Included in Guardian Core

Know when approved organisational identifiers appear in exposure data and what to do next.

Guardian Dark Web Monitoring turns approved domain, staff-email and brand-term matches into customer-readable findings, severity, context and accountable response.

Australian data residency

Guardian for Australian customers is built, operated and hosted in Australia. All Guardian customer and platform data, including backups and recovery copies, is maintained and stored within Australia.

Approved domain and email scopeBrand and keyword monitoringCustomer-readable findingsAction and risk follow-up
Buyer decision summary

Know what Guardian Dark Web Monitoring does, what the customer sees and what Damocles is responsible for before activation.

Guardian retains supported observation dates, affected identifier, source category, severity, customer-safe evidence, action and review history. Raw credentials, full breach dumps, source infrastructure and unrelated records remain restricted.

The package schedule identifies monitored domains, email addresses, keywords, brands, customer contacts, reporting and any expanded or specialist investigation scope.

Guardian does not claim visibility into every illicit forum, dataset, marketplace, private channel or exposure event.

01

What the product does

Exact collection methods and restricted source details remain operational; the customer receives the context needed to act.

02

What the customer sees

Sensitive source and record detail remains restricted according to the operational and legal controls.

03

What Damocles manages

Specialist investigation and expanded monitoring remain separate where outside the Core allowance.

The operational problem

Raw breach and dark web data is noisy, duplicated and sensitive. The customer needs verified scope and a practical response.

An exposed email address, credential record, domain reference or brand mention may require password reset, identity review, endpoint investigation, communication, monitoring or no action after review. Raw source material alone does not answer that question.

Damocles operates approved collection and review. Guardian presents only the customer-readable finding and links required response to risks and actions without exposing restricted sources, crawler infrastructure or unrelated records.

01

Monitor the identifiers that matter

Use approved business domains, staff email addresses, brands and keywords within the package allowance.

02

Present usable context

Show what was observed, affected identifier, source category, severity, dates and practical response context.

03

Drive accountable response

Create password, identity, endpoint, communication, investigation or other actions where appropriate.

Product capability

Approved external exposure monitoring through Guardian Core.

Exact collection methods and restricted source details remain operational; the customer receives the context needed to act.

DM

Domain monitoring

Monitor authorised business domains and related organisational identifiers within the package allowance.

EM

Email monitoring

Monitor approved staff or organisational email identifiers without exposing unrelated records.

KM

Keyword and brand monitoring

Track approved names, brands or terms relevant to the customer exposure risk.

CF

Customer-readable findings

Present title, severity, source category, affected scope, dates, status and practical context.

RA

Risk and action linkage

Link material exposure to Guardian risks, All Actions, owners, due dates and review.

MS

Monitoring status

Show monitored-item counts, service state and latest finding without exposing collection infrastructure.

What the customer sees

Customers see authorised exposure findings and response state, not raw breach dumps.

Sensitive source and record detail remains restricted according to the operational and legal controls.

SC

Scope summary

Approved monitored domains, emails, brands and keywords plus service state.

FD

Finding detail

Affected identifier, source category, severity, observation dates, context and required response.

AC

Response actions

Password reset, identity review, endpoint investigation, user contact, monitoring or other agreed follow-up.

HS

History and status

Open, in-progress, resolved-pending-review, closed and reopened states with ownership.

RP

Exposure reporting

Monitored scope, material findings, response progress and known collection limitations.

PV

Provider view

Authorised customer findings and actions without exposing other customers or restricted source information.

What Damocles manages

Damocles operates the approved collection, matching, review and customer-publication process.

Specialist investigation and expanded monitoring remain separate where outside the Core allowance.

SO

Scope onboarding

Confirm customer ownership, identifiers, brands, keywords, contacts and authorised monitoring purpose.

CO

Collection operation

Operate approved collection sources and supporting infrastructure according to the service design.

MM

Matching and mapping

Match potential records to the authorised customer identifiers and avoid unrelated attribution.

QR

Quality review

Normalise material exposure, reduce duplicates and prepare customer-readable context.

ER

Escalation and response

Create required customer, endpoint, identity or investigation actions according to severity and context.

SR

Service review

Review monitored scope, findings, response, source limitations and expanded monitoring needs.

Operating lifecycle

From approved monitoring scope to reviewed customer action.

Only authorised identifiers and customer-readable records are exposed through Guardian.

01

Authorise

Confirm customer-owned domains, email addresses, brands, keywords, purpose and contacts.

02

Collect

Damocles collection services retrieve and process approved source material.

03

Match

Potential records are matched to the authorised customer scope using approved rules.

04

Review

Material exposure is normalised, de-duplicated and checked before customer publication.

05

Respond

The customer, provider or Damocles completes the agreed security, identity or communication action.

06

Track and report

Guardian retains status, ownership, evidence and review history for the finding and response.

Common use cases

Common dark web and exposure-monitoring use cases.

The product focuses on organisational identifiers and approved customer response.

CR

Credential exposure

Identify approved staff or organisational email exposure requiring password, identity or endpoint response.

DM

Domain exposure

Monitor approved domains and associated external exposure records.

BR

Brand monitoring

Review approved brand or organisation mentions that may indicate abuse, fraud or exposure.

MS

MSP customer monitoring

Operate exact customer domains, email identifiers and findings within provider scope.

ND

NDIS provider monitoring

Monitor approved provider domains and staff identifiers within the package allowance.

IR

Investigation context

Use exposure findings as authorised context for endpoint, identity or security-operations investigation.

Operating model

How Guardian Dark Web Monitoring is onboarded, integrated, evidenced and scoped commercially.

These details remain explicit before activation, but are grouped into one operating view so buyers can review the responsibilities without working through four separate page sections.

ON

Onboarding and implementation

Onboarding confirms monitored identifiers, ownership, purpose and response contacts. The customer provides approved domains, email identifiers, brand terms, keywords, ownership, monitoring purpose, contacts, response authority and any legal or privacy constraints. Damocles confirms the included allowance and suitability of each item. Initial matching and review validate customer attribution, duplicate handling, finding context, severity and the response workflow before broad publication. Go-live includes monitoring status, finding contacts, action routing, reporting, expanded-scope process and the boundary to specialist investigation and personal monitoring.

IN

Connector and integration model

Guardian separates the customer product from the restricted collection and source infrastructure. Collection sources and supporting services feed a controlled internal workflow. Guardian receives approved customer-readable records and source categories rather than unrestricted source identities or raw dumps. New source or connector options are reviewed for legal authority, source terms, data handling, customer attribution, duplication, provenance, supportability and operational risk before use. Customer and provider access never derives from a keyword match alone. Tenant and provider authority remains explicit and server derived.

EV

Data, evidence and reporting

Findings retain provenance and response context while protecting restricted source material. Guardian retains supported observation dates, affected identifier, source category, severity, customer-safe evidence, action and review history. Raw credentials, full breach dumps, source infrastructure and unrelated records remain restricted. A match is not automatically represented as a confirmed current compromise. The response depends on source age, context, credential state, affected identity and available corroborating evidence. Reports identify monitored scope and known limitations. The absence of a finding is not represented as proof that no exposure exists anywhere.

CM

Commercial unit and responsibilities

Guardian Core includes monitoring within the approved domain, email and keyword allowance. The package schedule identifies monitored domains, email addresses, keywords, brands, customer contacts, reporting and any expanded or specialist investigation scope. Participant Free does not include continuous personal dark web monitoring. Paid personal or sponsored monitoring requires an explicit product and privacy model. The customer owns identifier accuracy and response decisions. Damocles owns the collection, review and publication activities listed in the service definition.

Frequently asked questions

Questions buyers ask about Guardian Dark Web Monitoring.

The exact answer is confirmed in the proposal and package schedule, but these points should be understood before activation.

Q1

Does Guardian monitor the entire dark web?

No. Source access changes and no service has universal coverage. The product monitors approved identifiers across the available approved collection capability.

Q2

Are exposed passwords shown?

Sensitive raw credential material is restricted. Customer views provide the context and response information required without publishing unsafe secrets.

Q3

Does a match prove current compromise?

No. Source age, context and other evidence must be reviewed before a conclusion is made.

Q4

Can an MSP monitor customers?

Yes through explicit provider authority and customer-owned identifiers.

Q5

Can participants receive monitoring for free?

No continuous personal monitoring is included in Participant Free. It requires separate entitlement, privacy and support.

Q6

What actions can follow a finding?

Password reset, identity review, endpoint investigation, user communication, monitoring, incident review or another customer-approved response.

Scope and boundaries

Dark web monitoring is a valuable signal source but never represented as universal or conclusive by itself.

Guardian does not claim visibility into every illicit forum, dataset, marketplace, private channel or exposure event.

Exact source identities, collection methods, raw breach material, credentials and crawler infrastructure are not exposed publicly or to unauthorised roles.

Findings require context and human review before the organisation concludes that an identity, device or account is currently compromised.

Take the next practical step

Confirm the domains, staff addresses and brand terms that should be monitored.

We will define the included identifiers, customer contacts, finding workflow, response actions and any expanded monitoring required.