Drop our agents into any app, online shop, social platform or website. They watch every login, payment and data request in real time and tell you exactly who is attacking, how, and what to do next.
Nothing is deployed without the owner’s personal approval.
LEDGER · just nowcritical
Transfer right after password reset
customer_4821 reset their password and sent 18,500 to a payee added 3 minutes earlier.
Owner alerted
The roster
Five specialists. One mission.
Each agent inspects every event your application reports, in real time, and files an incident when something looks wrong.
01
Sentinel
Intrusion detection
Brute-force and password-spraying attempts
Credential stuffing across many accounts
SQL injection, XSS, path traversal and command injection payloads
Unexpected privilege escalation
Password resets and security-setting changes (MFA off, email changed)
02
Ledger
Transfer & payment fraud
Transfers above your risk threshold
Rapid-fire transfer velocity
Money sent to a payee added minutes earlier
Transfers right after a password reset (account takeover)
Amounts far outside a user’s normal behaviour
03
Vault
Personal data protection
Bulk exports of user records
Scraping of many customer profiles in a short window
Card numbers or national ID numbers leaking into logs and payloads
04
Watchtower
Bots, probes & account takeover
Known attack tooling (sqlmap, nikto, hydra, nuclei…)
Request floods from a single address
Probing of secret files and admin panels
Logins from a never-before-seen country or device
05
Analyst
AI incident triage
Explains what happened in plain language
Rates confidence and likely intent
Recommends defensive next steps for your team
How to get access
Get your keys in four steps.
Every deployment is approved by hand, so nothing is watched until you’ve agreed the scope. Here’s what to do.
STEP 1
Send a request
Fill in the request form below with your name, work email, organization, the website or app you want protected and what worries you most.
STEP 2
Get approved
We review every request personally and email you with terms. Once you agree, we set up your deployment for the domains you named.
STEP 3
Receive your keys
We send you a public key for your website and a secret key for your servers, and your email is added so you can sign in to the console. Keep the secret key private — it’s shown only once.
STEP 4
Install and go live
Add one script tag to your site or one API call to your server. Alerts then reach you in the console and by Slack, Discord, email or SMS.
Enterprise-level security, from a single shop to a global SOC.
The same controls large security teams expect — identity, isolation, auditability and integrations — are built in for every customer, not sold as an upgrade.
Multi-tenant isolation
Every organization’s deployments, events and incidents are walled off from every other tenant, with per-tenant rate limits so one customer can never starve another.
SSO, SCIM and role-based access
SAML single sign-on, SCIM user provisioning and one role per member — admin, analyst, viewer and more — scoped to each organization.
Tamper-evident audit trail
Every privileged action is written to a hash-chained audit log that cannot be edited or deleted, and can be verified end to end.
Encryption at rest
Connector credentials and queued telemetry are sealed with AES-256-GCM envelope encryption, with master-key rotation.
Plugs into your SOC
Incidents stream to Splunk, Datadog or any signed webhook, mapped to MITRE ATT&CK, with retries and a dead-letter queue so nothing is lost.
SLAs, retention and legal hold
Response clocks per severity, per-organization data retention windows and legal hold for incidents under investigation.
Built to keep up under load
A durable ingest queue with idempotency keys, fair scheduling across tenants and automatic recovery of stuck work.
Scoped service keys and REST API
Org-scoped service accounts for the incidents, reports and audit APIs — hashed at rest and shown only once.
Rules of engagement
No going rogue. Built in, not bolted on.
These aren’t promises in a policy document — they’re how the system is engineered. The team works for the people it protects.
Observe and report — never act on its own
The agents watch, detect and alert. They cannot block users, move money, delete data or touch anything in the protected application. A human always makes the call.
Deployed only with the owner’s permission
Every deployment starts as pending. Nothing is watched until the owner personally activates it, and the owner can pause or revoke it at any time.
Scope-locked
Each deployment only accepts telemetry from the domains and keys it was issued. The team cannot wander into systems it wasn’t invited into.
Minimum data, maximum privacy
Raw form values and payloads are scanned in memory and discarded. Card and ID numbers are redacted from evidence before anything is saved.
One-touch kill switch
The owner can stand the entire team down across every client in one click. Ingestion and alerts stop immediately.
Every permission change is on the record
Activations, revocations, key rotations and drills are written to an audit log that shows who did what and when.
Defensive only, for the good of all
The AI Analyst is instructed to recommend only lawful, proportionate defense — no hacking back, no doxxing, no exploit code.
Borrow the team
Put the team on your side.
Tell us what you run and what keeps you up at night. The owner reviews every request personally and replies with terms and next steps.