VIP Guardian Protect executives' personal accounts and devices, with consent.
Attackers target the people who run your organisation by name. VIP Guardian watches each executive's corporate and personal identifiers for stolen credentials and stealer infections, and keeps their personal data under their own control.

How VIP Guardian works
From enrolment to remediation in five steps, on the same engines that already power DarkStrata.
Enrol your VIPs
An admin invites each executive or board member. Their corporate email is monitored straight away, with any existing corporate findings linked from day one.
The VIP consents and adds personal identifiers
In their private portal, the VIP gives consent and adds their own identifiers, such as personal email addresses and usernames.
Continuous matching
Every identifier is matched continuously against our breach, combolist and stealer-log data. There is no new tooling for you to set up.
Tiered alerts
Findings are scored and tiered. A stealer infection on a VIP's personal device is escalated to critical automatically. Corporate findings go to your security team; personal findings go privately to the VIP unless they choose to share.
Guided remediation and training
A step-by-step wizard helps the VIP securely reveal an exposed password, change it and turn on two-factor or passkeys, starting with device cleanup where malware is involved. A short executive security training module covers personal-device hygiene, household exposure and SIM-swap awareness.
Why attackers go after VIPs
A single compromised executive inbox drives business email compromise, fraudulent wire transfers and social engineering that trades on the VIP's authority. And VIPs live outside your security perimeter: personal laptops and phones with no EDR, and family-shared accounts.
What one stealer log from a personal laptop can hand an attacker
Corporate SSO credentials
Single sign-on passwords saved in a personal browser are lifted straight out of the log, a working path into your environment.
Live session cookies
Stolen session tokens let an attacker resume a signed-in session and bypass MFA. Changing the password alone won't close the gap.
Proof of infection
The log proves the device is compromised, so remediation starts with cleaning the device, not just changing one password.
Personal data stays the VIP's
Corporate identifiers belong to the organisation and are monitored under legitimate interest. Personal identifiers belong to the VIP and are processed only with their explicit, audited consent. The VIP chooses what to share, exposure by exposure, and can withdraw consent at any time, which purges all personal-side detail.
DarkStrata is a UK company operating to UK GDPR. We store salted hashes wherever cleartext isn't operationally required.
Your security team sees
- Findings on corporate email, from the moment a VIP is enrolled
- Aggregate counts of personal findings
- Personal findings the VIP chooses to share
Only the VIP sees
- The personal identifiers they add
- The detail of every personal exposure
- Their guided remediation and training
What we monitor for each VIP
A VIP is a cluster of identifiers, not one address. When a VIP turns up in a breach, we also flag the mobile numbers and aliases exposed alongside it, showing the SIM-swap and account-takeover risk the address alone would not.
Identifiers
- Corporate and personal email
- Mobile numbers
- Usernames and aliases
Matched against
- Stealer-log infections
- Credential combolists
- Breach records
On the roadmap
- Owned domains
- Social handles
- Dark-web mentions
- Impersonation detection
Keep reading
- Infostealer infectionsWhat they are, how they take corporate credentials from personal devices, and what to do if you've been hit.
- Two-factor guideHow to set up two-factor authentication, linked from the VIP portal.
- LensEmployees privately review their own compromised credentials and act on them. Admins see completion, not private data.
- Stolen data monitoringFind your organisation's exposed credentials, stolen session cookies and compromised devices in stealer logs.
- VIP portalAlready enrolled? Sign in at vip.darkstrata.io.(opens in a new tab)
Protect your most targeted people
Start with a free check of your domain, then talk to us about covering your executives.