Technical note · Edition 2026
Certificate Transparency for authorised intermediaries.Look-alike and typosquat detection at certificate issuance.
InvestShield watches public Certificate Transparency logs (RFC 6962), matches observed names against the authorised intermediary's brand perimeter, and freezes evidence at first-seen. It does not replace authorities or providers: it anticipates the window while the domain is still observable.
Operating path: Free analysis · Monitor · how the service works.
§ 1 · Context
Why the certificate is the useful moment.
A domain that imitates an authorised intermediary often has a short useful life. By the time a report arrives, the site may already be offline — and the technical evidence with it.
Issuance of a TLS certificate is a public, repeatable event. For compliance, antifraud and firms assisting intermediaries, it is an earlier entry point than complaints alone or manual ex-post search.
§ 2 · Certificate Transparency
Public logs, not opaque intelligence.
Certificate Transparency requires certificate authorities to publish issued certificates in append-only, auditable logs. InvestShield consumes these logs as the primary source: every name that requests a certificate can be matched against the brand perimeter defined by the client.
- Standard
- RFC 6962. Logs are public and designed for auditability of certificate issuance.
- Signal
- A certificate request is often earlier than full exposure of the site to investors.
- Limit
- CT alone does not prove abusive offering of services. It is a technical entry to the observable perimeter.
§ 3 · Types
Look-alike and typosquat.
Typosquat
Orthographic and typographic variants of the brand or official domain: omissions, transpositions, confusable characters.
Look-alike
Brand + trust or service terms, alternate TLDs, strings that evoke the intermediary's identity.
Classification is technical and descriptive. It is not a finding of unlawfulness nor a legal qualification of the offer.
§ 4 · Pipeline
Listen, match, freeze.
Three operating stages. The goal is a consultable dossier while the domain is still reachable.
- 01
Listen
Continuous ingest of Certificate Transparency logs. Every candidate name enters the match queue.
- 02
Match
Comparison with the brand perimeter and official domains of the authorised intermediary. Descriptive technical classification.
- 03
Freeze
Acquisition of evidence on the public perimeter (snapshot, metadata) with integrity hash and first-seen timestamp.
§ 5 · Principles
Four constraints that precede the product.
Independence
No authority, intermediary or firm determines which domains the engine analyses.
Methodological transparency
Evidence that generated a signal is retained and consultable in the dossier.
Proportionality
We do not publish open lists of suspect domains. Information stays in the client or institutional channel provided.
Respect for data
Public content only. Zero investor profiling. Infrastructure in the European Union.
§ 6 · Limits
What the method does not do.
A method with no stated limits is not a method: it is a promise. These are ours.
- CT sees certificates, not sites.
- A domain that never requests a public TLS certificate does not appear. Out of scope: sites served over plain HTTP, subdomains already covered by a previously issued wildcard, and domains registered before monitoring started.
- Log coverage is not total.
- We observe a set of Certificate Transparency logs. A certificate published only on logs we do not follow enters our window late, or not at all.
- Brand matching produces false positives.
- Generic brands and common words generate harmless similarities; legitimate homoglyphs and transliterations exist. Severity orders the work queue; it does not remove the error.
- We do not publish a false-positive rate.
- Computing one requires an independently labelled sample, which we do not have today. Stating a percentage without it would be an unfalsifiable number — exactly what this page exists to avoid. We publish the criterion instead, so you can estimate it on your own perimeter.
- A snapshot is an instant, not content monitoring.
- Frozen evidence reflects the moment of capture. If the page changes afterwards, the change is not in the snapshot: arriving before it disappears is the point of the method, and also its boundary.
- A verdict is not a legal characterisation.
- We produce reasoned technical indicators. Characterisation, orders and removal remain with authorities, registrars and hosting providers.
- When we get it wrong.
- Tell us: we review the case and, if the observation does not hold, we withdraw it from the queue. Evidence and the withdrawal stay on record, so that the error is verifiable too.
§ 7 · Data governance
Public data only, EU perimeter.
- Data source
- Public Certificate Transparency logs and published content of detected web pages.
- Location
- Data and application infrastructure in the European Union (Italy). Some analysis steps rely on third-party providers, including outside the EEA, on the public page content only: no client data leaves the EU perimeter.
- Chain of custody
- Every technical evidence item is retained with SHA-256 hash and timestamp. Suitable as documentary support, not as a judgment.
§ 8 · FAQ
Operational clarifications.
- What is Certificate Transparency and why does it detect look-alikes?
- It is the public log system (RFC 6962) where issued TLS certificates appear. A look-alike or typosquat that obtains a certificate leaves a public trace often earlier than full site diffusion.
- What is the difference between look-alike and typosquat?
- Typosquat imitates with typographic errors. Look-alike combines brand and trust terms or uses alternate TLDs. Both can confuse the authorised intermediary's client.
- Does InvestShield replace supervisory authorities?
- No. It is a technical provider. Legal qualification and orders remain with authorities and competent parties.
- Where is data hosted?
- In the European Union. We process public logs and publicly accessible pages. No investor profiling.
- What are the limits of the method?
- Certificate Transparency detects certificates, not sites: domains served over plain HTTP, subdomains covered by a pre-existing wildcard and domains registered before monitoring started stay out of scope. Brand matching produces false positives, especially on generic brands. We do not publish a false-positive rate because we have no independently labelled sample to compute one. A snapshot freezes an instant; it does not monitor content over time. A verdict is a technical indicator, not a legal characterisation.
Start
Begin with a free analysis of your brand.
One-shot analysis of the domains imitating your brand. Then, if useful, continuous monitoring. See pricing.