Dark web monitoring for you and your suppliers

See what they see.

What ransomware groups have published about you and your suppliers. Your supplier won’t tell you. The leak will.

If we miss a significant leak about you, next year is free.

Request my statement Free, within 24 business hours.
OwlyScan Monitoring, Overview of the demo company ACME: on the left a briefing with the verdict High exposure, a summary of four publications, six new documents, three documents to look at first, the top attack scenario and the four publications; on the right a globe placing each publication, with a zoom lens on France and Belgium.
AI native · our models read every document MCP native · your AI tools plug in · all included

How it works

A ransomware group exfiltrates the files before encrypting them. If it is not paid, it publishes them. Among them are military secrets, trade secrets, HR files, and the means to get into a site or reach a person.

These files stay online for years, and others use them. An attacker finds passwords in them for the next intrusion, a competitor reads your commercial terms, and an intelligence service collects the names of your engineers.

In several sectors, the law also requires you to know. A bank under DORA or an operator under NIS 2 must be able to say what has been published about it and its suppliers, and since when it has known.

Because nobody can read all of this by hand, we do it with software. Each document is read automatically, and we work out what it is, what it is about and whose it is. You receive the part that concerns you.

  1. Fetch

    As soon as a group publishes a new victim, we fetch everything it put online, in every format and every language. We open every archive, even those holding other archives.

    The Breakdown view shows what each publication holds, by type of data.

    Breakdown view: ACME's four publications in rows, the kinds of data in columns, each cell captioned with its high-criticality documents, for example 8 high of 28 credentials in the stealer logs.

    Monitoring · Breakdown view · demo data

  2. Read

    Our models read each document in full and give it a title in plain words, its kind, its date, and the name of the company it is about.

    In the Documents view, the most important ones are at the top of the list.

    Documents view: 119 documents, most important first, each titled in plain words with its kind and type of data, the publication it comes from, its date and whose data it is, with quick filters To review, High, New and Starred.

    Monitoring · Documents view · demo data

  3. Hand over

    For each document that concerns you, you receive one page: the line that matters, what an attacker can do with it, where it comes from, and who on your side has to act.

    Passwords are masked.

    A document open: Database password in a pasted config file. Why it matters, what it is, the evidence line with the password masked, the attack scenario it supplies, where it comes from, and which team has to act: Security.

    Monitoring · a document open · demo data

No one will ask you to read ransomware sites. Your clients, your insurer and the regulator will ask what leaked about you, and since when you knew. We agree with you what to watch and who receives what. After that, it takes almost none of your time.

Some of it is yours.

A publication can hold millions of files, the victim’s and those of all its partners. The dashboard pulls out what is about you and shows what it changes for you.

Impact view: attack scenarios, most severe first. Scenario 1, High: sign in to ACME's VPN as a finance employee, evidence 3 of 4 found, why it matters, and the three publications it combines, none of which shows it alone. On the right, a flow from publications to scenarios to attacker types.Timeline view: 55% of ACME's dated documents are less than a year old. One ridge per publication across 2023 to 2027, the documents placed on it by date and criticality, with when each publication was seen online and a Today line.Themes view: a treemap of ACME's documents grouped by theme, such as Saved staff passwords, Finance files and payments, Supplier contacts and terms; each block sized by its number of documents and coloured by criticality.Report panel: ACME, a billing API key and a database password pasted on 27 September. In short first, then what was found, what an attacker can do and coverage, with each document cited as a reference chip and listed on the right.

The Impact view shows what an attacker can do with the published documents, most serious first. A password in one publication, an employee’s name in another and the address of a gateway in a third are enough to open a door.

Monitoring · Impact view · demo dataKeys shown as in the app

How you get it.

Three offers, one starting point: your free statement.

You search everything that is published yourself. You set your keywords, and we alert you when a new document contains them. Your searches leave no trace.

From

3 000 €

excl. VAT a year, per organisation

Monitoring

We read every new publication that touches your organisation and the companies you monitor. Each finding fits on one page, addressed to the team that has to act. Once a month, we go through them with you.

The whole search engine is included.

From

7 200 €

excl. VAT a year, for your organisation and up to three monitored companies

Guarantee

If we miss a significant leak about you, next year is free.

Ecosystem monitoring

Everything Monitoring does, at the scale of your ecosystem: all your suppliers, a programme, a cluster or a portfolio. The price depends on the number of monitored companies.

The whole search engine is included.

Higher tiers

On quote

From four monitored companies upward

Guarantee

If we miss a significant leak about you, next year is free.

Request my statement free, within 24 business hours, then our proposal

FAQ

“Is it legal?”
Yes. We work like a search engine: our indexing is purely technical, automatic and passive. We index what is already published, and you have nothing to download.
“What do you index?”
The whole dark web, without picking: everything published there, read document by document. So it covers business risk, military risk, exposed personal data and physical risk alike.
“What if you find nothing?”
Good news, and a dated statement to prove it the day someone asks. The real question is whether you can trust the product: that is what our guarantee is for. If we miss a significant leak about you, next year is free.
“Does it plug into our SOC, our CTI platform or MISP?”
Yes. Findings go out over syslog, or as STIX over TAXII. An MCP server is also available for your AI tools.
“Where does our data stay?”
As an option: AI models hosted in the EU, or OwlyScan deployed on your premises.

Now see your own company.

No access to your systems. We read only what is already exposed. The results go to you alone.

The statement is free because it shows you our work on your own scope. By hand, it would take two people three weeks.

What happens next

  1. You send the form below.
  2. Within 24 business hours, you receive your complete statement.
  3. An analyst reads it with you for 30 minutes. Together you decide what to watch and who receives what.
  4. You try the service before you buy, with our help and training.
  5. Monitoring starts the day of that reading.

Your statement

Your company, your suppliers, a programme, or the entities you watch. You choose.

The domain we start from. Suppliers and programmes are defined with you.

Or write to us: contact@owlyscan.com

GDPR: your details are used only to deliver the statement.

What you receive

Specimen · fictitious data In yours, every fact has its source and its date, and the names are in clear.

Guarantee

If we miss a significant leak about you, next year is free.

P.S. Take stock before a client or an auditor asks you to.

Example statement · ACME, a fictitious company

10 pages

Download the PDF
Example statement, page 1 of 10Example statement, page 2 of 10Example statement, page 3 of 10Example statement, page 4 of 10Example statement, page 5 of 10Example statement, page 6 of 10Example statement, page 7 of 10Example statement, page 8 of 10Example statement, page 9 of 10Example statement, page 10 of 10

Hosted in France, available on your premises

Developed in France. Our clients include government services, banks, aerospace groups and ERP software vendors. Member of GICAT. Cited by the French Senate. Published at IEEE ICTAI and IFIP SEC.

GICAT SitinCloud