Built from London by GuardianGaze Limited.
Guardian Gaze is built by GuardianGaze Limited, a London cybersecurity team with backgrounds in offensive security, detection engineering and large-scale platform engineering: senior engineers, threat researchers and analysts, alongside an advisory group spanning cloud, infrastructure and SaaS.
How the team is organised
A small, full-time team across four functions, each shipping features end to end. We do not list individual names publicly during this build phase, happy to make introductions on a call.
Scanners, signals, intel feeds
Owns the scanners across the six modules. Maintains the dark-web monitoring feed and the breach-dataset pipeline, and develops new detection logic across application, network, domain and brand surfaces.
Scan orchestration, data, API
Owns the scan-job pipeline, the cluster, the REST API and event delivery. Multi-tenant isolation, scoped cloud integrations, and webhook delivery into your stack.
Dashboards, reports, takedowns
Designs the company dashboard, the reports library, alerts views, the takedown workflow, the MITRE ATT&CK lens and the compliance mapping interface. Writes the documentation.
Disputes, takedowns, customer success
Reviews disputed findings, runs the brand-takedown workflow end to end, onboards new customers and owns the response queue.
Detection quality is a function of who writes it
Security ratings are only as good as the judgement encoded in them. Deciding that a particular exposure is critical rather than moderate, that a version match is a genuine finding rather than a backported patch, or that a lookalike domain is preparation rather than coincidence, none of that is automatable, and all of it comes from people who have done the work.
That is why the team's background is offensive security and incident response rather than compliance tooling. The model reflects what actually gets exploited, in what order, by people who have been on both sides of it.
It also shapes what we decline to claim. A team that has run incident response knows the difference between an external assessment and an audit, which is why the boundary is stated on every module page rather than blurred.
Four functions, each shipping end to end
Research builds detection and validates findings. Platform engineering builds the discovery and scoring infrastructure. Product decides what gets built and what gets refused. Customer engineering works directly with design partners on findings quality and workflow fit.
Each function ships end to end rather than handing work across a boundary, which matters more at this size than any process. The person who wrote a detection is the person who hears when it produces a false positive, and that loop is where accuracy actually comes from.
It also means a customer raising a findings issue reaches the research team rather than a support tier reading from a script. At our size that is achievable; we would rather build the company so it stays achievable.
London, small, and honest about the stage
GuardianGaze Limited is a London company registered in England and Wales, and a subsidiary of RedSecLabs, a security research practice with a background in offensive security and incident response.
Both products came out of investigating real compromises rather than from a product roadmap. The WordPress plugin exists because filesystem-only cleanups kept getting reinfected from the database; the enterprise platform exists because vendor questionnaires kept describing organisations that looked very different from outside.
We are early, we run design partner engagements rather than presenting a customer roster, and we would rather say that than assemble a logo wall. The buyers we want are the ones who check.
Common questions
Who is behind GuardianGaze?
GuardianGaze Limited, a London company registered in England and Wales and a subsidiary of RedSecLabs, a security research practice with a background in offensive security and incident response.
Why does the team's background matter for a ratings product?
Because severity judgement is not automatable. Deciding that an exposure is critical, that a version match is a real finding rather than a backported patch, or that a lookalike domain is preparation rather than coincidence comes from people who have done the work.
Do customers reach the research team?
Yes, for findings issues. At our size that is achievable, and we would rather build the company so it stays achievable than route accuracy questions through a support tier.
Where did the products come from?
Investigating real compromises. The WordPress plugin exists because filesystem-only cleanups kept getting reinfected from the database; the enterprise platform exists because questionnaires kept describing organisations that looked very different from outside.
Are you hiring?
Yes, across all four functions. London-based and remote-friendly within the UK.
Talk to the people who built it
The walkthrough is run by the analyst operations team, on a domain you control.
You join a call with a security analyst, not an SDR.