Real-time Certificate Transparency monitoring

Catch phishing impersonating your brand
before it goes live.

Heartex watches every SSL certificate issued worldwide. The moment a domain impersonating your brand gets a certificate — often hours before the phishing site is live — you get an alert and a one-click coordinated takedown.

< 2 min
cert → screenshot
22
brands monitored
CT + Telegram
detection sources
AI vision
visual proof
How it works

Detection to takedown, in one place

No agents to install, no SDK. You add the brand names you want protected; we handle the rest.

Detect at certificate issuance

We stream the public Certificate Transparency logs in real time. When a new certificate's domain matches your brand and isn't your own, it's flagged — typically hours ahead of feeds that wait for the site to go live.

Classify with content-aware AI

Each candidate is checked against the domain's registrant (is it the brand's own domain?) and its live page (a credential-harvest login, or just a site that mentions the brand?). You see phishing, brand use, suspicious, or legit — not noise.

Coordinated takedown

Registrar, hosting, CDN and certificate-authority abuse contacts are resolved automatically. One click submits to Netcraft and the anti-phishing ecosystem. Browser-blocklist links are one tap away.

Automatic status tracking

We keep probing each domain. When a phishing site is taken down or sinkholed, the alert resolves itself — you watch your action work, hands-off.

Read the full step-by-step guide, screen by screen →
Inside the dashboard

Your whole brand-protection workflow, on one screen

Every impersonation domain and Telegram account — scored, visually confirmed, and one click from takedown. This is exactly what your fraud team sees.

app.heartex.eu/alerts
Heartex Brand Sentry alerts dashboard with visual-evidence badges
app.heartex.eu/alerts/finora.appsuite.id
Alert detail showing AI visual evidence of a brand-impersonation page

Live product, real data. The 📸 badges in the grid mark domains an AI vision model has visually confirmed as impersonation; the detail view shows the captured page itself, with a one-click coordinated takedown.

Visual evidence

We don't guess — we show you the page

For every live suspect, an isolated headless browser renders the actual page and an AI vision model confirms the impersonation from the pixels. You get court-ready proof to forward to a registrar — not just a probability score.

Captured fake Finora login page
finora.appsuite.id
match 92% credential-harvesting login clone
Captured fake Ignitis customer portal
e-bok-ignitis.billingo.pl
match 92% fake Ignitis customer portal
Captured Finora brand look-alike site
finora-me.com
match polished brand look-alike

Real captures from live monitoring — two credential-harvesting login clones (fintech & energy) and a brand look-alike landing page. Parked or unrelated pages return “no brand match” and auto-resolve, so analysts only ever look at real threats.

Why Heartex

Upstream of the browser. On the brand's side.

Browsers warn end-users once a phishing site is known. Heartex protects the brand — earlier, and with the levers to actually remove the site.

Browser Safe Browsing
Heartex Brand Sentry
Built for
End users, at browse time
The brand owner
When it acts
After the site is known / visited
At certificate issuance
What it does
Warns the visitor
Visibility + coordinated takedown
False-positive control
Heuristic
Registrant + content-aware AI

Early

Caught at cert issuance — hours ahead of feeds that wait for a live site or a victim report.

Coordinated

Registrar, hosting, CDN and CA abuse — hit every pressure point, not just one email.

Accurate

Registrant ownership + page-content AI separate real phishing from sites that merely mention you.

Visual proof

A headless browser screenshots every live suspect; an AI vision model confirms the impersonation — evidence you can act on.

Telegram & social

We also monitor Telegram for channels and accounts impersonating your brand — a blind spot for most vendors.

Look-alikes

Typosquats, homoglyphs and IDN/Punycode look-alikes are caught — not just exact keyword matches.

Pricing

Start free. Scale with us.

Prove it on one brand with a 14-day pilot. Need more brands, higher volume, or deeper integration? We size it to your portfolio — just talk to us.

Pilot

Prove it on your brand — free for 14 days.
  • 1 brand
  • Real-time CT-log + Telegram detection
  • AI classification + visual evidence
  • Coordinated takedown + auto status tracking
  • Email, Slack & Teams alerts

Scale & Enterprise

More brands, higher volume, deeper integration.
  • Multiple brands & higher alert volume
  • Custom webhook (SOC / SIEM) + API access
  • Priority takedown & metrics reporting
  • SLA & dedicated support
  • DPA / EU data residency
Talk to sales

Fair-use limits per plan · no setup fee · cancel anytime. Pricing tailored to your brand portfolio.