VIP Guardian Protect executives' personal accounts and devices, with consent.

Attackers target the people who run your organisation by name. VIP Guardian watches each executive's corporate and personal identifiers for stolen credentials and stealer infections, and keeps their personal data under their own control.

Free. We check the domain in your email address.

Talk to us about VIP Guardian
The VIP Guardian dashboard on a phone, under the organisation's own letterhead: "2 things need your attention", a Secure your accounts button, a high-severity password-stealing malware finding and a medium-severity data breach on a personal email address, and a note that what is found for personal addresses is visible only to the executive unless they choose to share it.
What the executive seesA real VIP Guardian screen, shown with sample data

How VIP Guardian works

From enrolment to remediation in five steps, on the same engines that already power DarkStrata.

  1. Enrol your VIPs

    An admin invites each executive or board member. Their corporate email is monitored straight away, with any existing corporate findings linked from day one.

  2. The VIP consents and adds personal identifiers

    In their private portal, the VIP gives consent and adds their own identifiers, such as personal email addresses and usernames.

  3. Continuous matching

    Every identifier is matched continuously against our breach, combolist and stealer-log data. There is no new tooling for you to set up.

  4. Tiered alerts

    Findings are scored and tiered. A stealer infection on a VIP's personal device is escalated to critical automatically. Corporate findings go to your security team; personal findings go privately to the VIP unless they choose to share.

  5. Guided remediation and training

    A step-by-step wizard helps the VIP securely reveal an exposed password, change it and turn on two-factor or passkeys, starting with device cleanup where malware is involved. A short executive security training module covers personal-device hygiene, household exposure and SIM-swap awareness.

Why attackers go after VIPs

A single compromised executive inbox drives business email compromise, fraudulent wire transfers and social engineering that trades on the VIP's authority. And VIPs live outside your security perimeter: personal laptops and phones with no EDR, and family-shared accounts.

What one stealer log from a personal laptop can hand an attacker

  • Corporate SSO credentials

    Single sign-on passwords saved in a personal browser are lifted straight out of the log, a working path into your environment.

  • Live session cookies

    Stolen session tokens let an attacker resume a signed-in session and bypass MFA. Changing the password alone won't close the gap.

  • Proof of infection

    The log proves the device is compromised, so remediation starts with cleaning the device, not just changing one password.

Personal data stays the VIP's

Corporate identifiers belong to the organisation and are monitored under legitimate interest. Personal identifiers belong to the VIP and are processed only with their explicit, audited consent. The VIP chooses what to share, exposure by exposure, and can withdraw consent at any time, which purges all personal-side detail.

DarkStrata is a UK company operating to UK GDPR. We store salted hashes wherever cleartext isn't operationally required.

Your security team sees

  • Findings on corporate email, from the moment a VIP is enrolled
  • Aggregate counts of personal findings
  • Personal findings the VIP chooses to share

Only the VIP sees

  • The personal identifiers they add
  • The detail of every personal exposure
  • Their guided remediation and training

What we monitor for each VIP

A VIP is a cluster of identifiers, not one address. When a VIP turns up in a breach, we also flag the mobile numbers and aliases exposed alongside it, showing the SIM-swap and account-takeover risk the address alone would not.

Identifiers

  • Corporate and personal email
  • Mobile numbers
  • Usernames and aliases

Matched against

  • Stealer-log infections
  • Credential combolists
  • Breach records

On the roadmap

  • Owned domains
  • Social handles
  • Dark-web mentions
  • Impersonation detection

Protect your most targeted people

Start with a free check of your domain, then talk to us about covering your executives.

Talk to us about VIP Guardian