TIA · HYDRA OSINT · CZ/EU

You don't get a dashboard.
You get evidence.

Sources named, queries listed. Check the finding yourself.

OSINT & Threat Intelligence for organizations that need to know what an attacker already knows about them — before the strike.

HYDRA cuts heads of dragons threatening the kingdom.
Not heads of merchants exaggerating their wares in the marketplace next door.
Tier 1 from
CZK 18,000
Delivery
2–15 days
Intel recon
Passive only
Compliance
GDPR · NDA
METHODOLOGY

How we work. What we guarantee.

An auditable workflow, a documented evidence chain, full source transparency.

◢ PASSIVE RECON — INTELLIGENCE ONLY

Tiers 1–3 touch nothing: no active exploitation, no authenticated scanning, no contact with your systems or anyone else's. Public sources only.

E-mail Shield and TALOS are different work, and they say so. Both are authorised in writing, scoped in a contract, and both touch systems — that is what they are for. A guarantee stretched to cover them would be worth nothing, so it is not stretched.

CUSTODIANS touches nothing either — for a different reason. It does not look at your estate at all. It reads what your own agents emit, on your side of the line, and hands you the means to check the result yourself. The one system it invites you to audit is ours.

◢ AUDITABLE EVIDENCE CHAIN

Every finding includes a URL, a timestamp and a source. Independently verifiable. Labeled: CONFIRMED / UNCONFIRMED / INDICATIVE.

◢ GDPR · NDA-READY

Fully compliant workflow. NDA before work begins, agreed scope, retention policy.

◢ FINDINGS, NOT TOOLING

Reports carry findings and what to do about them — no exploit code, no tooling, no method. That is what keeps a report safe to forward: to your board, your auditor, your insurer, a supplier. A document full of working attack tooling is not. It also means the method stays ours — we would rather sell you the finding than the recipe.

DOOR 1 · INTELLIGENCE · PASSIVE, NO CONTACT

Three tiers. One intelligence chain.

T1 → T2 → T3. Each tier includes the one before it. That chain is intelligence. It does not include E-mail Shield, TALOS, Spoof Check, or Custodians.

TIER 1
Exposure Scan
What your estate looks like from the outside
from CZK 18,000
/ €700 · excl. VAT
⏱ 2–3 business days
  • Public infrastructure map (domains, subdomains, hosting) — read from certificate-transparency logs and public DNS
  • Mail-spoofing posture — SPF, DKIM, DMARC, MX. Public DNS only. Delivery of a published address is Shield, not T1.
  • Subdomain-takeover candidates — names of yours still pointing at targets that no longer exist
  • Named third parties who can act in your name or see your visitors — suppliers read from your SPF includes, your TXT verification records and an archived copy of your own homepage. We name them. We do not match CVEs against software versions: that would need a request to your servers, and we send none.
  • Registry facts that carry a date — when each registration expires, and whether the registry publishes a transfer lock.
  • Look-alike domains — names built from how domains actually get impersonated, then checked against the registry: who holds them, and whether they can receive mail.
  • The whole estate on one page, not one domain — how many of your domains can be spoofed, and how many separate islands your portfolio really is.
  • Risk score 0–10 shown with its arithmetic — every point traced to a named finding
  • Action checklist — top 5 findings
  • PDF report (Czech; English on request)
  • A named list of what the sources could not see. We hold no breach database and no Shodan / Censys subscription. Rather than imply coverage we do not have, the report names the gap — and for credential leaks points you to the free route that gives you more than we could: HIBP Domain Search, on your own domain, in your own account.
TIER 2
Threat Assessment
Sector threat landscape + extortion-site exposure
from CZK 28,000
/ €1,100 · excl. VAT
⏱ 5–7 business days
  • Everything in Tier 1
  • Extortion-site and paste check — your name, domains and people against publicly readable ransomware leak sites and paste dumps. No paid breach feed; the report names which sources answered and which did not.
  • Sector-specific threat landscape (active ransomware groups)
  • NIS2 / DORA exposure indicators — INDICATIVE; a gap analysis needs access we deliberately do not have
  • Leadership exposure check
  • PDF report 20–30 pages + 60-min briefing call
TIER 3
Full Intelligence
Board-ready intelligence product
from CZK 48,000
/ €1,900 · excl. VAT
⏱ 10–15 business days
  • Everything in Tier 1 + Tier 2
  • Threat-actor prioritisation — which currently active groups' documented sector, geography and TTPs overlap your profile, ranked with reasons, and which are ruled out. A hypothesis set that points defence at a kill-chain — never a name we assert. Attribution from public sources is the most dangerous output in this field and we treat it that way.
  • Supply chain mapping & vendor compromise vectors — third parties readable from your own DNS, SPF and certificates
  • Regulatory exposure signals (NIS2 · DORA · GDPR) — INDICATIVE, from outside only
  • Influence-operation analysis (frame seeding, information laundering) — analyst-performed against a named framework, scoped on request
  • Executive briefing — board-ready PDF + slides
  • PDF report 40+ pages + 2 briefing calls
SPOOF CHECK · FREE · ONE AXIS

Free, we look at exactly one thing.

Whether someone can send mail as you. That is the whole free check. The rest of your estate — subdomains, takeover candidates, your suppliers, look-alike domains — is Tier 1, and this does not look at any of it.

WHAT WE READ

  • SPF · DKIM · DMARC · MX — four public DNS records
  • Read through a public resolver. Zero packets to your systems, the same promise as Tiers 1–3. No exception, no asterisk.
  • You get a one-page finding on the evidence chain HYDRA uses everywhere: URL, timestamp, source, and every item marked CONFIRMED / UNCONFIRMED / INDICATIVE.

BEFORE WE READ ANYTHING

  • You pick a random string and put it in DNS as a TXT record on _tia-verify.<your-domain>
  • Send us the domain and that string
  • We hold no secret. The only proof of ownership is that you can create that record — and we read nothing until it is there.

If it comes back spoofable, two doors follow — and they are different questions.

▶ CLOSE THE MAIL

  • E-mail Shield — Fix, from CZK 39,000. The direct answer to this finding: we change your DNS, phased, with zero mail downtime.

▶ THE REST OF THE ESTATE

  • Tier 1 — Exposure Scan, from CZK 18,000. A different question entirely. Its entry point is the sample report, not this check.

REQUEST THE FREE CHECK →

DOOR 2 · E-MAIL SHIELD · AUTHORISED, WE CHANGE YOUR DNS

Finding is step one. Closing is step two.

Findings are worthless until the gap is closed. E-mail Shield takes your domain from "anyone can impersonate you" to full enforcement — phased, with zero mail downtime, and before/after proof your IT and management both understand.

FIX
Close the gap
E-mail Shield Fix
39,000 Kč
/ €1,500 · excl. VAT
⏱ 2–3 weeks · phased, no mail downtime
  • Inventory of all legitimate senders
  • SPF hardening (-all) + DKIM 2048-bit
  • DMARC phased: none → quarantine → reject
  • Before/after proof (external re-scan)
  • Delivery test — we send one message to the address you publish and confirm it arrives. DNS says where mail is pointed; only a sent message shows it is received. Authorised work, so this is not an exception here — it is the job.
  • Executive summary (CZ/EN)
PRO
Full protection
E-mail Shield Pro
79,000 Kč
/ €3,100 · excl. VAT
⏱ 3–4 weeks
  • Everything in Fix
  • MTA-STS + TLS-RPT + DNSSEC
  • BIMI-ready
  • DMARC report monitoring (30–90 days)
  • BEC-awareness one-pager for the team
SENTINEL
Ongoing watch
E-mail Shield Sentinel
12,000 Kč / mo
/ €470 · excl. VAT · 3-mo min
⏱ ongoing
  • Monthly DMARC report review
  • Alerts on new senders and threats
  • Quarterly external exposure re-scan
  • Priority incident support
DOOR 3 · TALOS · AUTHORISED, WE RUN YOUR CODE

Beyond the outside-in. Into the code itself.

TALOS — our attack-first code audit, named for the bronze guardian who defended by attacking. Passive recon shows what an attacker sees from outside. When you're ready to go deeper — with your explicit authorization — we assess the application and code itself: attacker-first, and only the findings that are actually exploitable.

You are not paying for a list of suspicions but for a list of defects — we tried to disprove every one and failed, so the remediation budget goes to real defects instead of triage.

AUDIT
Code Security Audit
Attacker-first, verified findings
CZK 60,000
/ €2,400 · excl. VAT
⏱ 5 working days from access
  • Attacker-first analysis — real attack paths from entry points (APIs, uploads, network), not pattern-matching
  • Falsification pass — we disprove our own findings, so you get verified exploitable defects, not false-positive noise
  • Every finding: exploit path, business impact, severity
  • Prioritized report + fix strategy (CZ/EN)
  • Authorized & confidential · NDA-ready
  • The stated price and timeline hold for one repository up to 25,000 lines; anything larger is quoted and scheduled before we start
+ REMEDIATION
Audit + Fix + Verify
Closed loop — proven, not assumed
CZK 120,000
/ €4,700 · excl. VAT
⏱ 10 working days from access
  • Everything in the Audit
  • We implement the fixes — reviewable, minimal, targeted changes
  • Independent re-test — a separate pass re-tests each fix and reports what it found, including anything that did not hold. Evidenced, not taken on faith.
  • Before/after proof your IT and management both understand
  • Findings are yours — never public
  • The stated price and timeline hold for one repository up to 25,000 lines; anything larger is quoted and scheduled before we start
DOOR 4 · CUSTODIANS · WE TOUCH NOTHING AT ALL

Your agents act. Can anyone else prove what they did?

CUSTODIANS — auditable agents. Doors 1–3 look at your estate. This one looks at the software you have running inside it, and asks the question an auditor asks: “show me what it did, and show me why I should believe you.” An agent that reports on itself is not audited. It is quoted.

A prompt is not a security boundary. We put the boundary where it cannot be argued with, seal every action into an append-only record, and hand you a bundle — charter, envelopes, chain head, and a verifier — so that your client, your auditor or your insurer can check it without being given access to anything. That includes checking us.

What it does not do: it does not make an agent correct. A sealed record of a bad decision is a well-preserved bad decision. It decides what is reachable and what is provable — never whether the judgement was good.

OPEN CUSTODIANS →

THE DOCTRINE

Who we target. Who we don't.

HYDRA is an intelligence function, not vigilantism. This line is non-negotiable and protects both sides.

VALID TARGETS

  • Attackers — an active threat to you, your partners, your clients
  • Prospects — trust calibration before closing a deal
  • Self-audit — your own exposure check

INVALID TARGETS

  • Competitors with marketing problems
  • Ego targets — "they're wrong on the internet"
  • Public shaming — HYDRA reports are for the client, not for LinkedIn
SAMPLE OUTPUT

Anonymized sample. Free. No strings attached.

Before you order, see the structure and depth of a real HYDRA report. All sensitive data is redacted.

Sample pack — Tier 1 + Tier 3

An anonymized Tier 1 PDF (~10 pages) + an anonymized Tier 3 enterprise report (~30 pages). For assessing the format and depth of your potential deliverable only. No contact forms, no commitments.

Request Sample Pack
START THE CONVERSATION

Send a message. We reply the same business day.

For the sample pack, write "SAMPLE". For a custom investigation, a short description of the situation. Decision-maker preferred.

WhatsApp Business