Platform

The instruments of the watch.

One platform, a handful of parts, each named for the job it does. Some of it is live in the portal today and most of it is being built right now. Every part carries a label saying which, because a threat intelligence company that inflates its own claims shouldn't be trusted with yours.

Live
In the portal today
Building
Under construction now
Designed
Specified, build queued
Roadmap
Planned

01 / Collection

Getting to the source without crossing the line.

Original collection

Gleaner

Building

Collection from the places stolen data is shared in the open: Telegram channels, underground and onion forums, leak sites and paste sites. It runs on isolated infrastructure, kept apart from the platform, and it only ever reads. We don't buy data, pay actors or trade.

And she went, and came, and gleaned in the field after the reapers.

Ruth 2:3 KJV
Isolated parsing

Threshing Floor

Designed

An offline, unprivileged floor for stealer-log archives. It keeps the text that matters (credentials, cookies, autofill and host details) and deletes everything else unopened. Nothing collected is ever executed.

He will throughly purge his floor, and gather his wheat into the garner; but he will burn up the chaff.

Matthew 3:12 KJV

02 / Analysis

Separating the real from the recycled, at machine speed.

Novelty and authenticity

Discern

Building

Every artifact is de-duplicated against the whole corpus, so a "new breach" that is mostly old data gets labeled as exactly that. Stealer logs are told apart from recycled combo lists, and every source carries an Admiralty-style reliability grade.

Beloved, believe not every spirit, but try the spirits whether they are of God.

1 John 4:1 KJV
Provenance and confidence

Witness

Building

Each record keeps the source, the first-seen time, the surrounding post and a confidence grade in plain language. Attribution is stated as "consistent with", never as fact.

In the mouth of two or three witnesses shall every word be established.

2 Corinthians 13:1 KJV
Agentic analysts

Watchmen

Designed

AI analysts that read the collection as it arrives: triage, translation, entity extraction, source discovery and first-draft briefs. Their limits are enforced in code: no buying, trading or soliciting, text only, collected content treated as hostile, and a person approves every new source.

I have set watchmen upon thy walls, O Jerusalem, which shall never hold their peace day nor night.

Isaiah 62:6 KJV

03 / Investigation

Following a thread from one email address to everything around it.

Global search

Lampstand

Building

One search across retained posts, chats, pastes and credential records. Pivot from an email address to the post it appeared in, the channel that posted it, and everything else that channel has shared. Secrets stay masked in results.

For nothing is secret, that shall not be made manifest; neither any thing hid, that shall not be known and come abroad.

Luke 8:17 KJV
Restricted evidence vault

Ark

Designed

When an authorized investigation needs the complete credential or session evidence, it is held encrypted under separate key custody, opened only after step-up authentication, scoped to the case, audited and set to expire.

And thou shalt put into the ark the testimony which I shall give thee.

Exodus 25:16 KJV

04 / Response

Getting the warning to someone who can act on it.

Alerts

Shofar

Designed

Alerts for new exposures on your verified domains, sent to email, Slack, webhooks or your SIEM, with a severity that reflects what was actually stolen. A live session cookie outranks a five-year-old password.

If when he seeth the sword come upon the land, he blow the trumpet, and warn the people.

Ezekiel 33:3 KJV
Guided remediation

Restore

Roadmap

Remediation through your identity provider: force a reset, revoke sessions and close the finding from the same screen. Entra ID and Okta first.

And I will restore to you the years that the locust hath eaten.

Joel 2:25 KJV

05 / Foundation

The parts that are already running.

MSP console

Shepherd

Live

The multi-tenant console. MSP staff reach every client organization from one sign-in with per-client roles. Customers only see domains they have proven through DNS. Findings move from new to acknowledged to resolved or false positive, API tokens are scoped and expiring, and the audit log can't be edited, even from the database.

What man of you, having an hundred sheep, if he lose one of them, doth not leave the ninety and nine in the wilderness, and go after that which is lost, until he find it?

Luke 15:4 KJV
Sign-in and access

Gate

Live

Sign-in held to the standard we'd ask of you: passkeys, single sign-on through Okta, Entra ID, Google or any OIDC provider, or a password with an authenticator app. No SMS or email codes. Organizations can switch to phishing-resistant sign-in only.

He that entereth not by the door into the sheepfold, but climbeth up some other way, the same is a thief and a robber.

John 10:1 KJV

06 / Build it with us

Help decide what gets built next.

Design partners get early access and a direct line into the roadmap. We're starting with MSPs and small security teams.