- Collection and correlation
- Every capability — Attack Surface, Brand Protection, Data Exposure, Dark Web, Threat Intelligence, Threat Feeds, CART, Vendor Risk Management, Unified Console — running continuously against each client estate and resolving into one correlated exposure model per client. The same set a direct customer buys.
- Tenancy and access control
- Each client is a separate tenant under your organisation. Roles — administrator, analyst, SOC user, and a scoped vendor seat for third parties you invite in — decide what a person can reach, so an analyst assigned to three accounts sees three accounts. SSO via SAML or OIDC against your identity provider, and an audit log recording actor, source address, target and timestamp per tenant.
- The operations you would otherwise staff
- Takedown filing and follow-through against impersonating domains, pages and profiles — unlimited, subject to fair use, where fair use means notices filed for the marks and estate under monitoring rather than a filing channel opened for third parties. Where managed service is part of the engagement, that extends to direct escalation into the Security Brigade red team for incidents.