Where our visibility ends

We won't tell you
you're safe when we don't know that.

A green scan is not a promise of total safety, and no security vendor can honestly make one. Here is exactly what we watch, exactly where our visibility ends, and what to do about each gap — before you sign up, not after an incident.

What we do watch

  • Continuously scan your internet-facing domains, DNS, TLS, headers, and public infrastructure
  • Watch for leaked secrets, exposed services, and vulnerable software versions
  • Alert you in plain language, by email and WhatsApp, the moment something changes
  • Auto-fix what we can reach directly (DNS records, Cloudflare rules) and hand you exact steps for the rest

What we do not protect

These 8gaps are structural — no scan, no connected integration, and no plan upgrade changes them. Each one routes to a real next step, not a feature we're about to sell you.

  1. 01

    Malware, infostealers, and ransomware running on your computers

    Ransomware and infostealers execute on a laptop or server, and we have no software installed there — we watch your internet-facing surface, not your devices. By the time we could see any trace of it (a stolen credential surfacing in a breach dump), the damage is already done.

    What to do: Deploy endpoint detection and response (EDR) or managed detection and response (MDR) on every device that touches your business data.

    EDR/MDR partner
  2. 02

    Stolen login sessions and MFA-bypass attacks

    Adversary-in-the-middle (AiTM) phishing kits can steal a live session token right after someone enters their password and MFA code, letting an attacker in without ever needing the password again. That theft happens on your staff's own device and browser, outside anything we can see from outside your network.

    What to do: Move your highest-value accounts to phishing-resistant FIDO2 security keys or passkeys — the theft technique that steals a password-plus-MFA session can't intercept them.

    Phishing-resistant MFA (FIDO2/passkeys)
  3. 03

    Payment fraud from a vendor's own real mailbox

    When a criminal takes over a supplier's actual email account and sends a genuine-looking invoice with new bank details, there is no spoofing of your domain for us to catch — the email really did come from them, it's just malicious. This is one of the largest sources of payment-fraud losses, and it never touches anything we scan.

    What to do: Verify any bank-detail change by phone, using a number you already have on file — never a number from the email itself. Make this a permanent habit, not a one-time fix.

    Payment-verification process
  4. 04

    Phishing email that lands in your inbox

    We secure your domain against being used to spoof other people (SPF/DKIM/DMARC); we do not filter what arrives in your staff's inbox. A phishing email sent from a look-alike domain, or from an account compromised somewhere else entirely, is invisible to us.

    What to do: Put an email-filtering vendor in front of your inbox, and run regular phishing-awareness training so staff catch what the filter misses.

    Email filtering + staff training
  5. 05

    Exploits against VPNs, firewalls, and remote-access boxes

    We detect that a vulnerable VPN, firewall, or RDP appliance is exposed to the internet, and we alert you within minutes of a known exploit going active. We cannot patch it for you — that box is infrastructure only you, or your IT provider, can reach.

    What to do: Treat any alert on an internet-facing VPN, firewall, or remote-access appliance as top priority and patch it immediately.

    Your patching process
  6. 06

    Data leaving your network

    We work to prevent the visible entry paths attackers use to get in. Once someone is already inside, we cannot see data being copied out — most modern ransomware attacks steal data before encrypting anything, and that theft happens on your internal network, never on your public-facing surface.

    What to do: Pair us with an incident-response retainer and an egress-monitoring or data-loss-prevention partner that watches outbound traffic from inside your network.

    Incident response + egress monitoring
  7. 07

    Flaws behind a login (authenticated application testing)

    We deliberately do not log in and test the parts of your application that require authentication. Broken access control, insecure direct object references, and business-logic flaws inside a logged-in area are out of scope by choice, not an oversight — that kind of testing needs explicit authorization we don't have from outside.

    What to do: Commission an annual penetration test that specifically covers the authenticated areas of your application.

    Annual penetration test
  8. 08

    Insiders, physical access, deepfake fraud, and shadow SaaS

    A careless or malicious employee, someone walking into your office, a deepfake video call impersonating your CEO, or a team quietly signing up for an unapproved SaaS tool — none of these leave any trace on your internet-facing surface for us to find.

    What to do: Cover these with employee training, a same-day offboarding checklist, a callback-verification habit for unusual requests, and a lightweight approved-tools policy.

    Security-awareness training