For developer platforms

A cloned login page for your product harvests API keys.

Your users hold credentials that reach production systems — theirs and their customers’. A convincing copy of your sign-in is worth far more than one account, and your security function is probably one person with other responsibilities.

Fit

Who this is for

Infrastructure, database, auth, and observability platforms with self-serve signup. The size where security.txt exists but nobody owns brand monitoring.

Threats

What gets copied

Cloned dashboards and sign-in pages

Harvesting the credential that reaches production. The blast radius is not one account — it is every environment that key touches.

Typosquatted package names

Packages on npm or PyPI using your name, installed by autocomplete and typo. We watch the registries alongside the domains.

Fake docs and quickstart pages

Copies of your documentation that rank in search and route developers to a lookalike console. Often the highest-traffic clone, because docs get linked from everywhere.

Impersonated support in developer communities

Accounts in Discord and forums using your brand to offer help, then a link to a “debug console” that is not yours.

Stakes

The numbers that matter

Production

What a stolen key reaches

Not a consumer account. Their systems, and often their customers’ data.

Registries

Watched alongside domains

npm, PyPI, GitHub and GitLab, because for you the typosquat is as likely to be a package as a domain.

No access

Integration required

Everything we use is public. There is nothing to review and no credential of yours we could lose.

Paste your domain into the public scan. You will see exactly what we can see, which is exactly what an attacker can see.

Plan

Start on Essential

$499per month · 1 brand · 3 domains

Essential is usually right to start: daily monitoring, page-level clone verification, code and package registry sweeps, and up to ten takedown cases a month.

Questions

The ones people actually ask

We publish a security.txt and get reports already.
You get reports about flaws in your own systems. Nobody reports a lookalike domain to you, because the person who sees it is a developer who assumes it is yours — which is the whole problem.
Is this not just certificate transparency monitoring, which is free?
The watching is free and you should do it. What is not free is opening every candidate to check whether it reproduces your page, and then spending a week getting it removed. That is the part we sell.
Do you cover package registries or only domains?
Both. For your segment the registries often matter more, and they are included from Essential rather than held back for a higher tier.

More in the full FAQ.