Scope · the register

Everything we read, and everything we leave alone.

This is the page to forward to whoever is asked whether it is safe to let us do this. Five sources, one of which runs inside your own browser; two checks deliberately switched off until you prove the domain is yours; and a list of things we will not do at any tier or any price. Set out as a register rather than a pitch, so it can be checked line by line.

Sources
Four public records · one in-browser check
Contact with you
One public DNS lookup, and nothing else
Switched off
Two checks, until you verify the domain
Cost
Free · one domain · once every 30 days

01 The sources

Five things we read, and who publishes each one

Every row below is already published about your domain by somebody other than you — your DNS operator, a certificate log run by a third party, the domain registry. We are reading the same records a criminal would start with, and we are reading them in the same way: from the outside, with no privileges, and with nothing installed anywhere.

Free snapshot · sources read on an unverified domain
Source What it shows Who publishes it Reaches your systems?
DNS records A · AAAA · MX · NS · TXT Where your website resolves, who runs your nameservers, which mail servers you publish, and what stray records an old supplier left behind. Your DNS operator, answered by whichever nameservers are authoritative Yes — one ordinary public lookup
Mail posture SPF · DKIM · DMARC Whether a stranger can send email that appears to come from your domain to your guests, patients or suppliers. You, in the TXT records above — no separate source is queried No — read from the same lookup
Certificate transparency CT logs Every HTTPS certificate ever issued for your domain, including the internal-sounding hostnames a business never meant to publish. Certificate authorities and log operators — third parties, not you No
Domain registry RDAP Your registrar, when the registration expires, and whether the domain is locked against transfer. The registry and your registrar No
Password check In your browser · optional Whether a password you use has appeared in a known public breach. You choose whether to run it at all. A public breach index run by Have I Been Pwned No — and nothing reaches us either

The password check is the one row you control completely: it runs on your device, only the first five characters of a fingerprint of the password are sent, and they go to a public breach index rather than to us. There is no page on this site that asks you to type a password and send it here. Background on all five sources: what a stranger can already see.

02 The claim

The same sentence is returned by our intake service in every response, so the page and the contract cannot drift into two different promises.

Stated exactly, including the part that is not absolute

What we do

We read public records — DNS, mail records, certificate transparency logs and the domain registry. We never connect to your website or servers, never log in, and never test your defences.

What we will not tell you is that nothing of ours ever reaches anything of yours. Looking up a domain asks whichever nameservers are authoritative for it, and those may be machines you or your provider run — so a lookup of the ordinary kind every mail server on the internet makes to find you is the one point of contact. Any supplier claiming their outside-in check reaches nothing at all is describing something that cannot be done.

Everything else in the register above is read from records held by third parties. Nothing we do opens a connection to your website, your ports or your applications, and on a domain whose control you have not verified that is enforced in our software rather than promised in our marketing.

03 Switched off

Two useful checks we are not allowed to run yet

These are worth having and we are not withholding them to sell you something. They connect to your systems, Kenyan law requires your permission first, and permission means a record that you gave it — not a checkbox on a form anybody could have ticked.

Checks that require your permission, and what grants it
Check What it would tell you Why it is off What turns it on
What your website actually serves Whether an admin panel, an old staging site or a forgotten application is reachable from the public internet. It requires an HTTP request to your server, which is a connection to your system. Domain verification — about ten minutes, and the check is still free
How your TLS is configured Whether your certificate, protocol versions and cipher configuration are current, and when the certificate expires. It requires a TLS handshake with your server, which is a connection to your system. Domain verification — about ten minutes, and the check is still free
Changing anything you own Nothing on its own. This is the fix work rather than the reading. We would be altering your configuration, so your instruction has to exist as a record. A paid engagement you asked for. The sprint that connects to your systems needs verification or written authorisation as well

Proving domain control takes about ten minutes: a DNS record we give you, a file on your web server, or a code sent to an address at your own domain. The reason the line is drawn here rather than somewhere more convenient is Kenya's Computer Misuse and Cybercrimes Act 2018, as amended in 2025, which separates reading what is published from connecting to somebody's system to test it. The second needs their written authority, and Kenya has no responsible-disclosure safe harbour.

04 Never

Not at any tier, and not at any price

  • We do not attempt to break in

    No exploitation, no password guessing, no attempt to get past anything. This is not a penetration test, a security audit or a vulnerability scan, and we do not sell one. Nothing changes that at any tier or any price.

  • We do not test your people

    No phishing simulations, no calls to your reception pretending to be a supplier, no approaches to your staff at all. If you want that done, it is a real and useful exercise and somebody else sells it.

  • We do not assess a domain nobody asked us to

    A snapshot exists because somebody at that business asked for it and confirmed they were authorised to, and their confirmation is stored with the exact wording they were shown. A business can also ask us never to assess its domain, and we keep that refusal permanently.

  • We do not publish what we find

    Findings go to the business, privately. We do not name anybody in marketing, do not use a serious finding as a sales lever, and do not write case studies about somebody else’s weaknesses. Where something has wider public consequences, the route in Kenya is the national response team, KE-CIRT, not a press release.

  • We do not watch anything afterwards

    A snapshot is one day’s picture. No monitoring, no alerting, no incident response and no response-time commitment. The monthly option is a person re-reading the same public records and writing to you, which is a different thing and is described as one.

  • We do not sell you compliance

    Nothing here makes a business compliant with the Data Protection Act. It is documented evidence about one technical control — your external exposure — which is a real part of what the Act expects and is not the whole of it.

05 What you get

A person reads all of it before it is sent. That is the expensive part of this service and it is the reason the report is short.

Five records in, one plain-language report out

What comes back is not a dump of the records above. It is an A to E rating with the findings that produced it, a stated confidence level, the three issues that matter most for a business like yours in ranked order, what is already working, and a 30-day plan. It arrives by email in one to two business days.

It also states its own limits on the front page. A free snapshot rests on external evidence alone, so it is never rated high confidence, and it cannot see your internal network, your staff devices, your point-of-sale or your Wi-Fi. Read a complete worked example — thirteen findings on a fictional hotel — in the sample report, or read how one is produced.

One free snapshot per domain every 30 days. We read public records — DNS, mail records, certificate transparency logs and the domain registry. We never connect to your website or servers, never log in, and never test your defences. This is not a penetration test.

Find out what a stranger already knows about your business

One domain, read from public records, written up by a person and emailed to you in one to two business days. Free. Nothing to install, no payment details, no account.

Get my free snapshot Read a sample report first