Questions, answered
23 short answers about LeakTrace and the External Cybersecurity Assessment, each true as written.
What does LeakTrace do?#
LeakTrace provides independent external cybersecurity assessments for owner-run firms. It reads what anyone can already see about a firm from outside and reports what a stranger would find first: whether email can be sent in the firm’s name and delivered, whether staff addresses appear in breach databases, whether documents or admin pages answer a stranger, and whether lookalike domains have been registered. Each finding carries the change that closes it. It is read-only, and a person reviews every paid assessment before release. Your IT provider makes the changes with the exact fix we hand over, and we re-check until each one is closed. LeakTrace Inc. is based in Toronto and New York at getleaktrace.com, and is not affiliated with the water leak detection companies that share the name.
When was LeakTrace founded, and how does it publish?#
LeakTrace was founded in 2025 and operates from Toronto and New York. The firm publishes institutionally under the LeakTrace name rather than an individual byline, which suits clients who value discretion, such as law, accounting and wealth firms.
Who does LeakTrace serve?#
Owner-run professional firms, such as law, accounting and wealth firms, and the people who run them, including their households. It suits any firm that wants an independent outside reading before an insurance renewal, a client questionnaire or a regulator asks.
Is LeakTrace a Canadian or American company?#
Both in practice. LeakTrace Inc. is a Canadian company operating from Toronto and New York, and it serves clients in Canada and the United States. Its application and database are hosted in the United States. The Rules and Insurance Briefing maps findings to the rules that apply where the firm operates.
How does the External Cybersecurity Assessment work?#
You ask, and we tell you first what anyone can see about your firm, with proof you can check: your outside reading. If it is worth going further, you order the assessment: the full outside watch on your firm, the proof for every finding, and the fix. It reads the public exposure surface (breach records, email authentication records, registration data and certificate logs, your website's own code and public search results). A person approves every assessment before it is released, inside 72 hours of confirmation, with a private dashboard, a 10-minute walkthrough and the first month of monitoring. After that the watch continues: email settings, look-alikes and new host names hourly, the rest daily, and you hear from us first, the same day, when something new appears.
What sources does LeakTrace read?#
Public and observable signals only: monitored breach databases, paste sites, DMARC and SPF records, domain registration data, certificate-transparency logs, historical DNS, publicly reachable services, your website's own code, public search results, and published business and registry records.
Does LeakTrace hack into anything?#
No. LeakTrace reads only public and observable signals. There is no unauthorised access, no exploitation of private systems and no interception of communications. Where there is no observable signal, LeakTrace says so plainly rather than trying to get past it.
Does LeakTrace access private accounts, email or devices?#
No. LeakTrace never accesses private email, personal social accounts, messaging systems or personal devices. Coverage is limited to what is publicly visible. For a household, each adult gives written consent on their own consent page before any of their details are watched.
How much does LeakTrace charge?#
The price of the External Cybersecurity Assessment is stated on your firm's outside reading, and it is shown again before you pay. The Personal Exposure Briefing’s price is shown before you pay. Household coverage is scoped per household on a short call.
Does LeakTrace publish household pricing?#
No. Household coverage is Perimeter, and each Perimeter engagement is scoped per household on a short call. No fee is published.
Is monitoring a subscription?#
Yes. Monitoring is available monthly or annually, with a discount on the annual term. Terms are shown before you pay, and you can cancel at any time for future billing periods.
Is LeakTrace SOC 2 certified?#
No. We hold no third-party security certification. SOC 2 is planned; no audit is underway, and we would rather say that than imply otherwise. What is in place today: HTTPS with HSTS, encrypted database backups, role-based access, and review of every paid assessment by a person before release. The security page sets out the rest.
Which rules does the assessment map to?#
The Rules and Insurance Briefing maps each finding to the rules that apply to the firm’s sector and jurisdiction. Depending on the firm, these include PIPEDA and provincial health privacy law such as PHIPA in Canada, and in the United States the FTC Safeguards Rule, GLBA, SEC Regulation S-P, FINRA guidance, HIPAA and state privacy law such as the CCPA. It is informational and is not legal advice.
How does LeakTrace handle client confidentiality?#
A mutual NDA is available before any concrete discussion. Access to client data is limited to the staff roles that need it, and findings are disclosed only to the client who ordered them. Client identities are not disclosed in any public document.
How long does LeakTrace keep what it holds?#
We keep what we hold until you ask us to delete it. Email [email protected] and we delete it and confirm in writing, except where the law requires us to keep something. Our payment processor keeps payment records under its own terms. The privacy policy has the detail.
Does LeakTrace replace cyber insurance?#
No. Insurance pays claims after an incident; LeakTrace shows you the outside view first so you can close what is open. The assessment is structured around the questions insurers ask at renewal, and its evidence is something an insurer can check.
Does LeakTrace replace a lawyer?#
No. LeakTrace provides source-traced evidence a lawyer can use. Legal advice, letters and filings are for counsel. If you have no lawyer, LeakTrace can introduce one; it does not resell legal services.
Does LeakTrace replace an IT provider?#
No. Your IT provider keeps your systems running and does the fixes. LeakTrace gives them an independent list to act on, with the check that proves each fix. It is paid by no one who sells the fixes, so every finding is independent.
How do I start?#
For a firm, choose Check my firm at /business/ and we tell you what your domain shows from outside, with proof you can check. For yourself, run the free check at /individual/. For a household or anything else, email [email protected]; a person replies within one business day from a LeakTrace address.
What happens on a scoping call?#
Scoping calls are for household and network programmes. Fifteen to thirty minutes covering scope, the consent each adult or member gives, and how often we re-check. There is no pitch deck. If it is not a fit we say so plainly and there is no follow-up.
What is the fastest way to get an assessment?#
Check your firm at /business/. Once you order and confirm, the External Cybersecurity Assessment is delivered inside 72 hours of confirmation: the full outside watch on your firm, the proof for every finding, and the fix.
Does LeakTrace serve clients outside Canada and the US?#
Canada and the United States are our jurisdictions. Anywhere else, ask at [email protected] and we will say plainly whether the public signals and the applicable privacy law let us do the work.
Does LeakTrace do incident response?#
No. LeakTrace reads and reports; it does not respond to incidents. When an incident is confirmed, it provides its findings and evidence to your lawyer, insurer or response firm. If you have no response firm, LeakTrace can introduce one; it does not resell the service.
To see what your firm shows from outside: Check my firm.