Free report · Two business days

    What an attacker can learn about you without touching your network

    We tell you what is publicly findable about your domain. Free, in two business days. We scan nothing. We only read sources that already published the data.

    Passive OSINT report

    What usually turns up

    A PDF, normally eight to twelve pages. Every finding carries the public source link, so your engineer can reconfirm it in ten minutes.

    • Open ports and services somebody else already scanned and published.

    • Forgotten servers and subdomains nobody patches.

    • Broken DNS: SPF, DMARC, dangling records.

    • Certificates past expiry, or issued by someone you would not expect.

    • Company emails and passwords that surfaced in breach dumps.

    Passive OSINT reconnaissance

    What we do not do

    The report is built from public sources only. We never touch your network.

    • we do not scan ports or send requests to your servers
    • we do not probe your mail servers to check whether a mailbox exists
    • we do not test the passwords we find, and we never hold them in plaintext
    • we do not publish the report or share it with anyone else
    FAQ

    Frequently asked questions

    Straight answers to what clients ask us most.

    Passive reconnaissance queries registries, CT logs, search indexes and breach feeds that other parties operate. Active testing sends packets at the target, scans ports and probes services, which is why it needs a contract and a testing window. The only thing that goes from us to you is a standard public DNS lookup.

    Our position, reviewed by Czech counsel, is that it is. Reading data that registries, certificate transparency logs, search indexes and public code repositories have already published is not access to a computer system, and Section 230 of the Czech Criminal Code turns on gaining access or overcoming a security measure. That is why the boundary matters, and why we publish it in full above rather than calling our method "non-intrusive" and stopping there. If your own counsel reaches a different view for your organisation, tell us and we will not run the assessment.

    Only a mailbox in that domain. The requester's address must be in the domain being profiled, free mail providers are rejected, and the analysis does not start until someone opens a signed confirmation link delivered to that address and confirms the request. We profile exactly the domain your mailbox is in, and there is no way to name another one. The finished report goes only to the address that asked for it. If you believe somebody requested a report for your organisation without authority, write to security@kybit.cz and we will block the domain from further requests.

    Your email address, because that is where the report goes. That is the whole exchange. We are not signing you up to anything, we run no newsletter, and opening the report starts no sales sequence.

    Collection working data, including every raw source response, is deleted within 90 days. Raw source responses containing credential material are deleted at the end of the collection run. The delivered report stays in our outbound mail records for 12 months. Request metadata is kept separately for 12 months for abuse investigation; the copies held inside the declaration record follow the four-year period below. The record of your scope and authority declaration is kept for 4 years as proof of lawful processing. We do not publish the report, we do not name you as a recipient anywhere, and we do not share a single finding with anyone.

    Free report · Two business days

    Request the report

    Three fields and one tick box. The report goes to a mailbox in your domain.

    We take the domain we profile from your work address. Free mail providers are rejected.

    We do not sell or share your details. Privacy policy.

    We email the address you enter and nobody else. The report goes to you alone.

    Report author: Lukáš Jonák. Direct email: lukas.jonak@kybit.cz.