For authorised intermediaries
A complaint shouldn't be your first alert.
It usually arrives weeks later, and by then it is late. A site imitating your brand is one we see when it requests its certificate: the logs are public, so you can reproduce our observations.
On your brand · no commitment
A sample of what the system observes. The suffixes are real, taken from Certificate Transparency logs; the brand is redacted.
- ██████-verify.comCritical
- secure-█████.ioLow
- ██████-connexion.frFRHigh
- ██████-c1 (substituted character, imitates: l) ienti.itITLow
- ███████-konto.deDECritical
- my-█████-wallet.appHigh
- ██████-accesso.itITCritical
- ██████-rn (substituted character, imitates: m) ercado.esESHigh
Certificate Transparency logs are public: you can reproduce these observations yourself. The brand is redacted because naming it would be attributing. Severity is a technical measure, not a legal qualification — that rests with the competent authority.
The problem
Evidence window — closed
The site is gone in a few weeks. The complaint reaches you.
It promotes, attracts clients, then disappears. By the time a report arrives the site is often already offline, and with it the evidence you need to reconstruct what happened and when.
How it works
From certificate to evidence you can use
Three automated steps. At the end you hold a dated, verifiable copy of the site, ready to attach to a report.
- 01
Listen
We see every new domain the moment it requests a certificate.
- 02
Match
We check the name against your brand and its variants.
- 03
Evidence
A copy of the site with an integrity hash, ready for compliance and reporting.
Observatory · July 2026
What we see across the sector
Automated detection from Certificate Transparency, 30-day window. Aggregate data, no party named: indicators, not determinations.
Read the observatory- 14,340domains analysed
- 5,119high-risk profile
- 1,669aimed at Italian investors
- 317with strong signals toward Italy
Offer
Scout, then Monitor
Same monitoring. A free one-shot snapshot, or continuous cover.
For banks, investment firms and asset managers serving retail clients. Public logs, hashed evidence, infrastructure in the European Union. No investor profiling.
How to check us
Don't wonder whether to trust us. Check.
The signal is public.
Certificate Transparency logs are open to anyone: you can reproduce our observations.
The method is documented.
How we classify, on which indicators, with which limits.
Methodology →The evidence is verifiable.
Every snapshot carries an integrity hash you can check yourself.
The proof costs nothing.
The analysis runs on your brand before any commitment.
Request the free analysis →
let's work
Start with the free analysis
Free analysis: see your brand's exposure, 15-minute call, then Monitor.
Reports are reasoned technical hypotheses. Legal characterisation and removal remain with the competent parties.
Institutional path for supervisors For authorities →