A structured, analyst-led investigation of dark web markets, paste sites, breach corpora and threat-actor channels — not an automated scrape.
Most organisations learn their data is on the dark web only when something downstream goes wrong — a credential reused in an account takeover, a customer's data in a forum post, a leak nobody internally was tracking. By then the exposure has already happened; the open question is how long it has been sitting there.
A structured findings report: confirmed exposures with severity ratings, source attribution and remediation guidance. A clean result is documented with the same rigour as a findings-heavy one — the absence of confirmed exposure is itself a finding.
Analyst-led search across active and archived sources, distinguishing first-generation breach data from aggregated combo lists and assessing provenance of any leaked material found — not a keyword scrape.
Yes — it's commonly run ahead of renewal, as part of a post-incident review, in support of an executive protection programme, or simply as a first baseline check.
A clean result is documented with the same rigour as a findings-heavy one. Absence of confirmed exposure is reported as a finding in its own right, not omitted.
Every enquiry is reviewed by an analyst and routed to a scoping call — a fixed fee is confirmed in writing before any work begins.