Prime contractors and clusters

Prime contractors: which of your documents are circulating on the darknet through your suppliers?

Request your exposure audit: the answer, piece by piece, within 48 working hours.

Request my audit

You get the record of what the darknet exposes about your suppliers and, through them, about you:

  • trade secrets
  • technical and industrial data
  • sensitive defence information
  • HR data
  • entry points for a cyber attack or a physical approach

And, in the same report, what an adversary can infer about your programmes by cross-referencing those pieces with public information.

What you will find in there

Five things the dark web already says about your supply chain.

  • Yes, protected documents circulate. Their confidentiality marking is exactly what makes them easy to find.
  • Harmless files, cross-referenced, rebuild what never gets published: an org chart, a pricing grid, an internal process.
  • Why the most damaging pieces sit with your rank 1 and rank 2 suppliers, in dumps ranging from years old to last week.
  • What an attacker does with your HR data once it is out there: targeted phishing, competitor intelligence, approaches to at-risk staff.
  • The one thing no secret scanner tells you, because it only ever looks for passwords.

Some of what the machine finds, we publicly release — real cases, real data. Browse the public reports

The exposure audit, free

On a perimeter you choose, not on your whole chain.

Your rank 1 suppliers, your top ten, or a single programme: you scope it, we read it. It is a real sample of your chain, wide enough to judge and narrow enough to deliver fast.

  1. Report within 48 working hours, every piece sourced and dated.
  2. Then 30 minutes with an analyst to read the findings with you.
  3. No fee and no access to your systems: the audit only reads what is already exposed.

Results go to you and nobody else.

Why this audit is free

OwlyScan is built in France by SitinCloud, a member of GICAT. The audit is free so you can see, on your own perimeter, what the tool can do.

What comes next

The whole chain, under one annual contract.

If the sample shows what you feared, the analyst scopes the real perimeter with you: hundreds of entities under a single contract, at a price that falls as the volume rises. That is a conversation, not a checkout.

Let us talk

Inside your organisation

You keep control of the tool and of the findings.

  • If your CERT wants to run it themselves, OwlyScan installs on your side, air-gapped included.
  • Under a Portfolio contract, findings go straight to your SOC (MISP, STIX/TAXII, syslog).
  • No log of your queries. Hosted in France, member of GICAT, deployed for French state services.

See OwlyScan Investigation

For your suppliers

What your rank 1 and 2 can put in place on their own.

A sealed exposure statement on their own company, every month, at €990 a year and without going through you. It covers the AirCyber Gold 4.11 requirement, and it is the simplest way to ask them for proof rather than a declaration.

See Monitoring

Right now, you don’t know what your suppliers have put out there. In 48 working hours, you could.

Request my audit

PS. Nothing on the dark web gets deleted, and anyone promising removal is selling comfort. What changes is who knows first. Today that is whoever went looking: a competitor, your client’s security officer, a journalist. The audit takes one conversation, and it starts with the form above.

Cited by the French Senate (2023) IEEE ICTAI IFIP SEC Milipol Paris Member of GICAT