Today it's a layer-7 mess — every app's own silo, every breach the same model failing again. xposeTIP is building the layer below: behavioral, addressable, persistent. The foundation that was missing.
We're building infrastructure, not extracting data — the layer returns what the internet already knows to the person it describes.
The credential failed. The collection is wasteful. The subject pays — and is the last to know. That's why identity has to be a layer — and that layer has to be sovereign to its subject.
The internet was designed around addressing machines. IP. DNS. BGP. TLS. Every primitive routes bytes between endpoints. Identity, though, was bolted on at layer 7 — every app reinvents authentication, every silo holds its own record, every breach proves the model is failing at scale.
But there's a signal underneath the silos. When infrastructure rotates, something persists. The IP changes. The hash morphs. The domain rotates. Yet the person behind them — their writing rhythm, their platform mix, their geographic stamps, their interest signature — stays.
Identity is not the credential. It's the behavior. And behavior, observed across enough public sources, becomes addressable. That's the layer.
Identity-aware regulation (NIS2, DORA in the EU) is starting to treat identity as a security primitive, not an application-layer concern.
Cyber-physical threats — supply chain compromises, deepfake-driven fraud, infrastructure rotation by APTs — demand identity context faster than current SOCs can produce it.
The breach epidemic of 2024 — 26B records leaked — proved at scale what we already knew: the silo model has failed. Something has to take its place. We think that something is a layer.
Four principles · How we build this layer
These aren't aspirational. They're constraints we accept upfront, encoded in the product. The layer is only worth building if we build it like this.
Self-scan: Anyone can scan their own email. Free, no justification needed.
Third-party scan: Requires documented consent — a signed DPA, an employer policy, or explicit written authorization from the data subject.
Bulk scan: Permitted for organizations scanning their own workforce under GDPR Article 6(1)(f) legitimate interest — never for profiling external individuals.
No scan is ever anonymous to us. Every scan is logged with who authorized it, when, and why.
These aren't aspirational. They're commitments we publish and expect to be held to. Every finding xpose produces shows its source, and the scoring methodology is public — so if a future version drifts from these lines, it shows up in the output, not hidden in the code.
Most identity-intelligence stacks assume a data center — managed search clusters, GPU fleets, a sprawl of services that only ever runs in someone else's cloud. xposeTIP runs 179 OSINT sources, graph algorithms, and a rules engine on a deliberately small footprint: light enough to deploy inside your own perimeter, and light on the planet at the same time.
Lean isn't a limitation we apologise for — it's a design choice. Every component is picked to do more with less, and that's exactly what makes the whole engine portable enough to run where your data has to stay.
Measured on a single low-power host (~50 W)
xpose Scan
Typical Cloud OSINT
We don't claim 100x. We claim significantly less — and we show our math.
Most tools hand you a number and tell you to trust it. xposeTIP shows the reasoning behind every finding — so a human can check it, not just accept it. Explainability isn't a courtesy here; it's what makes a finding safe to act on.
"Your score is 42 because you reuse the same username across 12 platforms. Here's why that's risky: an attacker who compromises one account can try the same credentials on all 12."
"We found your email in the LinkedIn 2021 breach. This means your password hash was exposed. Even if you changed your LinkedIn password, attackers test these credentials on every other service."
"Your GitHub profile reveals your real name, employer, location, and timezone. This is enough for a targeted phishing email that mentions your company by name."
Every finding carries its reasoning, its source, and its confidence — the context an analyst needs to validate it and act. No black boxes, no scores you take on faith.
We'd rather be the tool your team trusts because they can see how it thinks — not because they're locked in.
"Your scan data exists to protect you. The moment it stops serving that purpose, it should stop existing."
Built in Luxembourg — Ethical by constitution, not by marketing.
Methodology published, every finding sourced — so you can verify the claims on this page against what xpose actually produces.
Manifesto v3.3 — Jul 2026