Under construction The ClearSight Center is coming soon. These tools are being built in the open — what you see here is a preview, results are indicative, and everything on these pages may change before launch.
Exposure Center · Methodology & Trust
How every number here is produced
You should not trust a security company's score because it looks confident. Here is the model, the inputs, the limits, and the rules we will not break.
Governance rules
Every claim carries a citation
No score, factor or statement ships without a named source and a link. If we cannot cite it, we do not show it — including our own corpus, which is labelled as ours.
No biometrics, ever
No facial recognition, no voice matching, no 'find yourself online' image search. Not as a current limitation — as a permanent product rule.
No third-party scraping
Results come from three places only: what you consented to give us, published research and public records, and Aktoh's own breach corpus.
Consent is per action
There is no blanket terms checkbox standing in for permission. Each lookup asks for that lookup.
Pasted content is never stored
Reality Check processes in your browser and discards. The password tool never transmits the password at all — only a five-character hash prefix.
No unconsented scanning
Attack Surface Snapshot and the Executive Check read published records. We never probe infrastructure without the owner's explicit permission.
Free answers the question honestly
Paying is only ever about continuous watching. We never withhold the current answer to sell you the subscription.
The scoring model
Each product or habit carries a weight derived from what published research shows it collects and what can be inferred from it. The composite is 100 × (1 − e^(−Σw / 55)) — deliberately diminishing, because the tenth connected device tells an attacker far less than the first.
Bands: 0–24 Low, 25–49 Moderate, 50–74 High, 75–100 Severe. Percentiles come from applying the same weights across the full catalogue of profile combinations — never from comparing you against other visitors.
Limits. This is a structural model, not surveillance of you. It cannot know whether you have already hardened a setting, and it cannot see anything private. A Low score means little is inferable from what you told us — not that you are safe.
Aktoh's own corpus (Argus & Pulse)
Argus maintains our breach corpus; Pulse is our feed of breach and vulnerability activity. We report counts, data classes and meaning. We never republish raw breach content — doing so would extend the harm rather than reduce it.
Where a result is drawn from our own data we say so explicitly rather than dressing it as third-party research.
Source: Aktoh Argus · breach corpus (own data)Read the research behind the tools
Every module here is written up in long form — the incident, the data, and what to do about it.
Primary sources used across the Exposure Center
- Source: Mozilla · Privacy Not Included, "What Data Does My Car Collect?" (2023) ↗
- Source: FTC · In the Matter of Ring LLC (enforcement action) (2023) ↗
- Source: FTC · Data brokers and location data enforcement (2024) ↗
- Source: Illinois BIPA settlements (Facebook/Meta, Google Photos) (2021) ↗
- Source: Have I Been Pwned · Pwned Passwords (k-anonymity) ↗
- Source: NIST SP 800-63B · Digital Identity Guidelines ↗
- Source: CISA · Implementing phishing-resistant MFA ↗
- Source: FCC · SIM swap and port-out fraud rules (2024) ↗
- Source: FBI IC3 · Internet Crime Report (2024) ↗
- Source: Verizon · Data Breach Investigations Report (2024) ↗
- Source: OWASP · Top 10 ↗
- Source: NIST National Vulnerability Database ↗
- Source: Aktoh Argus · breach corpus (own data)
- Source: FTC · Connected devices and always-on microphones guidance ↗
Found something you think we have got wrong? That is a bug, and we want it. Tell us. Our wider security posture and published artifacts live in the Trust & Security Centre.