DomainDrift for compliance and GRC

A dated, signed reading of vendor posture. And every drift since.

The questionnaire was true at signing. The job is what a vendor’s public posture is now, whether it has drifted since, and being able to show what it was on any date, in a form an auditor, an insurer or counsel working a dispute can check.

For compliance and vendor risk2 minA questionnaire says what a vendor said. The signed record says what a vendor did, on the day it happened.Transcript

Third party risk monitoring that runs continuously

Put each vendor’s domains in a group. DomainDrift watches DNS, certificates and reachability continuously, records SPF and DMARC on every scan, and alerts you on material change. It runs between reviews, which is when drift happens.

Vendor security posture change alerts

A new certificate issuer, a nameserver move, a mail-exchanger change: each lands as a drift event carrying the value before and the value after, timestamped. You learn it from the alert, not from next year’s reassessment.

How do I show a cyber insurer what our posture was?

Every observation is Ed25519 signed when it is made, chained to the previous scan, and its window is anchored to a public chain so the date is confirmed off our own infrastructure. What a domain’s DNS, certificate and email authentication looked like on a date comes out as a dated reading with a signature on it, and the insurer re-checks that signature themselves.

Evidence that verifies years later

The signing keys are published, receipts are public, and the verifier runs at /verify with no account and keeps working offline once loaded. A signature proves who made the observation and that it has not been altered since; it is added trust, on the record, permanently.

What do I hand counsel for a domain dispute?

The record is kept before any dispute exists: put the marks you defend under watch, and every reading is signed and dated from that day on, so the history a filing needs is already on the record when the filing lands. A UDRP filing, a cease and desist or a trademark infringement matter runs on dated evidence of what a name published and when. Any reading exports as a signed evidence report: DNS, certificate, registrar and email authentication as read on that date, every line signed and the reading’s window anchored to a public chain. Counsel, a registrar, an arbitration panel or a court re-checks each signature at /verify, offline, with no account.

An exhibit is evidence, not an outcome, and none of this is legal advice. A signature proves who took the reading and that it has not been altered since. What that is worth in a dispute is for counsel to say.

Check the record yourself

Every observation is Ed25519 signed the moment it is made and chained to the previous scan, against published keys. The verifier checks any receipt in your browser, with no account, and keeps working offline once the page has loaded. A signature proves who observed something and that the record has not been altered since; it does not, on its own, make the observation correct. DomainDrift puts its name on every observation, permanently.

Start with one domain

A DRM3 account puts one of your own domains under watch in a group, with signed webhook alerts on change and the complete signed record open. Paid plans raise the dials; what it costs is on its own page.

Watching something we have not built for yet? Tell us what you would watch.

CONTINUOUS INTERNET TELEMETRY24H DRIFT5,994 material changesacross 3,386 domains · 24h to ~55m ago · -579 vs yesterdayDNS DRIFT87 domains changed DNS providertop destination koaladns.comCERT DRIFT1 domains switched issuing CA24hNOW621 curated domains not reachablelast probe, steadySITE ERRORS17,705 sites serving errorslast probe · 5xx / 404 / TLSBOT DEFENSEbot defense observed on 80,408 sites429 rate-limit / 403 bot-block, a posture signal