When AI sends your client to the wrong number
Your clients now ask an AI assistant for your phone number or your client login. The answer comes from pages your firm does not control. A wrong one sends the client to whoever answers. We ask the same questions first, check each answer against your own website, and show you what your clients are told.
Attackers now use AI to read a firm from outside the way a search engine does: the website, directories, search results and what AI assistants say. We read it first, and every finding is human-verified before your assessment is released.
Four answers that send a client to the wrong door.
On 29 September, SecurityWeek reported Users searching for ChatGPT: the way in was an AI answer pointing people to the wrong place.
A client asks for your number and is given one that appears nowhere on your website. It may be an old line, a directory’s number or somebody else’s. We show you the number and the answer it came in.
A client asks where to sign in and is sent to a page off your domain. A sign-in page you do not control can collect your client’s password.
In the assessment we also ask how to pay you and where to send a wire. An answer that gives bank details, or a payment page off your domain, is shown to you word for word.
Sometimes an assistant gives a web address for your firm that no one owns. We check whether each address it gives is registered, and whether it is yours.
Proof, not scores. Every finding carries its evidence.
A wrong answer is a fact to correct. We say where it came from.
We do not tell you that a wrong answer is fraud, or who put it there. An answer can be wrong because a directory is out of date. What we give you is the question, the answer, the date and the page it came from, and the correction for that page.
A different job from the people you already work with.
Excellent at running your systems, and makes the changes. We read what the outside world sees and hand them the exact fix, with the check that proves each one. Different job, and independent: we are paid by no one who sells the fixes.
Tries to break in and needs access. We are not a pen test: nothing attacked, nothing installed, no access given. We read only what is already public, from outside, and log into nothing.
Feeds your premium and eligibility. We show you the same outside view first, in plain words, so you walk into renewal knowing the answers.
See what AI assistants tell your clients about your firm, before a client acts on it.
The External Exposure Check: your outside reading, the openings a stranger can see on your firm today, each with its proof. Read-only, from outside.