$ hydra recon --passive acme.example
[✓] 14 subdomains · CT logs
[✓] 4 mail senders · SPF
[!] DMARC p=none · spoofable
[!] 1 look-alike · live MX
▸ exposure mapped · 0 packets sent
TIA · HYDRA OSINT · CZ/EU
You don't get a dashboard.
You get evidence.
Sources named, queries listed. Check the finding yourself.
OSINT & Threat Intelligence for organizations that need to know
what an attacker already knows about them — before the strike.
HYDRA cuts heads of dragons threatening the kingdom.
Not heads of merchants exaggerating their wares in the marketplace next door.
◢ HYDRA · INTEL · PASSIVE-RECON · UTC --:--:-- ▮
DOOR 4 · CUSTODIANS · WE TOUCH NOTHING AT ALL
Your agents act. Can anyone else prove what they did?
CUSTODIANS — auditable agents. Doors 1–3 look at your estate.
This one looks at the software you have running inside it, and asks the question
an auditor asks: “show me what it did, and show me why I should believe you.”
An agent that reports on itself is not audited. It is quoted.
A prompt is not a security boundary. We put the boundary where it cannot be argued with,
seal every action into an append-only record, and hand you a bundle
— charter, envelopes, chain head, and a verifier — so that your client,
your auditor or your insurer can check it without being given access to anything.
That includes checking us.
What it does not do: it does not make an agent correct.
A sealed record of a bad decision is a well-preserved bad decision.
It decides what is reachable and what is provable — never whether the judgement was good.
OPEN CUSTODIANS →