Company
We are building the outside-in view of your organisation — the one attackers already have.
0DaySecure is a security product company. One platform, three jobs: watch the places stolen corporate data surfaces, map everything you have facing the internet, and shut down the people pretending to be you. The product is still being built, so this page is about what we think and how we work rather than a company story we have not earned yet.
- What we make
- One platform for external threat exposure
- The three modules
- Dark web monitoring, attack surface, brand protection
- Who we build for
- CISOs, security engineers, SOC leads and fraud teams
- Where we stand
- Pre-launch, building alongside design partners
The argument
Why we are building this
Nobody needs another security category. This one exists because of a specific, structural problem — and because the problem is getting worse rather than better.
For most of the last two decades, defending a company meant defending a boundary you could point at: a building, a data centre, a firewall with rules in it. That boundary is gone. Your estate now includes SaaS tenants signed up with a corporate card, cloud accounts opened for a proof of concept and never closed, a campaign microsite living on an agency’s hosting, an API gateway a team stood up on a Friday afternoon, and every certificate and DNS record all of that leaves behind. No single person owns that list. In most organisations the list does not exist at all.
Attackers work from the outside, and the outside is public. Long before anyone touches your network there is a reconnaissance phase, and it runs entirely on infrastructure you do not control — certificate transparency logs, DNS history, public code repositories, job adverts that name your internal tooling, credential dumps from breaches at companies you have never heard of, brokers quietly advertising working access to a network that happens to be yours. None of that produces a log line on your side. None of it trips an alert.
So exposure tends to get discovered from the wrong direction. A customer forwards a phishing email that used your login page. A bank calls about fraud running through a domain one character away from yours. A ransomware crew posts your name on a leak site with a countdown next to it. Every one of those is a late notification of something that was readable weeks earlier, in the open, by anyone who thought to look.
That asymmetry is the whole reason for this company. The data is out there; the difficulty is collecting it continuously, attributing it correctly to you, discarding the large majority that is noise, and putting the evidence next to the claim. It is dull, specialist, unending work, and it is not a reasonable thing to ask a security team to fit around incidents. We are building the system that does it and hands back a short list with proof attached. Not a feed. Not a score. Findings about you.
Two views of one company
IllustrativeReadable from outside, without touching you
- Subdomains and hosts in certificate transparency logs
- DNS records, including ones nobody remembers creating
- Cloud storage buckets and their permissions
- Login portals, admin panels and remote access endpoints
- Credentials leaked in breaches at other companies
- Job adverts naming the internal tooling you run
- Access brokers advertising a route into your network
- Domains registered one character away from yours
Tracked on the inside
- The asset register, as last reconciled
- What the CMDB says production is
- The domains legal knows it renews
The difference between the two lists is the part of your organisation that is exposed and unmanaged. Closing it starts with being able to see it.
Principles
What we believe
Four positions that decide what gets built and what gets refused. They are here so you can hold us to them.
Findings, not feeds
Volume is not value. A tool that mails you nine hundred threats a week has not taken work off your desk, it has put work on it and called that coverage.
We would rather send three things that are true and specifically about you, and let a quiet week be quiet.
Evidence over adjectives
Every alert carries its proof: where we found it, when we found it, what the raw record said, and the screenshot, WHOIS or breach reference behind it.
You should be able to check our work without asking us to explain it. Critical is a label, not an argument.
Read-only by default
Discovery is passive first. We do not scan, probe or authenticate against anything until you have confirmed in writing that it is yours and that we may touch it.
Nothing we run should ever be the reason your on-call phone goes off.
Boring is good
Security tooling should be the least dramatic thing you own. Predictable pricing, predictable alerts, plain language in the console, no countdown timers.
If we ever make a finding look worse than it is to win a renewal, we have failed at the job.
Design partners
How we work with early customers
The platform is in active development. That is not a soft launch line — it changes what an engagement with us looks like, and it is only fair that you know how before a call, not after one.
- Step 01
A scoped first look
You give us a domain. We run passive discovery and dark web collection against it, then walk you through what came back — line by line, including the things we could not attribute confidently. You keep the findings whether or not you buy anything.
- Step 02
Written scope before anything active
Before a single active check runs, we agree in writing which assets are yours, what we may touch, what stays passive and who to call if something looks wrong. You can narrow that scope at any point without a conversation about contracts.
- Step 03
A short loop back to the people building it
Design partners talk to the engineers writing the code, not to a queue. When you tell us a finding is noise, we treat that as a defect: it goes in with your reasoning attached, and you hear what we did about it.
- Step 04
Commercial terms that match the stage
The platform is not finished, and early pricing reflects that. We are not asking anyone to sign a multi-year commitment to software that is still changing every week.
What we will tell you plainly
- Which parts of the platform are running today and which are still being built
- What is on the roadmap, and what we have decided not to build at all
- Where a finding came from and how confident we are in the attribution
- When the answer is that we do not know yet
Straight answer
Some of what this site describes is running now and some of it is still being written. We are not going to blur that line in marketing copy. Ask on a call and you will get it module by module, with dates where we have them and an honest “not yet” where we do not.
Deliberately blank
What is not on this page yet
A company page usually fills this space with headshots, a founding myth and a row of certification badges. We would rather leave the gap visible than fill it with something we cannot stand behind.
The team
Coming soonWho is building this and what they worked on before. Named people with real roles — no stock portraits, no composite leadership team.
Where we are
Coming soonOperating entity, registered address, and the jurisdictions your data may be stored and processed in.
How this started
Coming soonFounding year and the short version of why the product exists. One honest paragraph, once there is one worth reading.
Assurances and certifications
Not claimed yetWhat we can say today: data is encrypted in transit and at rest, SSO and SAML are available, and internal access follows least privilege. We are not putting an audit badge on this site before an audit exists. When a report does exist, it will be named here with its date and scope.
Careers
Not open yetNo roles are posted. If you build collection infrastructure or triage external findings for a living, write to us anyway and we will keep the note.
Current security practices are written up in full, with no badges attached.
Judge us on the findings, not the copy.
Give us one domain. We will come back with what is exposed, what has leaked and who is impersonating you — and the report is yours either way.
- Scope agreed in writing first
- Passive discovery to begin with
- Findings are yours to keep