how it works
Collect, detect, remediate.
The same three steps we run on every customer - against
60 billion leaked records, updated continuously.
01 · Collect
We watch the places
attackers trade.
AI agents on leak sites, breach dumps, and human intelligence in closed forums.
60B+ credential records indexed
Closed-community human intelligence
Telegram, IRC, Discord channels
Partner intelligence feeds
02 · detect
We match against
your business.
Your domains and email patterns are cross-checked continuously.
Email and in-app alerts in minutes
Severity scored (critical / high)
Direct proof of the source dump
Audit trail for every event
03 · Remediate
You rotate in
one click.
Native identity integrations with Microsoft 365 and Google enables session revocation and MFA lock down instantly.
Native integrations with major identity platforms
Enforce MFA on exposed accounts
Compliance-ready audit trail
The rotation flow
Detection to rotation, in seconds.
dwm.flow · acme.com tenant
Live
Step 1
Leak detected
finance@acme.com surfaced in Collection #142 · 9s ago
Step 2
Severity scored
Critical · password reused on 2 internal services · MFA off
Step 3
Auto-remediated
Force reset · revoke 4 active sessions · enrol MFA - across Microsoft 365, Google

Step 4
Audit trail closed
Compliance log written · ICO-ready · 11s end-to-end
End-to-end median: 11 seconds
audit log → SOC export → compliance evidence

Scenario
The Finance Director
Resolved in minutes
From dark-web breach to resolved - in minutes.
A 40-person firm. Their FD's credentials appear in a fresh combolist on a criminal forum. CyberProtect surfaces the threat the moment it lands and fires a critical alert.
The admin opens the finding card. Severity is critical. One click triggers a Graph API force reset, revokes sessions, and enforces MFA. The audit trail writes itself.
Total time to rotation: less than 3 minutes. Board-ready summary generated.
PLATFORM_OUTCOME
Instant
alert on surfacing
1 click
to force-rotate + MFA
0
manual resets needed
100%
audit-trail coverage
Defining the perimeter
The honest scope.
What we surface - and, just as honestly, what we don't.
Email + Passwords
Combolists, breach dumps, and raw credential logs.
API Keys & Tokens
Secrets leaked in public archives and code repositories.
Source Code
Secrets and logic found in the wild.
Auth & Cookies
Session cookies stolen by active infostealer malware.
Personal Data (PII)
Names, addresses, and phone numbers in leaked datasets.
Payment Cards
Credit card data circulating in dark-web marketplaces.
Internal Docs
Sensitive files found on ransomware leak sites.
Infostealer Data
Full machine fingerprints captured by malware logs.
What we don't cover
Network scanning
Vulnerabilities behind the
firewall.
Endpoint & EDR
What's running on the
machines themselves.
Exploitation testing
Actively attacking your own
infrastructure.
Inbound email security
Phishing and spam filtering on the inbox.
Cloud posture (CSPM)
Misconfiguration auditing
inside your accounts.
identity-aware
Two integrations.
The two that matter.
Almost every UK business runs Microsoft 365 or Google Workspace.
We integrate deeply with both, no extra agents, no inbox scanning.
Microsoft 365
Native integration for instant session revocation, password resets and MFA enforcement — straight from the finding card.
Reset Password
Revoke Sessions
Enforce MFA
Google Workspace
Admin SDK force reset, revoke OAuth scopes and app passwords, and re-enrol the user into 2-step verification.
Reset Password
Revoke OAuth
Enforce 2SV
The hard questions, answered straight.
What does 'instant' alerting actually mean?
What if our employees already have MFA enabled?
Is this GDPR-compliant?
Do you sell the dark-web data you collect?
How do you handle false positives?
What happens if a current employee leaves?












