Continuous monitoring for impersonation and exposure affecting you and your immediate family, with every alert assessed before it reaches you.
Impersonation and exposure develop over time. A single point-in-time report does not catch a new impersonating account created six months later.
Shield monitors continuously for a defined set of signals, assesses each hit, and alerts only where there is something worth acting on. The differentiator is the assessment layer: automated tools generate volume; Shield delivers assessed, prioritised findings with an evidence record attached.
Where escalation beyond assessment is needed, Greyline refers to specialist counsel or providers and supports that referral with its evidence record. Greyline does not itself provide content removal, platform enforcement, or public relations.
Accounts and content created to imitate you.
| Signal | What We Watch For |
|---|---|
| Fake social profiles | New accounts using your name, photographs, or likeness |
| Lookalike domains | Domains registered to imitate you or your representation |
| Fraudulent messaging | Impersonation used to solicit money or information from your contacts |
Whether your identifiers have newly surfaced somewhere they should not have.
| Signal | What We Watch For |
|---|---|
| New data breaches | Your identifiers appearing in newly disclosed breach data |
| Dark web listings | Credentials or personal data offered for sale |
| Credential reuse indicators | Signs of your details circulating in fraud-adjacent databases |
New publication of your personal details or presence.
| Signal | What We Watch For |
|---|---|
| New public mentions | Fresh media, forum, or public record appearances |
| Doxxing activity | Publication of your address, phone number, or family details |
| Search result changes | New content appearing prominently against your name |
Continuous monitoring for accounts and profiles impersonating the client
Monitoring for the client's identifiers appearing in breach and credential exposure data
Monitoring for publication of the client's personal details across monitored public sources
Assessment of each alert, with a severity rating and a recommended course of action
A dated, retained evidence record of each finding, suitable for onward use
A monthly summary, with priority alerts issued as they arise
Removal of content, platform enforcement or takedown action
Public relations, crisis communications or narrative management
Legal action or representation
Monitoring of any person who has not consented, or of a subject other than the client and their immediate family
Monitoring of private, closed or access-controlled platforms
The subject is an individual and their immediate family, not a company, brand or set of domains. The buyer is that individual, a family office, or a corporate sponsor acting for a named executive.
Individuals with public visibility and their immediate families most commonly instruct this work, along with family offices and organisations commissioning cover for a named executive, where that executive consents.
An inquiry is submitted and a scoping call confirms the client, their immediate family, and the signals to monitor.
Where an organisation is commissioning cover for an executive, that executive's written consent is confirmed before monitoring begins.
Monitoring runs continuously across the agreed public sources, breach data, and impersonation signals.
Each hit is assessed and rated for severity before it is added to the record.
A monthly summary is delivered, with priority alerts issued directly whenever something warrants immediate attention.
The following are illustrative examples of how Shield is typically used, not accounts of specific client engagements.
Following a Mirror exposure audit, a public figure subscribes to Shield so a new impersonating account or a fresh breach is caught between the annual re-scans rather than sitting undetected for months.
A company commissions Shield for a named executive following a public appointment or announcement, with the executive's written consent confirmed before monitoring begins.
A family office extends Shield coverage to a family member alongside a principal, so impersonation or exposure affecting either is caught and assessed under the same subscription.
Following a contentious personal or legal matter, an individual wants ongoing visibility into any renewed impersonation or exposure connected to their name.
| Section | Content |
|---|---|
| The period at a glance | Headline volumes: signals collected, hits assessed, alerts raised |
| Priority alerts issued during the period | Full detail on every same-day or 24-hour alert |
| Further findings this period | Medium and low-severity findings from the period |
| Items carried forward | Everything still open from this or an earlier period |
| Closed since the last summary | What has been resolved, and why |
| Trend against the subscription baseline | How this period compares with the baseline and recent months |
| Recommended actions | What to do, who owns it, and by when |
| Referrals made | Any evidence record passed to counsel or a specialist provider |
| Coverage statement | Confirmation of what was monitored, and any interruption to collection |
| Limitations and scope | What this subscription does, and does not, cover |
The specimen below shows a full monthly monitoring summary, illustrating the report structure above section by section. The subscriber, the subjects and every alert are fictitious.
Download the specimen report (PDF) →Monitoring has real edges, stated here so a client knows exactly what is, and is not, being watched.
Every enquiry is reviewed by an analyst and routed to a scoping call, a written scope is confirmed before any work begins.