Move breached employees into training, simulations and policy completion.
“Is my company data breached?” became the entry point into a much larger security system. We researched how exposure moves across people, identity, IT, platform, cloud/code and vendors — then designed products that turn that risk into evidence and action.
Current research points in the same direction as the product: people, credentials, vulnerabilities, cloud assets and third parties overlap. That is why the system could not be designed as one vulnerability table.
We stopped thinking in terms of “features” and started thinking in terms of connected attack surfaces. A compromised employee can create an identity event; the same identity can touch code, cloud and vendor systems; the product therefore needed shared context and different depths for different users.
These chapters separate external domain evidence from our design inference. The numbers are research inputs; the product implications are the decisions we derived from them.
The design journey starts with public proof, grows into an authenticated operating platform, then branches into focused intelligence products for customers who need less depth or a different commercial model.
Filter the board. Each note contains a real product question or risk plus the interface/product response it suggests.
Different users enter at different points, but every meaningful product interaction follows the same logic.
This gave us a way to keep executive views simple without taking evidence away from analysts.
The user gets evidence first. Authentication appears only when the job changes from discovering risk to continuously operating on it.
One input. No account. Answer the question already in the user’s head.
Show enough evidence to prove the product before signup.
History, score, monitoring and entry into deeper operations.
People, Platform, IT, VAPT, vendors, cloud and code.
BitWatch and Infoleak package selected jobs for different buyers.
Freshness, change, remediation and recurring intelligence justify subscription.
The system uses different scale and density for executive storytelling versus analyst evidence, while keeping the same state grammar.
Live counters and a continuously moving data field establish scale. The domain input creates a direct path into open evidence without onboarding friction.
The strongest acquisition argument is the product doing something useful. We deliberately keep navigation quiet and the main action singular.
The open result tells the user what was found, where it touches the organisation, and which surface deserves attention — without exposing every authenticated detail.
The graph is deliberately annotated, not decorative. Each point is hoverable, every axis is labelled, and the score can be drilled into vector-level evidence.
Move breached employees into training, simulations and policy completion.
Run 3,500+ structured checks and prioritise findings.
Correlate repositories, workloads, owners and runtime consequence.
See vendor posture beside first-party risk.
The product turns an identity event into a behavioural loop: classify the risk, recommend a course, schedule a simulation, track policy completion and verify improvement.
Credential or session exposure attaches to the employee.
Phishing, password, policy or technical risk determines the next action.
The relevant course is assigned instead of a generic awareness module.
Behaviour is tested after the learning intervention.
The employer sees completion and repeat-risk reduction.
The system assembles an intervention sequence from the observed risk: learn → simulate → harden identity → verify behaviour.
The redesign maps internet-facing entry points to repositories, workloads, secrets, cloud assets and owners. Findings sit beside the graph as evidence, while the bottom narrative turns scattered signals into an actionable attack path.
The engine stays dense without becoming noisy: families, state, progress and exceptions remain inspectable.
We use the same reputation language across first-party and third-party risk, while preserving the exact reason behind each score.
Security posture is translated into a procurement decision: exposure, control coverage, evidence freshness and remediation velocity.
Colour, needle position, vector detail and remediation behaviour change together so the score is consistent across company, IT and vendor views.
BitWatch compresses the same security thinking into recent compromise discovery, clear threat context and subscription access.
The information architecture becomes lighter, but evidence and visual quality stay serious. This is a different product job, not a cheaper-looking version of the platform.
Discover compromised credentials and recent data leakage without adopting the full suite.
The redesign prioritises active sessions, privilege, artifact type, recency, device context and exploitability. The table is denser, but the hierarchy is clearer because each column answers an investigation question.
Ranked by what can still be abused now. Instead of treating every credential equally, the view separates session artifacts, privileged identities, device evidence and freshness.
The case study documents how founder input, research, design and engineering changed specific parts of the system.
Founder goal was acquisition through usefulness, not a standard marketing funnel.
→ public domain scanResearch showed awareness programmes become more valuable when tied to actual employee risk.
→ automatic interventionEngineering and security workflows required URLs, CVEs, sources, owners and states to remain inspectable.
→ progressive disclosureDifferent depth and price sensitivity justified BitWatch and Infoleak as focused products.
→ portfolio architectureBecause actual production telemetry was not supplied here, the visual below is an instrumentation model with clearly labelled demonstration shapes — not claimed product performance.
The measurement model follows the product journey: public proof → account → first meaningful action → cross-module adoption → return → remediation. Each signal tells us where product value is becoming habitual or where the journey leaks.
Demo cohort normalised to 100 visitors for visual structure only.
Demo heatmap only. Final version should use organisation-level cohorts and active-value events, not page visits.
Final bars = % of active organisations using each module in a rolling 30-day window.
Measure median time from first actionable signal to verified closure by severity.
From the first domain check to identity evidence, employee intervention, technical remediation and vendor decisions, the system was designed around one principle: signal → context → action.