal · not customer data
30-Day ActivityDaily incident volume · hatched days were not yet watched
unwatched — collection had not begun 2 incidents5374169532846317524631 unwatchedcollection begins9today
Since Last CollectionEach organization against its own previous collection
~40 organizations vs their previous collection3 changed cloud footprint
████████ (operating unit)Aug 17 → Aug 24 · 2 domainssource ↗
subdomains +6+ Cloudflare
Vendor ████████serves 5 units · Aug 16 → Aug 23source ↗
findings +3− Akamaiposture: stable → watch
████████ (operating unit)Aug 18 → Aug 25source ↗
subdomains −2
A number that moved — a perimeter that grew, a provider that appeared, a vendor whose posture band changed — each line with its source and the date it was observed.

Thirty minutes, then thirty days

We'll show you your own organization.

The call is not a tour of your organization — that view doesn't exist yet, and won't until you ask for it. It's thirty minutes on what you'd want watched: which units, which third parties, which storylines. The pilot builds the view. If it names something you weren't tracking, you'll know inside thirty days. If it doesn't, you've spent one call.

  • The call. Thirty minutes on what you'd want watched, and what a pilot would return.
  • The packet. Security review, architecture, hosting and retention terms, pilot agreement — and pricing, set by the size and scope of your organization — before anything else is asked of you.
  • The pilot. Thirty days, your own ecosystem on screen, judged by you against your own scorecard.
Reach us

One email: your organization, and what you'd want watched — a vendor you'd like us to check, a unit, a past event — or nothing yet.

Email start@ciphren.com

Straight to the Ciphren team — no mailing lists, no trackers. We reply within two business days.