Engagement · Shield

Greyline Shield

Continuous monitoring for impersonation and exposure affecting you and your immediate family, with every alert assessed before it reaches you.

What This Is

What this is.


Impersonation and exposure develop over time. A single point-in-time report does not catch a new impersonating account created six months later.

Shield monitors continuously for a defined set of signals, assesses each hit, and alerts only where there is something worth acting on. The differentiator is the assessment layer: automated tools generate volume; Shield delivers assessed, prioritised findings with an evidence record attached.

Where escalation beyond assessment is needed, Greyline refers to specialist counsel or providers and supports that referral with its evidence record. Greyline does not itself provide content removal, platform enforcement, or public relations.

Service Categories

Where Shield applies.


1. Impersonation Monitoring

Accounts and content created to imitate you.

SignalWhat We Watch For
Fake social profilesNew accounts using your name, photographs, or likeness
Lookalike domainsDomains registered to imitate you or your representation
Fraudulent messagingImpersonation used to solicit money or information from your contacts

2. Identity & Credential Exposure

Whether your identifiers have newly surfaced somewhere they should not have.

SignalWhat We Watch For
New data breachesYour identifiers appearing in newly disclosed breach data
Dark web listingsCredentials or personal data offered for sale
Credential reuse indicatorsSigns of your details circulating in fraud-adjacent databases

3. Public Exposure Monitoring

New publication of your personal details or presence.

SignalWhat We Watch For
New public mentionsFresh media, forum, or public record appearances
Doxxing activityPublication of your address, phone number, or family details
Search result changesNew content appearing prominently against your name
What Is Included

What is included.


Continuous monitoring for accounts and profiles impersonating the client

Monitoring for the client's identifiers appearing in breach and credential exposure data

Monitoring for publication of the client's personal details across monitored public sources

Assessment of each alert, with a severity rating and a recommended course of action

A dated, retained evidence record of each finding, suitable for onward use

A monthly summary, with priority alerts issued as they arise

What Is Not Included

What is not included.


Removal of content, platform enforcement or takedown action

Public relations, crisis communications or narrative management

Legal action or representation

Monitoring of any person who has not consented, or of a subject other than the client and their immediate family

Monitoring of private, closed or access-controlled platforms

Who This Is For

Who this is for.


The subject is an individual and their immediate family, not a company, brand or set of domains. The buyer is that individual, a family office, or a corporate sponsor acting for a named executive.

Individuals with public visibility and their immediate families most commonly instruct this work, along with family offices and organisations commissioning cover for a named executive, where that executive consents.

How It Runs

How it runs.


  1. An inquiry is submitted and a scoping call confirms the client, their immediate family, and the signals to monitor.

  2. Where an organisation is commissioning cover for an executive, that executive's written consent is confirmed before monitoring begins.

  3. Monitoring runs continuously across the agreed public sources, breach data, and impersonation signals.

  4. Each hit is assessed and rated for severity before it is added to the record.

  5. A monthly summary is delivered, with priority alerts issued directly whenever something warrants immediate attention.

Illustrative Examples

How this looks in practice.


The following are illustrative examples of how Shield is typically used, not accounts of specific client engagements.

Continuing coverage after a Mirror audit

Following a Mirror exposure audit, a public figure subscribes to Shield so a new impersonating account or a fresh breach is caught between the annual re-scans rather than sitting undetected for months.

Corporate cover for a named executive

A company commissions Shield for a named executive following a public appointment or announcement, with the executive's written consent confirmed before monitoring begins.

Extended family office coverage

A family office extends Shield coverage to a family member alongside a principal, so impersonation or exposure affecting either is caught and assessed under the same subscription.

Ongoing visibility after a contentious matter

Following a contentious personal or legal matter, an individual wants ongoing visibility into any renewed impersonation or exposure connected to their name.

Cadence and Deliverable

How this is delivered.


Shape
Ongoing
Cadence
Monthly
Deliverable
Monthly summary with assessed, severity-rated alerts and a retained evidence record
Review
Every alert assessed by a named analyst before it reaches the client
Report Structure

What the report contains.


SectionContent
The period at a glanceHeadline volumes: signals collected, hits assessed, alerts raised
Priority alerts issued during the periodFull detail on every same-day or 24-hour alert
Further findings this periodMedium and low-severity findings from the period
Items carried forwardEverything still open from this or an earlier period
Closed since the last summaryWhat has been resolved, and why
Trend against the subscription baselineHow this period compares with the baseline and recent months
Recommended actionsWhat to do, who owns it, and by when
Referrals madeAny evidence record passed to counsel or a specialist provider
Coverage statementConfirmation of what was monitored, and any interruption to collection
Limitations and scopeWhat this subscription does, and does not, cover
Specimen Report

See a full specimen report.


The specimen below shows a full monthly monitoring summary, illustrating the report structure above section by section. The subscriber, the subjects and every alert are fictitious.

Download the specimen report (PDF) →
Limitations and Scope

Limitations and scope.


Monitoring has real edges, stated here so a client knows exactly what is, and is not, being watched.

  • Shield monitors an individual. Monitoring at organisation, brand or domain level is a separate engagement.
  • Every subject must consent. Where an organisation commissions cover for an executive, that executive's written consent is required before monitoring begins.
  • Monitoring covers defined public sources. No monitoring service observes the entire internet, and the absence of an alert is not evidence that nothing exists.
  • Where action beyond assessment is required, Greyline refers to specialist providers and supplies the supporting evidence record. Greyline does not conduct removal action itself.
Ready to Begin

Submit a confidential inquiry.

Every enquiry is reviewed by an analyst and routed to a scoping call, a written scope is confirmed before any work begins.