How it works

From “I think we got hacked” to “handled.”

GuardPilot does the watching, the explaining, and the follow-up. You just do the fixing — guided the whole way.

1

We watch

We continuously scan dark-web marketplaces and infostealer malware logs for your team’s logins — the moment they leak.

2

We explain

AI turns each raw finding into a plain-English incident summary: what was exposed, how it likely happened, and how serious it is.

3

We guide

You get a step-by-step recovery plan tailored to the exact account and threat — no security jargon, no guesswork.

4

We remind

We track every step and nudge you until the incident is fully resolved, so nothing slips through the cracks.

See how it works
Your runbook

What actually happens, step by step.

From creating your account to a closed incident. Here is the whole path, in plain language.

  1. 1

    Create your account

    Sign up with your email in under a minute. No credit card, no security setup. You land straight in your dashboard.

  2. 2

    Tell us what to check

    Add the login you want checked: a work email, a domain you own, or a specific vendor account (the website plus the username you use there). On the free plan you get one check to start.

  3. 3

    We run the check

    GuardPilot scans dark-web marketplaces, data breaches, and infostealer malware logs for that login. This takes about 1 minute. You do not have to do anything while it runs.

  4. 4

    See your result

    • Nothing found: you are clear for now. We keep watching and alert you the moment that changes.
    • Something found: we show you what leaked (the account, the breach it came from, the date, and whether a password was exposed). We never show or store the actual password.
  5. 5

    Open the incident

    If a login is exposed, GuardPilot opens an incident for it. Our AI explains it in plain English: what was exposed, how it likely happened, and how serious it is. No jargon.

  6. 6

    Work the fix, step by step

    Each incident comes with a short, ordered checklist built for that exact account. Typically:

    1. Change the password on the affected site first, to something new and unique.
    2. Sign out of all active sessions, so a stolen login is kicked out.
    3. Turn on two-factor authentication, so a leaked password can’t be used on its own.
    4. Change that password anywhere else you reused it.

    You do each step, then tick it off. GuardPilot tracks your progress.

  7. 7

    Confirm it’s resolved

    When you have worked through the checklist, mark the incident resolved. If you stall, we send reminders so nothing slips through the cracks. You can download a clean report of what happened and what you did, for an insurer, auditor, or your own records.

  8. 8

    Stay watched

    GuardPilot keeps monitoring in the background. If that login leaks again, or a new one does, you get alerted and the same simple runbook starts over.

Why GuardPilot

Most tools tell you you’ve been breached. Then they leave.

GuardPilot is the only one that puts an AI incident responder on the case, turning a scary alert into a guided recovery, in plain English, and staying with you until it’s fixed.

Typical breach-alert tools
  • Hand you a list of leaked emails
  • Leave you to guess how bad it is
  • No idea what to actually do next
  • No follow-up, you’re on your own
GuardPilot’s AI incident response
  • AI explains what happened and the likely root cause
  • Rates the severity and what’s truly at risk
  • Builds a step-by-step recovery plan for that exact account
  • Ask-anything chat answers your questions instantly
  • Tracks every step and reminds you until it’s resolved

See what’s already exposed.

It takes two minutes and the first scan is free. If we find nothing, that’s the best money you never spent.