TIA · HYDRA OSINT · CZ/EU

Intelligence cuts
that close cases.

OSINT & Threat Intelligence for organizations that need to know what an attacker already knows about them — before the strike.

HYDRA cuts heads of dragons threatening the kingdom.
Not heads of merchants exaggerating their wares in the marketplace next door.
Tier 1 from
CZK 18,000
Delivery
2–15 days
Methodology
Passive only
Compliance
GDPR · NDA
TIERED PRODUCTS

Three layers, one chain.

From a rapid exposure snapshot to a board-ready intelligence product. Each layer builds on the previous one. Start where you are — continue as needed.

TIER 1
Exposure Scan
Rapid public-exposure snapshot
from CZK 18,000
/ €700 · excl. VAT
⏱ 2–3 business days
  • Public infrastructure map (domains, subdomains, technologies)
  • CVE matching against the technology profile
  • Credential-leak check
  • Risk score 0–10 with rationale
  • Action checklist — top 5 findings
  • PDF report (8–12 pages, CZ/EN)
TIER 2
Threat Assessment
Sector threat landscape + dark web
from CZK 28,000
/ €1,100 · excl. VAT
⏱ 5–7 business days
  • Everything in Tier 1
  • Dark web monitoring — mentions & leaked credentials
  • Sector-specific threat landscape (active ransomware groups)
  • NIS2 / DORA gap analysis
  • Leadership exposure check
  • PDF report 20–30 pages + 60-min briefing call
TIER 3
Full Intelligence
Board-ready intelligence product
from CZK 48,000
/ €1,900 · excl. VAT
⏱ 10–15 business days
  • Everything in Tier 1 + Tier 2
  • Threat actor profiling — who, how, why
  • Supply chain mapping & vendor compromise vectors
  • Regulatory exposure (NIS2 · DORA · GDPR)
  • Disinformation / Reflexive Control detection
  • Executive briefing — board-ready PDF + slides
  • PDF report 40+ pages + 2 briefing calls
E-MAIL SHIELD · REMEDIATION

Finding is step one. Closing is step two.

Findings are worthless until the gap is closed. E-mail Shield takes your domain from "anyone can impersonate you" to full enforcement — phased, with zero mail downtime, and before/after proof your IT and management both understand.

FIX
Close the gap
E-mail Shield Fix
39,000 Kč
/ €1,500 · excl. VAT
⏱ 2–3 weeks · phased, no mail downtime
  • Inventory of all legitimate senders
  • SPF hardening (-all) + DKIM 2048-bit
  • DMARC phased: none → quarantine → reject
  • Before/after proof (external re-scan)
  • Executive summary (CZ/EN)
PRO
Full protection
E-mail Shield Pro
79,000 Kč
/ €3,100 · excl. VAT
⏱ 3–4 weeks
  • Everything in Fix
  • MTA-STS + TLS-RPT + DNSSEC
  • BIMI-ready
  • DMARC report monitoring (30–90 days)
  • BEC-awareness one-pager for the team
SENTINEL
Ongoing watch
E-mail Shield Sentinel
12,000 Kč / mo
/ €470 · excl. VAT · 3-mo min
⏱ ongoing
  • Monthly DMARC report review
  • Alerts on new senders and threats
  • Quarterly external exposure re-scan
  • Priority incident support
TALOS · APPLICATION & CODE SECURITY · AUDIT + REMEDIATION

Beyond the outside-in. Into the code itself.

TALOS — our attack-first code audit, named for the bronze guardian who defended by attacking. Passive recon shows what an attacker sees from outside. When you're ready to go deeper — with your explicit authorization — we assess the application and code itself: attacker-first, and only the findings that are actually exploitable.

AUDIT
Code Security Audit
Attacker-first, verified findings
from CZK 60,000
/ €2,400 · excl. VAT
⏱ scoped per codebase
  • Attacker-first analysis — real attack paths from entry points (APIs, uploads, network), not pattern-matching
  • Falsification pass — we disprove our own findings, so you get verified exploitable defects, not false-positive noise
  • Every finding: exploit path, business impact, severity
  • Prioritized report + fix strategy (CZ/EN)
  • Authorized & confidential · NDA-ready
+ REMEDIATION
Audit + Fix + Verify
Closed loop — proven, not assumed
from CZK 120,000
/ €4,700 · excl. VAT
⏱ scoped per codebase
  • Everything in the Audit
  • We implement the fixes — reviewable, minimal, targeted changes
  • Independent verification — a separate check proves each fix held (proven, not taken on faith)
  • Before/after proof your IT and management both understand
  • Findings are yours — never public
THE DOCTRINE

Who we target. Who we don't.

HYDRA is an intelligence function, not vigilantism. This line is non-negotiable and protects both sides.

VALID TARGETS

  • Attackers — an active threat to you, your partners, your clients
  • Prospects — trust calibration before closing a deal
  • Self-audit — your own exposure check

INVALID TARGETS

  • Competitors with marketing problems
  • Ego targets — "they're wrong on the internet"
  • Public shaming — HYDRA reports are for the client, not for LinkedIn
SAMPLE OUTPUT

Anonymized sample. Free. No strings attached.

Before you order, see the structure and depth of a real HYDRA report. All sensitive data is redacted.

Sample pack — Tier 1 + Tier 3

An anonymized Tier 1 PDF (~10 pages) + an anonymized Tier 3 enterprise report (~30 pages). For assessing the format and depth of your potential deliverable only. No contact forms, no commitments.

Request Sample Pack
METHODOLOGY

How we work. What we guarantee.

An auditable workflow, a documented evidence chain, full source transparency.

◢ PASSIVE RECON ONLY

No active exploitation, no authenticated scanning, no contact with target systems. Publicly available sources only.

◢ AUDITABLE EVIDENCE CHAIN

Every finding includes a URL, a timestamp and a source. Independently verifiable. Labeled: CONFIRMED / UNCONFIRMED / INDICATIVE.

◢ GDPR · NDA-READY

Fully compliant workflow. NDA before work begins, agreed scope, retention policy.

◢ COCA-COLA PROTECTION

Reports contain findings and action items, not tools or methodology. Your competition won't learn how it's done.

START THE CONVERSATION

Send a message. We reply within 4 hours.

For the sample pack, write "SAMPLE". For a custom investigation, a short description of the situation. Decision-maker preferred.

WhatsApp Business