What you get, before you commit.
For a firm, the External Exposure Check and the External Cybersecurity Assessment it leads to. For a person, the free address check and the Personal Exposure Briefing after it.
What arrives, and what we never need.
Read-only, from outside, from public sources only.
An outside view of your domain.
Is your address in a public breach?
Here’s what anyone can already see about your firm.
Attackers use AI to find openings. We use it to find yours first, and a person checks every finding before you see it.
One site for both countries. Each finding is mapped to the rule where your firm is.
United States
FTC Safeguards Rule: tell the FTC within 30 days.
Tax preparers, mortgage brokers and other financial institutions notify the FTC no later than 30 days after discovering a breach of 500 or more people.
Source: FTC, Safeguards Rule guidance.
- Law
- GLBA Safeguards Rule, 16 CFR 314
- Regulator
- Federal Trade Commission, and your state attorney general
- Checkout currency
- US dollars (USD)
Canada
PIPEDA: report a breach as soon as feasible.
Report to the Privacy Commissioner when a breach creates a real risk of significant harm, and keep a record of every breach for 24 months.
Source: Justice Laws Website, PIPEDA.
- Law
- PIPEDA s. 10.1
- Regulator
- Office of the Privacy Commissioner of Canada
- Checkout currency
- Canadian dollars (CAD)
See how a finding is explained, and how the 72 hours run.
What a finding looks like
Captions on, no sound. Illustrative finding; no firm is shown.
Read the transcript
- p=none. Anyone can send email in your name.
- A public DNS record for a firm: its email authentication setting.
- The setting that fails: p=none. Email in the firm's name can be forged.
- p=none is monitor mode. Mail servers are told to report a forgery, not to stop it.
- Delivered in your firm's name: a forged invoice, a fake payment instruction, a request for client records.
- The fix in three steps: read the reports, move to quarantine, then reject.
- Forged mail refused. Your own email still delivered. One public record changed.
- 8 in 10 professional firms cannot stop an email sent in their name.
- One finding, read from outside. Every finding at your firm, in one assessment.
How the 72 hours run
From confirmation to delivery, nothing installed and nothing logged into. Captions on, no sound.
Read the transcript
- 72 hours. One domain. Nothing to install.
- What happens in the 72 hours of an External Cybersecurity Assessment.
- You confirm the scope: one domain, your firm's. Nothing to install, no access to give.
- We read what anyone can see from outside: mail records, look-alike domains, staff addresses in monitored breach databases, website software, sign-in pages. We log into nothing.
- A person checks every finding and approves the release. Each one comes with a check anyone can run.
- Three documents and a signed summary: the Owner Summary, the Technical Evidence for your IT provider, the Rules and Insurance Briefing, and the Signed Assessment Record.
- Your IT provider gets the exact fix for each finding; we re-check until it is closed. A 10-minute walkthrough, and the first month of monitoring, are included.
- Inside 72 hours of confirmation.
Link to these videos: getleaktrace.com/see-it-first/
- A real client's documents, dashboards or names
- Testimonials or logos
- Prices