Trusted security · Built from London
Products
Platform

The platform, from the outside in.

Hand us a domain. We’ll discover every asset, scan it across six disciplines, score the findings, push them to your stack, and watch your rating change as you fix them.

STAGE 01

Discover

From a single domain we fan out: passive DNS, certificate transparency, ASN data, Wayback, search engines, public buckets, code repositories.

STAGE 02

Attribute

Every asset gets attributed to your organisation with confidence scoring. You can refute attribution at any time; the model learns.

STAGE 03

Scan

Six modules run continuously. Each finding includes evidence (screenshots, banners, headers, registry data) and a severity score.

STAGE 04

Score

Findings roll up to module scores, then to a company rating. Asset-weighted, geometric mean, compliance-mapped.

STAGE 05

Route

Findings push to Jira, ServiceNow, Slack, your SIEM, or via webhook. Owners get notified. SLAs start ticking.

Architecture

Non-intrusive by design.

No agents

Guardian Gaze never asks you to install anything. We work the way an attacker works, from the public internet, looking in. No credentials to manage, no production risk, no procurement battle.

No invasive scans

Banner-grabbing only. No active exploitation, no payload delivery, no DoS-shaped behaviour. Every probe is rate-limited and logged. We’ll send you a list of source IPs to allow-list if you want them in your logs.

Evidence-first findings

Every finding includes the raw evidence we saw: HTTP response, certificate chain, DNS record, page screenshot, registry data, leaked-credential timestamp. No hand-wave classifications.

Refute anything

See a finding you disagree with? Click refute, send a note, attach evidence. An analyst reviews within one business day.

Built for your data, not ours

Your findings, your domains, your vendor list, your evidence, yours. Export everything via API, CSV or signed PDF at any time. We sign a DPA on request; data lives in EU regions by default.

Data sources

Where the findings come from.

Twelve primary feeds, dozens of secondary sources, all reconciled into a single evidence record per finding.

DNS

Authoritative + recursive resolvers across 6 regions, plus passive DNS feeds (Farsight, SecurityTrails, CIRCL).

CERTIFICATES

Certificate Transparency log ingestion (4 major logs), real-time. Used for subdomain discovery and certificate hygiene.

REGISTRY

WHOIS (registrar APIs + thick WHOIS where available), RDAP, ASN registry data.

PUBLIC WEB

Page DOM, security headers, JavaScript inventory, Wayback Machine historical content, search engine indices.

VULNERABILITIES

NVD daily sync, CISA KEV catalogue, exploit-DB, GitHub Security Advisories, vendor advisories.

DARK WEB

Breach forums, ransomware leak sites, paste sites, Telegram channels, IRC dumps. Indexed and full-text searchable.

REPUTATION

AbuseIPDB, Spamhaus, Talos, GreyNoise, Surbl, URLhaus, Phishtank, OpenPhish.

CLOUD

Public IP space attribution for AWS, Azure, GCP. Bucket / blob / GCS enumeration. Origin-IP leakage via cert + DNS.

CODE

Public repository scanning for secret leakage. GitHub, GitLab, Bitbucket, pastebin and code-search engines.

Read the scoring methodology, then get a rating.