Provenstone is only as good as the evidence behind it. Here is exactly where our findings come from, and where we draw the line.
Everything we find comes from records anyone can look up. We read the public certificate-transparency logs that list new HTTPS certificates, public domain and DNS records, the registration record for a domain, and web pages that are already open to any visitor. Nothing we use is private or paywalled.
We read pages the way a visitor's browser does, and we stop there. We never sign in, never guess or bypass a password, and never probe a private system. Our scanner is built so it can only reach public hosts; if a name points at a private or internal address, it refuses to fetch it. Looking at what is public is the whole job.
When a look-alike uses your name, we show you the domain and the public evidence for it. We do not call it counterfeit, and we do not accuse a person. It is a lead you can act on, and the decision is yours.
We check your own and authorized domains against the same evidence and set them aside. They are never listed as impostors. When we are not sure, we say so instead of flagging you.
We send a brand's report to an email at that brand's own domain. If someone asks for a company's report from an outside address, we hold it for a person to check before anything goes out, so a report about your company never lands in a stranger's inbox.
We act on nothing for you without your say-so. No takedown, no message to a registrar or a marketplace, nothing, until you have seen the evidence and told us to proceed.
Every finding carries its public source and the date we saw it, so it holds up when you, or a lawyer, act on it. We would rather show you five things that are all real than fifty padded with maybes. If you want to see exactly how a finding was built, ask us at hello@provenstone.com.