Methodology
How it works
Moyo does not break into systems. It asks the same kinds of questions an adversary would ask of public large language models (LLMs) like ChatGPT and Deepseek, then turns the answers into scored findings with real-world citations. Use it on your own footprint, or to learn what is already reachable about a competitor, adversary, or opponent.
Moyo only probes what models can already infer about your topic from public information. Do not paste secrets, credentials, or private documents. Need the scan to run under your control? Ask about licensing.
Who it’s for
Anyone who cares about sensitive information
If you need to see what models can assemble about you, a competitor, an adversary, or an opponent from public sources, Moyo is built for you, especially:
- · CISOs and security leadership who need a board-ready read on outside-in exposure
- · Corporate counsel, privacy, and compliance teams tracking what models can infer from public records
- · Defense, intelligence, and public-sector OPSEC programs
- · Political campaigns, parties, and public figures managing reputational and OPSEC exposure
- · Opposition research and political intelligence teams mapping what models can assemble from open sources
- · Product, GTM, and communications teams before launches or partnerships
- · M&A and diligence advisors mapping inferable strategy without claiming private access
- · AI governance owners of RAG corpora, assistants, and customer-facing models
- · Companies with competitive, regulated, or classified-adjacent intellectual property
- · Competitive intelligence and strategy teams mapping a rival from public sources
- · Founders and operators who want to know what the internet already reveals about them or about an opponent
Process
Four steps
- 01
Start, scope & explore
Investigate a topic first with a free Exposure Data scan (one topic, about 15 minutes). Additional Exposure Data scans are paid. Or buy an Exposure Snapshot or a Basis Report. Snapshot and Basis: after payment you name the organization and may add points of exploration (up to 3 for Snapshot, up to 10 for Basis), or choose Let us guide the investigation. No credentials. No private uploads. Outside-in only.
- 02
Probe models
Our analysis worker queries multiple frontier models with varied strategies against lawful public sources (filings, news, disclosures, jobs, posts, and other open material), using your points of exploration as the investigation brief.
- 03
Extract, score & QC
Human QC gates packaged Snapshot and Basis delivery. Exposure Data skips that queue: extracted claims and structured findings go out when the scan finishes, typically about 15 minutes. The first scan is free.
- 04
Deliver & act
Exposure Data: first scan free, then extracted claims and structured findings in about 15 minutes — use AI as you see fit to crunch and present. Snapshot or Basis Report: packaged for presentation, delivered by email or secure link, typically within 48–72 hours after scope is confirmed, with a clear path to remediation, re-test, or authorized white-box work.
Output
Models corroborate claims. Claims support conclusions.
Independent models each extract candidate facts. When several models agree, that fact becomes a claim. Corroborated claims then support chains: the conclusions an outsider can already reach. The graph below is from a real Moyo run.
- 01
Models
Multiple systems independently read the same public footprint. Real-world citations stay attached.
- 02
Claims
Agreement across models turns a candidate fact into corroborated evidence.
- 03
Chains
Those claims support conclusions: a capability, a timeline, a hire plan.
What do AIs know?
Run a free Exposure Data scan for one topic in about 15 minutes, or buy a Snapshot or Basis Report packaged for presentation.
Products
Three outside-in products, one analytic pipeline
All three are public-source only. Exposure Data is one topic, fast — use AI as you see fit to crunch and present. The Snapshot answers what stands out and is packaged for presentation. The Basis Report answers what exactly was found, how models reached it, which sources they cited, and what to do next — packaged for presentation.
- 01
Exposure Data
One topic. Extracted claims and structured findings in about 15 minutes. First scan free. How to read Exposure Data.
One topic · Extracted claims · Structured findings · About 15 minutes
- 02
Exposure Snapshot
A rapid briefing: notable exposures with severity scores, short explanations, example model output, and cited public sources. Packaged for presentation, including a one-page summary you can share with leadership.
Up to 3 points of exploration · Headline findings, severity scored · Real-world source attribution · Packaged for presentation · Up to 48 hours
- 03
Basis Report
The complete package: full findings with evidence excerpts, a prioritized exposure inventory, corroborating model outputs, derivation of how each conclusion was reached, a numbered Sources and Citations registry, glossary, exploitation implications, and access to the underlying raw data. Packaged for presentation. Remediation playbook optional.
Up to 10 points of exploration · Complete inventory & evidence graph · Raw data access · Packaged for presentation · Cited sources, glossary, next steps · Up to 72 hours
Compare Exposure Data, Snapshot, and Basis Report → · How to read Exposure Data →
Outside-in first, red-teaming only when authorized
Exposure Data, Snapshots, and Basis Reports use public sources only. White-box reachability assessments instrument internal RAG and LLM workflows and always require written authorization. Organizations that need repeatable analysis under their own control can also license the software. See white-box engagements. For the conceptual background, see Sensitive Information Reachability on the SenTeGuard blog.
Research
Related research
Longer conceptual pieces on information reachability and related idea-security work are published on the SenTeGuard blog (company research site, not this product domain).
-
senteguard.com/blog
Sensitive Information Reachability: The Problem and the Solution
Core introduction to information reachability and the Moyo framing: what can be inferred from public crumbs, and how to measure it.
Open article → -
senteguard.com/blog
Defining the Limits of LLM-Reachable Intelligence with Gödelian Incompleteness
Theoretical boundaries on what models can reliably reach, useful when scoping confidence and residual risk in assessments.
Open article → -
senteguard.com/blog
The Emerging Threat of Idea Leakage
Semantic exposure without explicit disclosure: why traditional DLP misses combinatorial and proximity-based leaks.
Open article →