What the product does
Exact collection methods and restricted source details remain operational; the customer receives the context needed to act.
Guardian Dark Web Monitoring turns approved domain, staff-email and brand-term matches into customer-readable findings, severity, context and accountable response.
Guardian for Australian customers is built, operated and hosted in Australia. All Guardian customer and platform data, including backups and recovery copies, is maintained and stored within Australia.
Guardian retains supported observation dates, affected identifier, source category, severity, customer-safe evidence, action and review history. Raw credentials, full breach dumps, source infrastructure and unrelated records remain restricted.
The package schedule identifies monitored domains, email addresses, keywords, brands, customer contacts, reporting and any expanded or specialist investigation scope.
Guardian does not claim visibility into every illicit forum, dataset, marketplace, private channel or exposure event.
Exact collection methods and restricted source details remain operational; the customer receives the context needed to act.
Sensitive source and record detail remains restricted according to the operational and legal controls.
Specialist investigation and expanded monitoring remain separate where outside the Core allowance.
An exposed email address, credential record, domain reference or brand mention may require password reset, identity review, endpoint investigation, communication, monitoring or no action after review. Raw source material alone does not answer that question.
Damocles operates approved collection and review. Guardian presents only the customer-readable finding and links required response to risks and actions without exposing restricted sources, crawler infrastructure or unrelated records.
Use approved business domains, staff email addresses, brands and keywords within the package allowance.
Show what was observed, affected identifier, source category, severity, dates and practical response context.
Create password, identity, endpoint, communication, investigation or other actions where appropriate.
Exact collection methods and restricted source details remain operational; the customer receives the context needed to act.
Monitor authorised business domains and related organisational identifiers within the package allowance.
Monitor approved staff or organisational email identifiers without exposing unrelated records.
Track approved names, brands or terms relevant to the customer exposure risk.
Present title, severity, source category, affected scope, dates, status and practical context.
Link material exposure to Guardian risks, All Actions, owners, due dates and review.
Show monitored-item counts, service state and latest finding without exposing collection infrastructure.
Specialist investigation and expanded monitoring remain separate where outside the Core allowance.
Confirm customer ownership, identifiers, brands, keywords, contacts and authorised monitoring purpose.
Operate approved collection sources and supporting infrastructure according to the service design.
Match potential records to the authorised customer identifiers and avoid unrelated attribution.
Normalise material exposure, reduce duplicates and prepare customer-readable context.
Create required customer, endpoint, identity or investigation actions according to severity and context.
Review monitored scope, findings, response, source limitations and expanded monitoring needs.
Only authorised identifiers and customer-readable records are exposed through Guardian.
Confirm customer-owned domains, email addresses, brands, keywords, purpose and contacts.
Damocles collection services retrieve and process approved source material.
Potential records are matched to the authorised customer scope using approved rules.
Material exposure is normalised, de-duplicated and checked before customer publication.
The customer, provider or Damocles completes the agreed security, identity or communication action.
Guardian retains status, ownership, evidence and review history for the finding and response.
The product focuses on organisational identifiers and approved customer response.
Identify approved staff or organisational email exposure requiring password, identity or endpoint response.
Monitor approved domains and associated external exposure records.
Review approved brand or organisation mentions that may indicate abuse, fraud or exposure.
Operate exact customer domains, email identifiers and findings within provider scope.
Monitor approved provider domains and staff identifiers within the package allowance.
Use exposure findings as authorised context for endpoint, identity or security-operations investigation.
These details remain explicit before activation, but are grouped into one operating view so buyers can review the responsibilities without working through four separate page sections.
Onboarding confirms monitored identifiers, ownership, purpose and response contacts. The customer provides approved domains, email identifiers, brand terms, keywords, ownership, monitoring purpose, contacts, response authority and any legal or privacy constraints. Damocles confirms the included allowance and suitability of each item. Initial matching and review validate customer attribution, duplicate handling, finding context, severity and the response workflow before broad publication. Go-live includes monitoring status, finding contacts, action routing, reporting, expanded-scope process and the boundary to specialist investigation and personal monitoring.
Guardian separates the customer product from the restricted collection and source infrastructure. Collection sources and supporting services feed a controlled internal workflow. Guardian receives approved customer-readable records and source categories rather than unrestricted source identities or raw dumps. New source or connector options are reviewed for legal authority, source terms, data handling, customer attribution, duplication, provenance, supportability and operational risk before use. Customer and provider access never derives from a keyword match alone. Tenant and provider authority remains explicit and server derived.
Findings retain provenance and response context while protecting restricted source material. Guardian retains supported observation dates, affected identifier, source category, severity, customer-safe evidence, action and review history. Raw credentials, full breach dumps, source infrastructure and unrelated records remain restricted. A match is not automatically represented as a confirmed current compromise. The response depends on source age, context, credential state, affected identity and available corroborating evidence. Reports identify monitored scope and known limitations. The absence of a finding is not represented as proof that no exposure exists anywhere.
Guardian Core includes monitoring within the approved domain, email and keyword allowance. The package schedule identifies monitored domains, email addresses, keywords, brands, customer contacts, reporting and any expanded or specialist investigation scope. Participant Free does not include continuous personal dark web monitoring. Paid personal or sponsored monitoring requires an explicit product and privacy model. The customer owns identifier accuracy and response decisions. Damocles owns the collection, review and publication activities listed in the service definition.
The exact answer is confirmed in the proposal and package schedule, but these points should be understood before activation.
No. Source access changes and no service has universal coverage. The product monitors approved identifiers across the available approved collection capability.
Sensitive raw credential material is restricted. Customer views provide the context and response information required without publishing unsafe secrets.
No. Source age, context and other evidence must be reviewed before a conclusion is made.
Yes through explicit provider authority and customer-owned identifiers.
No continuous personal monitoring is included in Participant Free. It requires separate entitlement, privacy and support.
Password reset, identity review, endpoint investigation, user communication, monitoring, incident review or another customer-approved response.
Guardian does not claim visibility into every illicit forum, dataset, marketplace, private channel or exposure event.
Exact source identities, collection methods, raw breach material, credentials and crawler infrastructure are not exposed publicly or to unauthorised roles.
Findings require context and human review before the organisation concludes that an identity, device or account is currently compromised.
We will define the included identifiers, customer contacts, finding workflow, response actions and any expanded monitoring required.