Services

What we do, and what you get when you hire us

External Blind Assessment

We start with a domain, a name, or a location. Nothing else - no access, no interviews, no internal documents. The result is what a capable outsider would have on you before making contact: exposed infrastructure and forgotten assets, credentials surfacing in breach data, corporate and regulatory filings, public records, your employee footprint, and what third parties have published about you without asking.

You get a structured picture of your external attack surface and public exposure, with what's actionable separated from what's merely visible.

Executive & Personal Exposure

For executives, public figures, and families where visibility has become a liability. We assemble what's reconstructable about a person: their movements and routine, their residence, the people around them, and their household - drawn from data brokers, property and public records, and their own published footprint.

You get a clear view of what an adversary could already build, and a prioritised list of what can realistically be removed, reduced, or worked around.

Social Engineering Exposure Mapping

Who in your organisation is publicly identifiable, what an outsider can reconstruct of your reporting lines, and which people are realistic entry points - through which channel, using what pretext, and why them specifically.

This is analysis, not testing. Nobody is contacted and nothing is attempted. Authorized simulation is a separate engagement under separate rules.

Due Diligence & Counterparty Investigation

Pre-transaction, pre-partnership, pre-hire. We establish who you're actually dealing with: beneficial ownership and real control, corporate structure across jurisdictions, litigation and insolvency history, regulatory findings, sanctions and PEP exposure, adverse media in the relevant languages, and the verified professional record of the person signing.

You get a documented picture of the counterparty and the specific issues that should change how the deal is structured - or whether it happens at all.

Financial Crime & Illicit Finance

We don't trace transactions. We trace the structures transactions move through: ownership, control, and connection. Entity resolution through nominee and layered arrangements. Network mapping across shared directors, addresses, and incorporation agents, because a front company is rarely alone. Sanctions and PEP adjacency - the part screening misses, where the name clears the list and the question is who sits two steps behind it. Procurement awards, property holdings, insolvency filings, and leak corpora.

Where digital assets are involved, we trace on-chain flow and cluster activity, and we tell you exactly where attribution stops. Following value to an exchange deposit is straightforward. Identifying who controls it requires legal process, and some venues won't answer that process at all. We mark that line rather than let a report imply we crossed it.

We are not a regulated AML function and don't present ourselves as one. Your compliance team screens a name against a list. We tell you what the name is connected to.

Third & Fourth-Party Risk

Your vendors are assessed. Their vendors usually aren't. We map the contractual chain past your direct suppliers - who they depend on, whose code is inside the products you've deployed, and where concentration sits when several vendors turn out to rest on one provider.

Where you need a baseline first, an engagement can start by assessing your current third-party risk posture and identifying what it isn't covering.

You get the dependency chain as it actually exists, with the points where a single failure reaches you named specifically.

Hidden Dependency Tracing

Not every dependency comes with a contract. Shared infrastructure, upstream providers common to suppliers who appear unrelated, single points of failure in resolution, certificate, or identity layers, and the components sitting inside products you bought as finished goods.

This extends to the AI and compute layer, where dependency concentrates faster than anywhere else in a modern stack. Which models, inference providers, and hardware your operations rest on; whose infrastructure those providers sit on; and which jurisdictions gain reach over your data or your continuity as a result. Sovereignty questions are dependency questions - where a capability physically lives, who controls it, and what happens to you if access is restricted by policy rather than by outage.

You get a map of the reliances nobody procured and nobody monitors, and an assessment of which ones would actually stop you.

Insider & Access Exposure

Dormant accounts, orphaned credentials, contractor access that outlived the contract, and departed staff who never lost the keys. The internal version of the same blind spot - exposure through something you already stopped watching.

You get an external view of what access appears to still exist, assessed without relying on the internal records that are usually the reason it was missed.

Litigation Support

Evidentiary intelligence for counsel and for individuals. Asset and ownership tracing, counterparty and opposing-party background, witness and party verification, compliance and settlement monitoring, and material developed to be examined rather than skimmed.

We maintain our own chain of custody from the point of collection, and every finding carries explicit confidence language so nothing in a report claims more than the evidence supports.

You get material that holds up when someone is actively trying to break it - and a clear statement of what we could establish, what we couldn't, and where the difference matters.

Verification & Allegation Assessment

An anonymous tip checked before anyone acts on it. A whistleblower claim substantiated or knocked down. A disclosure package assembled to survive scrutiny. Often pre-decision and pre-counsel - the work that determines whether there's a case at all.

You get an assessment of whether the allegation stands up, what corroborates it, what contradicts it, and what remains unresolved. Including when the answer is that the claim doesn't hold, which is a result worth having before it becomes an action you can't take back.

Geopolitical Dependency Intelligence

Geopolitical risk is normally read top down - the country report, the stability index, the regional outlook. It tells you a region is volatile, which you knew, and leaves you with nothing to act on.

We read it laterally. From an event, along the connections, to the specific dependency that reaches you: which carriers, which routes, which counterparties, which component in your tier two turns out to be single-sourced through a jurisdiction now under sanction. Second and third-order transmission mapping, where the cascading path terminates at your operation rather than at a national average.

Jurisdictional and regulatory exposure - where your data physically sits, which legal regimes reach it, and what localization or export controls do to how you operate.

Market entry and expansion - for organizations moving into a new jurisdiction: who you'd actually be transacting with, local counterparty and corruption exposure, regulatory reality against regulatory text, and which relationships turn out to be load-bearing.

You get the specific chain between a geopolitical event and your operation, and an honest read on which links are fragile.

Directed Intelligence Engagements

Some questions don't fit a category. A problem with no owner. A situation two other firms couldn't crack. A question everyone involved has already declared unanswerable.

Directed means what it says: we work against your requirement and nothing else. The question is defined with you at the outset, the scope is agreed before anything starts, and the collection and analysis are assembled around that specific question rather than pulled off a shelf.

Most things get called impossible for the same reason. Everyone reached for the same standard approach, it didn't work, and they concluded nothing would. Usually the way through was somewhere nobody thought to check.

Training & Simulation

We also run crisis simulations, social engineering training, and intelligence workshops for teams and institutions - including authorized offensive and defensive simulation under agreed rules of engagement.

See training

Who We're For

We take on what others turn down.

Individuals

Executives, public figures, families. People whose visibility has become a liability, or who are facing a specific threat and need to know exactly what they're dealing with.

Sometimes it's knowing what already exists about you before someone else uses it. Sometimes it's a person in your life who doesn't add up. Sometimes it's something you can't quite name yet, but you know is wrong.

Organizations

Facing a crisis. Going through a merger. Adding a vendor. Vetting a hire. Different situations, but underneath them the same blind spot.

Every one comes down to trusting something you can't fully see. A partner whose real ownership is buried. A supplier quietly out of compliance. An insider who left but never lost access. A deal that looks clean until someone actually looks. We show you what's there before you commit, not after.

Cost

We don't publish pricing. No two engagements cost the same, and scope is agreed with you before anything starts.

How we scope and what an engagement looks like → Our Method