August 2, 2026Watching the checkout page from inside the browser
A card skimmer never touches the server: it arrives as one more script on the checkout page and reads the number out of the form before your own code sees it. So the origin is unchanged and a content hash sees nothing. This watches from the only place it exists — the visitor's browser — and reports structure, never content: which script hosts load, whether a native browser function has been replaced, how many inputs sit where nobody can see them. The first report is a silent baseline. A replaced function is something to explain, not proof of anything: that is also how every session-replay tool works.
August 2, 2026Look-alike domains, watched
We generate the names a fraudster would register against yours - a dropped letter, a swapped ending, a zero for an o - and check which of them actually resolve. Across the current portfolio that surfaced 45 registered look-alikes.
August 2, 2026An outside reading of every domain, with a grade
TLS, security headers, cookie flags, version exposure, SPF, DKIM, DMARC, MTA-STS, TLS-RPT and CAA are checked from outside the perimeter and summarised as a grade from A to F. Nothing is installed and no traffic is redirected; a domain can be monitored this way and nothing else.