Connect your existing security stack in days. Read-only. Nothing changes in your environment.
Exhibit 1 — External Posture
We probe your external posture — SPF, DMARC, DKIM, security headers, certificate transparency, DNSSEC — before you share a single credential.
SPF, DMARC, DKIM validation across all sending domains
CSP, HSTS, X-Frame-Options, Referrer-Policy and more
CT log monitoring, expiry tracking, rogue certificate detection
Exhibit 2 — Internal Telemetry
Drop in an API key, OAuth token, or webhook URL. We normalise everything into a unified security model. Live in under a week.
API keys and OAuth tokens only
Your data stays in Sydney (ap-southeast-2)
We read. We never write.