Fromenance

Compare

Fromenance vs brand protection and takedown vendors

Brand protection vendors find and take down impersonation infrastructure from the outside; Fromenance communication provenance answers the customer holding the lure and turns that lure into intelligence. They use different sensors at different points in the attack, so institutions run both and connect them.

What each one does

Brand protection compared with Fromenance
QuestionBrand protection and takedownFromenance
What is the sensor?Crawlers, domain registration feeds, certificate transparency logs, app stores, social platforms, and sometimes abuse mailbox submissions.The customer who received the lure. Every submission is a real impersonation attempt that was convincing enough for its target to hesitate and ask.
When does it see an attack?When the infrastructure becomes visible: a domain is registered, a certificate issued, a page crawled. Often before mail is sent, sometimes after.When the first customer forwards it, which is typically within the first hour of a campaign reaching inboxes. Fromenance does not see infrastructure that never reaches a customer.
What does the customer get?Nothing directly. The customer is not part of the workflow.A definitive Verified, Not verified, or Known fraud reply from the institution's domain in seconds, with a next step.
What does it do about the attack?Takedown requests to registrars, hosts, and platforms, with a lag measured in hours to days depending on the provider.Answers the customer, extracts indicators, adds confirmed lures to the fraud list so the next customer gets Known fraud in seconds, and exports indicators to your takedown vendor, gateway, and SIEM.
Does it know what you actually sent?No. Brand protection works from the outside in and has no record of your legitimate communications.Yes. The registry is the authoritative positive set. That is what makes Verified possible at all.
Coverage of channelsWeb, domains, social, app stores, and marketplaces. Broad, infrastructure focused.Email in v1, with the indicators from lures across any channel a customer forwards. SMS, documents, and voice are on the roadmap.
How they work togetherReceives indicators and campaign exports from Fromenance through signed webhooks and STIX 2.1, and gets the earliest possible signal: the lure itself.Uses your takedown vendor as the enforcement arm. Fromenance does not file takedowns.

A different sensor

Brand protection and takedown platforms are good at what they do, and Fromenance exports to them. The gap is the person on the other end of the message.

Outside in

Monitoring works from public signals: new domains that resemble yours, certificates, cloned pages, fake apps. It finds infrastructure. It cannot tell your customer whether the message in their inbox is yours, and it only sees the campaigns whose infrastructure is visible to a crawler.

Inside out

Fromenance starts from what you sent. A submission that does not match is, by construction, a message that reached a real customer and claimed to be you. Its domains, URLs, phone numbers, and QR payloads are extracted in seconds and can be pushed to your takedown vendor through a signed webhook or a STIX export. The vendor gets the lure before their crawler would have found the page.

Why both

Keep your takedown vendor; they are the enforcement arm. Add Fromenance as the customer facing answer and the earliest sensor, and connect them with the indicator.new and verdict.created webhooks. On the roadmap, confirmed campaigns export to the takedown vendor with one click.

Run a 60 to 90 day pilot on one communication stream.

Fraud alerts or transaction alerts are the best first stream. You get a written report of verification volume, verdict distribution, campaigns discovered, and intelligence yield.