Skip to content

Resources · FAQ

Frequently asked questions

Answers to the questions we're asked most.

Aleph's products

  • What are Aleph's main products?

    Aleph sells two products.

    • Aleph Search: unlimited monitoring and investigation across the clear, deep and dark webs. With Aleph Search, you find the confidential data of yours that is already circulating on those layers.
    • Aleph Alert: a dashboard of alerts on your strategic data leaked across the deep and dark webs. With Aleph Alert, you are warned about the confidential data already circulating in the web's risk zones.
  • What needs do Aleph's products address?
    • Securing your company's information system and its wider information ecosystem.
    • Monitoring your data and your company's reputation — strategic, financial, legal, contractual and health data — as well as that of its executives and exposed individuals.
    • Protecting your brand: image, disinformation, fraud, counterfeiting.
    • Protecting your buildings and your people: head office, production plants, points of sale, research centres, surveillance systems.
    See our webinars
  • What do they let you do in practice?
    • Detect any kind of threat likely to disrupt your business.
    • Control cyber risk and strengthen the protection of your information system.
    • Be warned without delay of sensitive information leaks on the deep and dark webs, including those coming from your suppliers and trusted third parties.
    • Meet the requirements of the DORA, NIS2 and CRA frameworks.
    • Continuously qualify and assess how critical the risks facing your company are.
    See our workshops
  • How do your products help anticipate a cyberattack or a critical event?

    Aleph detects and qualifies threats upstream, by analysing weak signals — leaked credentials, suspicious mentions on forums, data for sale — collected across an unmatched volume of OSINT sources on the deep and dark webs. Continuous large-scale monitoring, a thorough assessment of how critical the associated risks are, and real-time alerting let you react before an attack happens, by triggering the necessary preventive actions.

    You move from crisis management to risk anticipation.

    See our webinars
  • What makes your technology unique and sovereign?

    We built a proprietary, patented technology able to index the web's invisible layers in depth. Our ability to continuously explore more than 100 million sources and 3 terabytes of unindexed data, hosted on our servers in France, makes Aleph one of the most powerful tools in the world for detecting, qualifying and mapping emerging threats.

    Aleph's products, built on its independent search engine technology and its own artificial intelligence, are 100% French, sovereign and lawful.

    Try it for free with Aleph Open Search

Security, compliance and legal framework

  • Is it lawful to browse the dark web or the deep web?

    Yes, it is lawful to browse the dark web or the deep web. These terms match no existing legal concept in French or European law. Both are an integral part of the internet, a technologically neutral communication network: any content can travel across it. Only what users do with it can constitute an offence, because of the nature of the content published or consulted, or of the goods and services offered or bought.

    Read our legal framework
  • Are Aleph's products lawful?

    Yes. They rest on a technology that indexes content explored by Aleph's crawlers on the deep and dark webs, then returns indexing results according to users' queries and search criteria. Like mainstream search engines, Aleph's crawlers travel the web to index and read every link and page they find that is reachable without breaching an information system. That indexing is therefore technologically neutral.

    Read our legal framework
  • Is searching the internet for leaked information lawful?

    Yes, under conditions: a client's legitimacy alone is not enough to make such a search lawful. Its lawfulness depends on its purpose and on how it is carried out.

    First, the purpose must be to look for leaked data concerning the client. Second, the way it is carried out must comply with regulation: only information reachable without circumventing any security measure may be analysed. Third, when the analysis reveals information that does not concern the client, that information must be neither extracted nor kept. Fourth, the search must comply with the GDPR, and in particular with the French data protection authority's recommendations.

    Read our legal framework
  • Why does a leak search require a signed mandate?

    A mandate is only required when Aleph takes part in a leak search through human intervention. In that case, the mandate formalises the client's authorisation to act on their behalf and for their own account, in order to look for leaks of information belonging to them.

    That mandate records the client's explicit, specific authorisation, and protects Aleph from any liability claim over a possible breach of the client's automated data processing system and of the data it holds.

    Read our legal framework

How it works and how we support you

  • Can I try the product before buying?

    Yes. We offer personalised demonstrations, thematic workshops and limited test phases over a defined perimeter. This lets you assess how relevant our tools are, how rich the data is, how simple it is to use, and how well it fits your use cases. Those tests are framed and supported by our teams to make them as useful as possible.

    Book a demo or an introduction call
  • Who are your clients today?

    We work with clients of every size: small and mid-sized companies, large groups and public bodies. Our products are used in sensitive sectors such as banking, insurance, industry, energy, luxury, media, healthcare, security and defence. That variety of uses and needs is what proves the robustness and versatility of our technology.

  • Do you support onboarding and day-to-day use?

    Yes. Every client gets initial training, followed by personalised support as needed. We run regular follow-up sessions or thematic workshops with the teams, and advise on reading alerts and qualifying risk. That support means fast adoption and better daily use of our products.

    See our services, training and talks
  • Do you have partners for complete, 360-degree security?

    Our network of accredited partners forms a complete cyber protection, giving you the best possible cover across the whole range of cyber risks, a 360° view and the assurance of your compliance.

    We can also work alongside your own cyber service and tool providers, in full respect of your confidentiality policy.

    Become a partner

Technical and integration

  • Do your products require an installation?

    No. Our products are reached through a secure web interface, as SaaS. No local installation is needed, which makes deployment easier and limits technical constraints. Updates happen automatically, giving you constant access to the latest features and continued compatibility with your systems.

    Book a demo or an introduction call
  • Can I define my monitoring perimeter precisely?

    Yes. You define your keywords, languages, web zones, notable items, images, search scoring, filters and alerts, which can be shared with other users on your team. Those perimeters can be adjusted at any time and let you focus monitoring on the entities that really matter. Our interface allows fine-grained, evolving management according to your operational priorities.

    Book a demo or an introduction call
  • Can I feed your data into my own analysis tools?

    Yes. We provide APIs to bring our alerts into your cybersecurity ecosystem, in particular SOCs and data processing and analysis platforms. This lets you centralise detection and incident handling, automate certain responses, and enrich your analyses with our data, without breaking your security chain.

Another question?

Get in touch