Exposure monitoring
Ongoing search for your email addresses, phone numbers, passwords, and documents across the places this material gets traded. You hear from us when something surfaces, not on a monthly schedule.
San Diego first · working remotely nationwide
Ten years of sources in places automated scanners never reach. We routinely find exposures months before they surface in public breach databases — and sometimes when they never surface at all. When we find yours, a person checks that it is really you, and then tells you directly.
How it works
No dashboard to log into, no alert queue to triage. You hear from us when there is something real to hear about.
Public breach dumps, criminal marketplaces, closed forums, and licensed intelligence feeds — layered, because no single source sees everything. Ten years of access means we are reading places that automated scanners never reach.
A person confirms the data is real, current, and actually yours. Recycled dumps and reused credential lists get filtered out here. You do not hear from us about a ten-year-old password you already rotated.
Directly, in plain language, with what we found and where. No dashboard login, no alert score, no automated email that reads like it was sent to fifty thousand people, because it was not.
Rotating what leaked, recovering accounts already taken over, freezing credit, pulling listings down where that is possible. For individuals in San Diego this part is usually free.
What we do
Most of this starts the same way — an old password turns up somewhere it should not be. What follows depends on what they did with it.
Ongoing search for your email addresses, phone numbers, passwords, and documents across the places this material gets traded. You hear from us when something surfaces, not on a monthly schedule.
Someone is already in your email, bank, or social accounts. We work the recovery process with you, find how they got in, and close that route before handing the account back.
Passwords, multi-factor, and — the part almost everyone gets wrong — account recovery paths. Most takeovers do not defeat your password. They go around it through a recovery email you forgot existed.
Phones, laptops, router, and the smart devices nobody has updated since they were plugged in. Checked for compromise, then configured so the next thing that leaks does not become the next thing that spreads.
Children's data gets traded too, and it goes unnoticed for years because nobody checks a nine-year-old's credit. We cover the whole household, including the accounts your kids set up without telling you.
For people who are targeted rather than swept up: executives, public figures, journalists, and survivors of domestic abuse. Removing what is findable, monitoring what is not, and a direct line when something changes.
Community work
When we come across a San Diego resident's data in a place it should not be, we tell them. No invoice, no upsell, no account to create first. It is the reason we started doing this, and it is still the part of the job that matters most.
Free work is finite and we are a small team, so we cannot promise unlimited hours to everyone. But nobody has ever had to pay us to be told they were exposed.
Why Cynautic
For your business
Staff credentials for sale, customer records in a dump, an executive's home address circulating, a vendor breach nobody told you about. We monitor for it, verify it, and tell you what to do about it. Businesses are where we make our money, which is what keeps the personal side free. Most of our clients are in San Diego County, and this work travels — we take companies in any state.
Scope a business engagementSend an email with your name or your company's. We'll tell you what we can see, whether it's worth worrying about, and what to do next — before we ever discuss money. San Diego is home, but the search does not care where you live, and neither do we.
[email protected]