Nothing about your exposure is scanned, monitored, or reported on until you’ve explicitly authorized it. Here’s exactly what happens after you do.
You sign a written engagement agreement and tell us exactly which identifiers we’re authorized to search — your name, known aliases, emails, phone numbers, and, for a business audit, the business name and domain. Nothing outside that scope is touched.
Licensed OSINT, data-broker, breach-database, and dark-web monitoring tools compile a raw exposure dataset against the identifiers you authorized. This step casts a wide net — the next step is where it gets narrowed down to what actually matters.
A senior analyst personally confirms every finding for accuracy, removes false positives and stale data, and risk-rates what’s left as Low, Moderate, High, or Critical. Nothing in your report is machine-generated or AI-written — a person checks it before you ever see it.
Findings are translated out of security jargon into plain language, grouped by category, and paired with a specific next step for each one — a takedown link, a password to change, a setting to turn off.
You receive the written report and decide how to proceed: book a live consultation to walk through it with your analyst, or review it on your own time and send questions through your Q&A portal — or check the FAQ for the answers people ask most. If you’ve added monitoring, this is also when it’s set up.
One document, organized the same way every time, so you always know where to look.
Every category — identity, footprint, fraud, breach, dark web, location, social — with its risk rating at a glance, so you can see the whole picture before reading a single detail.
Each item names the source, explains in plain terms why it matters, and gives a specific action — not a generic "review your privacy settings" line.
Findings are ordered by what to fix first, not by category, so you’re never left guessing whether the breached password or the data-broker listing matters more.
Every term used in the report — SSN fragment, spoofed domain, credential stuffing — defined in one place, so the report stands on its own after your consultation call.
Persōna’s delivery stack is built on licensed, commercially available OSINT, data-broker-removal, breach-database, and dark-web monitoring platforms — combined with hands-on manual verification to catch what automated tools miss and rule out what they get wrong.
No tool or technique Persōna uses accesses an account, device, or system without authorization. Dark-web findings come from passive, licensed monitoring feeds — Persōna does not browse dark-web marketplaces directly or purchase stolen data on your behalf.
Turnaround: 3–5 business days for an Individual Audit, 5–7 business days for a Small Business Audit.
Complex cases — an active safety incident, multiple aliases, or a business with several locations — are scoped individually and may take longer. You’ll always know the expected timeline before work begins.
Choose your tier and we’ll start with a short intake conversation.