For brokerages and trading platforms

An impersonation incident is a filing, not a refund.

When a cloned portal takes a client credential, the cost is not only the money. It is the disclosure, the regulator asking what you did about it, and the answer being on a timeline you did not control.

Fit

Who this is for

Retail brokerages, trading platforms, and registered advisers. Especially where compliance is a named person rather than a department.

Threats

What gets copied

Cloned client portals

A copy of your login taking account credentials, often behind a search ad for your own brand. The client believes they were on your site, and their account statement will say otherwise.

Spoofed advisor communications

Letters and statements on lookalike domains used to redirect transfers. Your name, your letterhead, an account number that is not yours.

Fake “verification” and account-recovery flows

Triggered by market events, when clients are anxious and checking positions more often than usual.

Impersonated support and signal groups

Telegram and WhatsApp groups using your brand to sell access or solicit deposits, with no connection to you at all.

Stakes

The numbers that matter

On record

What a regulator asks for

When you knew, what you did, and how long it took. Those are the three numbers this product produces by default.

Sealed

Evidence, before any notice

Hashed and timestamped at discovery — which is what makes it usable months later when the page is long gone.

Per case

Time to removal, reported

Not detection counts. The number you can put in front of a compliance committee.

Scan your own domain and see what is public. It takes about thirty seconds and needs no card.

Plan

Start on Professional

$2,500per month · 5 brands · 25 domains

Professional includes DMCA and UDRP evidence packets prepared for your counsel, and monthly removal-rate reporting suitable for a compliance file.

Questions

The ones people actually ask

Will this create a disclosure obligation we did not have?
That is your counsel’s call, not ours, and we will not pretend otherwise. What we would say is that the obligation usually attaches to the incident rather than to your knowledge of it — and that "we had no monitoring" is a worse position than "we found it and removed it in nine hours".
Can we get the evidence in a form our lawyers can use?
Yes. Each finding carries the captured page, a SHA-256 hash, the resolving address, and a timestamp. Professional prepares DMCA and UDRP packets from that; Enterprise prepares them to an evidentiary standard for litigation.
Do you send anything without our approval?
Never. Nothing leaves under your name until you have seen the match and the evidence, and we will argue against sending a notice if we think the target is a legitimate business with a similar name.

More in the full FAQ.