Cloned dashboards and sign-in pages
Harvesting the credential that reaches production. The blast radius is not one account — it is every environment that key touches.
For developer platforms
Your users hold credentials that reach production systems — theirs and their customers’. A convincing copy of your sign-in is worth far more than one account, and your security function is probably one person with other responsibilities.
Fit
Infrastructure, database, auth, and observability platforms with self-serve signup. The size where security.txt exists but nobody owns brand monitoring.
Threats
Harvesting the credential that reaches production. The blast radius is not one account — it is every environment that key touches.
Packages on npm or PyPI using your name, installed by autocomplete and typo. We watch the registries alongside the domains.
Copies of your documentation that rank in search and route developers to a lookalike console. Often the highest-traffic clone, because docs get linked from everywhere.
Accounts in Discord and forums using your brand to offer help, then a link to a “debug console” that is not yours.
Stakes
Production
Not a consumer account. Their systems, and often their customers’ data.
Registries
npm, PyPI, GitHub and GitLab, because for you the typosquat is as likely to be a package as a domain.
No access
Everything we use is public. There is nothing to review and no credential of yours we could lose.
Paste your domain into the public scan. You will see exactly what we can see, which is exactly what an attacker can see.
Plan
Essential is usually right to start: daily monitoring, page-level clone verification, code and package registry sweeps, and up to ten takedown cases a month.
Questions
More in the full FAQ.