# Defench

*/Startups/Defench*

## Startup Overview

This threat mitigation engine automatically identifies and dismantles lookalike phishing domains. Rather than generating endless alerts for human review, the system executes the complete takedown sequence—from initial detection and evidence gathering to registrar submission and domain suspension.

Security and brand protection teams face a continuous barrage of malicious websites engineered to harvest customer credentials. Relying on manual investigations and prolonged legal correspondence leaves these fraudulent sites active for days, exposing users to attacks while draining internal resources.

Legacy threat intelligence vendors like ZeroFox and PhishLabs depend on human analysts to verify threats and process takedowns, often locking enterprises into rigid subscription retainers. By contrast, this solution operates fully autonomously to neutralize threats without manual intervention. Aligning cost directly with security outcomes, the service bills exclusively per successful domain takedown.

## Startup Founding Hypothesis

**Approach**: that automatically identifies and dismantles lookalike phishing domains
**Competitors**:
- [ZeroFox](/Competitors/ZeroFox)
- [PhishLabs](/Competitors/PhishLabs)
- [manual brand protection teams](/Competitors/manual_brand_protection_teams)
**Differentiator2x2**: fully autonomous in execution and billed only per successful takedown

## Startup Solution Coordinate

**Solution**: [Domain Takedown Agent](/Agents/Domain_Takedown_Agent)

## Startup Position2x2

```mermaid
quadrantChart
x-axis Manual Operations --> Fully Autonomous
y-axis Fixed Fee & Subscription --> Pay-per-Successful Takedown
quadrant-1 AI Takedown Agents
quadrant-2 Contingency Services
quadrant-3 Internal SOCs
quadrant-4 Brand Protection SaaS
Defench: [0.88, 0.88]
ZeroFox: [0.75, 0.25]
PhishLabs: [0.55, 0.30]
Manual Brand Protection Teams: [0.15, 0.15]
```

## Startup Offer

**Proof**:
- Target: Mid-market fintechs achieving under 24-hour median domain takedown times.
- Target: E-commerce brands automating lookalike discovery without deploying human analysts.
- Target: Crypto exchanges dropping their cost-per-takedown by over 50% compared to legacy legal retainers.
**Tiers**:
- Name: Standard Enforcement · Price: ~$200–$350 per takedown · Inclusions: Continuous lookalike domain scanning against your primary brand terms, automated evidence logging, and standard registrar abuse desk submissions.
- Name: Priority Dispatch · Price: ~$450–$650 per takedown · Inclusions: Expedited host-level notifications, automated DMCA drafting, and recursive upstream provider escalation for uncooperative registrars.
- Name: Enterprise Scale · Price: ~$100–$180 per takedown · Inclusions: High-volume enforcement designed to ingest custom threat-intelligence feeds, with API access and custom escalation routing. Requires an annual minimum commitment.
**Guarantee**: Clients are billed exclusively when a malicious domain is confirmed offline; if an enforcement action fails to remove the target, the attempt incurs zero charge.
**Business Function**: ProvideService
**Objection Handlers**:
- What if the registrar ignores your automated request? -> The system is designed to escalate automatically to the hosting provider, reverse proxy, and upstream transit networks if the registrar fails to act within 24 hours.
- How do you prevent taking down legitimate fan sites or authorized affiliates? -> The identification model relies on strict, objective matching criteria—such as active credential-harvesting forms or exact-match logo theft—and enforces based on your explicit allowlists.
- Why not just use our internal legal counsel? -> Internal counsel costs hundreds of dollars per hour to draft routine letters; this system executes the exact same abuse-desk protocols instantly at a fixed unit cost, 24/7.
**Pricing Architecture**: UsageMeter
**Agent Checkout Support**:
- agentic-commerce-protocol

## Startup Brand

**Voice**: Authoritative and decisive, prioritizing concrete action over theoretical risk.
**Tagline**: Guaranteed takedowns of lookalike phishing domains.
**Icon Concept**: hook
**Palette Intent**: institutional-cool
**Visual Identity**: Deep navy and stark white typography anchor the clinical aesthetic, accented by high-contrast crimson to flag dismantled threats.
**Archetype Reference**: the-hero

## Startup Buyer Chain

**Chain**: Defench → Corporate SecOps Team → Brand Consumer
**Gtm Motion**: Acquires customers by scanning certificate transparency logs to find live lookalike domains and offering the initial takedown on a contingency, pay-on-success basis. Expands account value by shifting buyers from ad-hoc threat remediation to continuous monitoring and automated takedown retainers across all global brand permutations.
**Agent Channel**: Designed for listing in security orchestration tool registries, such as the Tines action library or Torq integration catalog, allowing autonomous SecOps agents to discover and trigger the takedown API directly.
**Primary Channel**: Targeted outbound alerts to CISOs and IT Security Directors, triggered automatically when a live, un-remediated phishing domain matching their company name is detected in public DNS records.

## Startup Customer Journey

```mermaid
flowchart LR; A[DNS Phishing Alert] --> B[Contingency Offer]; B --> C[Abuse Desk Submission]; C --> D[Verified Domain Removal]; D --> E[Continuous Lookalike Scanning]; E --> F[Enterprise Takedown Retainer]; F --> G[Tines Action Registry];
```

## Startup Proof Points

_Illustrative — target and order-of-magnitude estimate figures, not an achieved track record (this Thing is concept-stage)._

**Pilot Goals**:
- A 30-day parallel run against legacy legal counsel to prove the automated system achieves equivalent or faster domain suspensions at a lower unit cost
- A 60-day integration pilot with a custom threat-intelligence feed to demonstrate zero manual intervention required from discovery to successful upstream provider escalation
**Target Metrics**:
- Target: Under 24-hour median time to domain suspension
- Target: 100 percent correlation between billed usage and successfully verified offline status
- Target: Greater than 50 percent reduction in average cost-per-takedown compared to internal legal counsel
- Target: Zero false-positive enforcement actions against authorized affiliate or fan domains
**Target Case Studies**:
- A mid-market fintech CISO transitioning from manual legal retainers to automated enforcement, aiming to reduce median lookalike domain takedown time from weeks to under 24 hours
- An enterprise e-commerce Fraud Director integrating the threat-intelligence API to automatically ingest and neutralize active credential-harvesting phishing sites without human review
- A cryptocurrency exchange Security Operations Lead aiming to cut per-incident brand enforcement costs by 50 percent while scaling takedown volume across uncooperative registrars
**Testimonial Targets**:
- Target CISO sentiment highlighting relief at replacing unpredictable hourly legal fees with a strictly success-based takedown cost structure
- Target Head of Fraud sentiment praising the automated escalation path from unresponsive registrars to upstream hosting providers
- Target Brand Protection Manager sentiment validating the accuracy of the automated evidence logging and DMCA drafting

## Startup Top Risks

**Risks**:
- Severity: existential · Description: Major domain registrars and hosting providers block or rate-limit automated takedown requests, severing the autonomous execution pipeline. · Mitigation Status: in-progress
- Severity: high · Description: False positives result in the accidental takedown of legitimate client or partner domains, leading to severe legal liability and immediate churn. · Mitigation Status: in-progress
- Severity: high · Description: The pay-per-takedown billing model generates unpredictable revenue that fails to cover the fixed compute costs required for continuous global web scanning. · Mitigation Status: unmitigated
- Severity: moderate · Description: Threat actors deploy rapidly rotating, procedurally generated subdomains that outpace the scanning frequency and depress the successful takedown volume. · Mitigation Status: unmitigated

## Startup Competitors

- [ZeroFox](/Competitors/ZeroFox) — Incumbent Platform
- [PhishLabs](/Competitors/PhishLabs) — Managed Service Provider
- [Manual Brand Protection Teams](/Competitors/Manual_Brand_Protection_Teams) — Status Quo
- [Bolster Security](/Competitors/Bolster_Security) — AI Brand Protection
- [Red Sift](/Competitors/Red_Sift) — Domain Security Vendor
- [MarkMonitor](/Competitors/MarkMonitor) — Legacy Corporate Registrar

## Startup Solution Stack

- [Lookalike Mitigation Service](/Services/Lookalike_Mitigation_Service) — Service-as-Software
- [Domain Discovery Agent](/Agents/Domain_Discovery_Agent) — Agent
- [Takedown Enforcement Agent](/Agents/Takedown_Enforcement_Agent) — Agent
- [Registrar Abuse API](/Software/Registrar_Abuse_API) — Software
- [Phishing Heuristics Engine](/Software/Phishing_Heuristics_Engine) — Software

## Startup Story Brand

**Hero**:
- **Need**: to be the proactive guardian of the brand's digital perimeter, not a reactive victim
- **Want**: to dismantle lookalike phishing domains before they harvest a single customer credential
- **Identity**: the Head of Trust and Safety at a mid-market fintech
**Plan**:
- Step: Upload allowlist · Detail: Provide your authorized affiliates and fan sites to ensure only true malicious lookalikes are targeted.
- Step: Approve targets · Detail: Review the identified threats and the evidence logs before triggering the automated enforcement sequence.
- Step: Monitor takedowns · Detail: Watch the dashboard as the system escalates from registrars to upstream providers until the site drops.
**Guide**:
- **Empathy**: You shouldn't still be manually drafting abuse reports. PhishLabs wasn't built to execute autonomous takedowns without human analysts.
**Problem**:
- **Villain**: lookalike domain sprawl
- **External**: Scammers register typosquatted domains that bypass manual ZeroFox alerts, leaving IT teams to draft manual DMCA takedown requests.
- **Internal**: You feel like you are playing a losing game of whack-a-mole while legal fees climb.
- **Philosophical**: Brand protection belongs in autonomous execution, not in billable legal hours.
**Success**: Phishing sites go dark in under 24 hours while you only pay for confirmed takedowns.
**One Liner**: Every day, mid-market fintechs lose customers to typosquatted phishing sites. Defench automates the discovery and dismantling of lookalike domains so your brand stays protected 24/7.
**Positioning**:
- **So That**: malicious domains are dismantled without manual legal drafting
- **Unlike**: manual brand protection teams
- **For Whom**: Head of Trust and Safety
- **Category**: Autonomous Brand Protection
**Call To Action**:
- **Direct**: Submit a domain
- **Transitional**: Download evidence log
**Failure Stakes**:
- Compromised customer credentials
- Ballooning legal retainer costs
- Delayed response to active fraud
**Transformation**:
- **To**: the guardian who automates digital enforcement
- **From**: the analyst chasing registrars in spreadsheets
**Controlling Idea**: Brand protection must be autonomous and results-based to stay ahead of scammers.

## Startup Token Hero

**Genre**: founding-hypothesis
**Rendered**: Every day, mid-market fintechs lose customers to typosquatted phishing sites. Defench automates the discovery and dismantling of lookalike domains so your brand stays protected 24/7.
**Mechanism**: spine-derived-v1
**Template Id**: spine-founding-hypothesis
**Vocab Fingerprint**: 2e8c6e011137df37

## Startup Token Positioning

**Genre**: moore-positioning
**Rendered**: Autonomous Brand Protection for Head of Trust and Safety. Unlike manual brand protection teams — malicious domains are dismantled without manual legal drafting.
**Mechanism**: spine-derived-v1
**Template Id**: spine-moore-positioning
**Vocab Fingerprint**: 7bf10b88d6347c3e

## Startup Token Pitch Deck

**Genre**: pitch-deck
**Rendered**: Problem: Scammers register typosquatted domains that bypass manual ZeroFox alerts, leaving IT teams to draft manual DMCA takedown requests.
Solution: Every day, mid-market fintechs lose customers to typosquatted phishing sites. Defench automates the discovery and dismantling of lookalike domains so your brand stays protected 24/7.
Customer: Head of Trust and Safety
Unlike: manual brand protection teams
**Mechanism**: spine-derived-v1
**Template Id**: spine-pitch-deck
**Vocab Fingerprint**: 03fe19ce639e65f6

## Startup Token M E D D P I C C

**Pain**: Scammers register typosquatted domains that bypass manual ZeroFox alerts, leaving IT teams to draft manual DMCA takedown requests.
**Metrics**: Target: Phishing sites go dark in under 24 hours while you only pay for confirmed takedowns.
**Rendered**: Pain: Scammers register typosquatted domains that bypass manual ZeroFox alerts, leaving IT teams to draft manual DMCA takedown requests.
Economic buyer: Corporate SecOps Team
Metrics: Target: Phishing sites go dark in under 24 hours while you only pay for confirmed takedowns.
Competition: manual brand protection teams
**Mechanism**: spine-derived-v1
**Competition**: manual brand protection teams
**Economic Buyer**: Corporate SecOps Team
**Vocab Fingerprint**: 3c19ac7725f6357f

## Startup Token Cold Email

**Genre**: cold-email
**Rendered**: Subject: Autonomous Brand Protection for Head of Trust and Safety

Head of Trust and Safety — Scammers register typosquatted domains that bypass manual ZeroFox alerts, leaving IT teams to draft manual DMCA takedown requests. Every day, mid-market fintechs lose customers to typosquatted phishing sites. Defench automates the discovery and dismantling of lookalike domains so your brand stays protected 24/7.
**Mechanism**: spine-derived-v1
**Template Id**: spine-cold-email
**Vocab Fingerprint**: 3a9f7d735fb940dd

## Startup Token Agent Spec

**Genre**: ai-agent-spec
**Rendered**: Autonomous Brand Protection. Every day, mid-market fintechs lose customers to typosquatted phishing sites. Defench automates the discovery and dismantling of lookalike domains so your brand stays protected 24/7. Serves Head of Trust and Safety.
**Mechanism**: spine-derived-v1
**Template Id**: spine-ai-agent-spec
**Vocab Fingerprint**: cd80c4e562620de2

## Neighborhood

### Candidate solutions

- [Service Technician Shortage](/Problems/Service_Technician_Shortage) — candidate solution for · Problems

### Composed of

- [Diagnostic Guidance Service](/Services/Diagnostic_Guidance_Service) — composes · Services
- [Fault Isolation Agent](/Agents/Fault_Isolation_Agent) — composes · Agents
- [Diagnostic Telematics API](/Software/Diagnostic_Telematics_API) — composes · Software
- [Telemetry Ingestion Engine](/Software/Telemetry_Ingestion_Engine) — composes · Software
- [Schematic Vision Worker](/Agents/Schematic_Vision_Worker) — composes · Agents
- [Telemetry Synthesis Agent](/Agents/Telemetry_Synthesis_Agent) — composes · Agents
- [Fault Code API](/Software/Fault_Code_API) — composes · Software
- [Diagnostic Telemetry Engine](/Software/Diagnostic_Telemetry_Engine) — composes · Software
- [Schematic Overlay Agent](/Agents/Schematic_Overlay_Agent) — composes · Agents
- [Diagnostic Triage Service](/Services/Diagnostic_Triage_Service) — composes · Services
- [Phishing Heuristics Engine](/Software/Phishing_Heuristics_Engine) — composes · Software
- [Registrar Abuse API](/Software/Registrar_Abuse_API) — composes · Software
- [Takedown Enforcement Agent](/Agents/Takedown_Enforcement_Agent) — composes · Agents
- [Domain Discovery Agent](/Agents/Domain_Discovery_Agent) — composes · Agents
- [Lookalike Mitigation Service](/Services/Lookalike_Mitigation_Service) — composes · Services

### Embodies

- [Software](/Theses/Software) — embodies · Theses
- [Agent](/Theses/Agent) — embodies · Theses

### What it offers

- [Defench Diagnostic Suite](/Software/Defench_Diagnostic_Suite) — offers · Software
- [Domain Takedown Agent](/Agents/Domain_Takedown_Agent) — offers · Agents

### Who it serves

- [Automobile Dealers](/CompanyTypes/Automobile_Dealers) — serves · CompanyTypes

### Competitors

- [Mitchell 1 ProDemand](/Competitors/Mitchell_1_ProDemand) — competes with · Competitors
- [ALLDATA Repair](/Competitors/ALLDATA_Repair) — competes with · Competitors
- [CDK Service](/Competitors/CDK_Service) — competes with · Competitors
- [Master Technician Escalation](/Competitors/Master_Technician_Escalation) — competes with · Competitors
- [Master Tech Escalations](/Competitors/Master_Tech_Escalations) — competes with · Competitors
- [Master Tech Escalation](/Competitors/Master_Tech_Escalation) — competes with · Competitors
- [Identifix Direct-Hit](/Competitors/Identifix_Direct-Hit) — competes with · Competitors
- [Alldata](/Competitors/Alldata) — competes with · Competitors
- [Master Tech Triage](/Competitors/Master_Tech_Triage) — competes with · Competitors
- [Master Technician Escalations](/Competitors/Master_Technician_Escalations) — competes with · Competitors
- [Mitchell 1](/Competitors/Mitchell_1) — competes with · Competitors
- [Red Sift](/Competitors/Red_Sift) — competes with · Competitors
- [Bolster Security](/Competitors/Bolster_Security) — competes with · Competitors
- [Manual Brand Protection Teams](/Competitors/Manual_Brand_Protection_Teams) — competes with · Competitors
- [ZeroFox](/Competitors/ZeroFox) — competes with · Competitors
- [PhishLabs](/Competitors/PhishLabs) — competes with · Competitors
- [MarkMonitor](/Competitors/MarkMonitor) — competes with · Competitors

### Similar Startups

- [Actiondomain](/Startups/Actiondomain) — similar · Startups
- [Retraga](/Startups/Retraga) — similar · Startups
- [Spottercenter](/Startups/Spottercenter) — similar · Startups
- [Security](/Startups/Security) — similar · Startups
- [Strikyard](/Startups/Strikyard) — similar · Startups
- [Sepsoph](/Startups/Sepsoph) — similar · Startups
- [Triage](/Startups/Triage) — similar · Startups
- [Shadowlounge](/Startups/Shadowlounge) — similar · Startups
- [Domyn](/Startups/Domyn) — similar · Startups
- [Canopy Strike](/Startups/Canopy_Strike) — similar · Startups
- [Viscop](/Startups/Viscop) — similar · Startups
- [Domainpoint](/Startups/Domainpoint) — similar · Startups
- [Detectionyard](/Startups/Detectionyard) — similar · Startups
- [Gatherstar](/Startups/Gatherstar) — similar · Startups
- [Forgescreen](/Startups/Forgescreen) — similar · Startups
- [Cfervices](/Startups/Cfervices) — similar · Startups
- [Casdomain](/Startups/Casdomain) — similar · Startups
- [Spamworks](/Startups/Spamworks) — similar · Startups
- [Abdicable](/Startups/Abdicable) — similar · Startups
- [Firmsabatement](/Startups/Firmsabatement) — similar · Startups
