We tell you what is publicly findable about your domain. Free, in two business days. We scan nothing. We only read sources that already published the data.
A PDF, normally eight to twelve pages. Every finding carries the public source link, so your engineer can reconfirm it in ten minutes.
Open ports and services somebody else already scanned and published.
Forgotten servers and subdomains nobody patches.
Broken DNS: SPF, DMARC, dangling records.
Certificates past expiry, or issued by someone you would not expect.
Company emails and passwords that surfaced in breach dumps.
The report is built from public sources only. We never touch your network.
Straight answers to what clients ask us most.
Passive reconnaissance queries registries, CT logs, search indexes and breach feeds that other parties operate. Active testing sends packets at the target, scans ports and probes services, which is why it needs a contract and a testing window. The only thing that goes from us to you is a standard public DNS lookup.
Our position, reviewed by Czech counsel, is that it is. Reading data that registries, certificate transparency logs, search indexes and public code repositories have already published is not access to a computer system, and Section 230 of the Czech Criminal Code turns on gaining access or overcoming a security measure. That is why the boundary matters, and why we publish it in full above rather than calling our method "non-intrusive" and stopping there. If your own counsel reaches a different view for your organisation, tell us and we will not run the assessment.
Only a mailbox in that domain. The requester's address must be in the domain being profiled, free mail providers are rejected, and the analysis does not start until someone opens a signed confirmation link delivered to that address and confirms the request. We profile exactly the domain your mailbox is in, and there is no way to name another one. The finished report goes only to the address that asked for it. If you believe somebody requested a report for your organisation without authority, write to security@kybit.cz and we will block the domain from further requests.
Your email address, because that is where the report goes. That is the whole exchange. We are not signing you up to anything, we run no newsletter, and opening the report starts no sales sequence.
Collection working data, including every raw source response, is deleted within 90 days. Raw source responses containing credential material are deleted at the end of the collection run. The delivered report stays in our outbound mail records for 12 months. Request metadata is kept separately for 12 months for abuse investigation; the copies held inside the declaration record follow the four-year period below. The record of your scope and authority declaration is kept for 4 years as proof of lawful processing. We do not publish the report, we do not name you as a recipient anywhere, and we do not share a single finding with anyone.
Three fields and one tick box. The report goes to a mailbox in your domain.
We email the address you enter and nobody else. The report goes to you alone.
Report author: Lukáš Jonák. Direct email: lukas.jonak@kybit.cz.