● Last anchor: 2026-09-03 · view on Polygonscan
EU AI Act enforcement: Aug 2, 2026 · GDPR fines $1.2B in 2025 · NIS2 active

Your business is a target.
Be the one that's protected.

Phishing simulation training. Dark web monitoring. Blockchain-verified audit trails. EU AI Act compliance. All in one — built for businesses without an IT team.

91% of breaches start with phishing · source: IBM 2025
EU AI Act enforcement: August 2, 2026 · fine up to $15M
WhatsApp impersonation up 340% in 2025 · Europol
Average breach detection time: 194 days · IBM Security 2024
GDPR fines 2025: $1.2B issued · DLA Piper
NIS2 enforcement begins 2026 · fine up to $10M
91% of breaches start with phishing · source: IBM 2025
EU AI Act enforcement: August 2, 2026 · fine up to $15M
WhatsApp impersonation up 340% in 2025 · Europol
Average breach detection time: 194 days · IBM Security 2024
// threat intelligence · 2025-2026
12B+
exposed accounts indexed by HaveIBeenPwned across corporate and personal breaches
197
average days before a business discovers they were breached
$20M
maximum GDPR Article 9 fine for healthcare data mishandling
340%
increase in WhatsApp business impersonation scams in 2025
$35M
maximum EU AI Act fine · or 7% of global annual turnover
60 days
until EU AI Act Article 12 logging is mandatory for AI systems

What's shipping today.
What's still being built.

One module is sold on its own right now (ZeroTrace Starter). Three ship inside Growth+ and Scale plans (phishing simulation, anti-impersonation, DSAR intake). Two are on the waitlist while integrations are being rebuilt (Dark Web Monitor · Threat Dashboard) and ZeroTrace Pro/Business are on the waitlist while Polygon on-chain publishing is paused.

// GROWTH+ / SCALE
🎣
Phishing Simulation Training
We send realistic fake phishing emails to your team every 2 weeks. Anyone who clicks gets a 2-minute training. You see a dashboard with click rates over time. Watch your team's vulnerability drop month by month.
// why this matters 91% of data breaches start with a phishing email (IBM 2025). Ships inside the Growth+ and Scale plans — no separate standalone SKU.
Included in Growth+ / Scale
See plans →
// WAITLIST
🕵️
Dark Web Monitoring
Daily scans of breach databases for your company's email domain — immediate alert when any employee credential surfaces in a leak. The upstream data source (HIBP API) has been unreachable from our fetcher since 2026-07-18; we've stopped selling this until the integration is restored.
// status HIBP API returning connection errors on every scheduled fetch. Waitlist opens as soon as the integration is verified live again.
$29 /mo · when live
Join waitlist →
// GROWTH+ / SCALE
🛡
Anti-Impersonation Monitoring
Weekly scan for typosquatting domains and fake social media profiles (Facebook, X/Twitter, TikTok) impersonating your business. When a scammer registers "yoursalon-official.com" — we detect it and give you an evidence pack ready for takedown.
// why this matters WhatsApp impersonation scams up 340% in 2025 (Europol). Ships inside the Growth+ and Scale plans — no separate standalone SKU.
Included in Growth+ / Scale
See plans →
// STARTER LIVE · PRO/BUSINESS WAITLIST
ZeroTrace Audit Trail
Tamper-evident cryptographic hash-chain of every message, consent, and deletion event. Two integrity layers with an explicit coverage boundary. Layer 1 (self-attested integrity, local HMAC audit chain) covers all entries from tenant onboarding forward. Layer 2 (third-party verifiable timestamp, daily Polygon Merkle root) has been operational since 2026-08-27 (UTC) — genesis anchor tx e261814e0cf7… in block 92779361. Entries dated on or after this date are covered by both layers with a lag of up to 24 hours (the daily anchor cycle). Entries predating it remain under Layer 1 only — on-chain proof does not backfill. Download a PDF evidence pack for any regulator, any time.
// what's live today ZeroTrace Starter — GDPR Art. 5(2) accountability audit log with local hash-chain and monthly PDF evidence pack — is available now at $49/mo. Professional ($99) and Business ($199) tiers, which promise daily Polygon on-chain publishing, are on the waitlist until the wallet is topped up and the anchor probe reports live again.
Starter $49 /mo
Learn more →
// GROWTH+ / SCALE
🤖
DSAR intake
Customer types "delete my data" on WhatsApp in any language. Intake tool records the request, generates a signed receipt for the subject, and files an internal ticket. Responds within the timeframe set by GDPR Art. 12(3) — one month from receipt of the request.
// scope Covers Art. 15 (right of access) and Art. 17 (right to erasure). Runs in 5 languages (EN/PT/ES/RU/FR). Ships inside the Growth+ and Scale plans — no separate standalone SKU.
Included in Growth+ / Scale
See plans →
// COMING SOON
📊
Security Threat Dashboard
Real-time view of your security posture: message anomalies, suspicious activity spikes, failed verification attempts, impersonation alerts, and breach detections — in one dashboard with a weekly digest email every Monday.
// status Backend security data pipeline complete; the customer-facing dashboard UI is in final build. Join the waitlist and we email you the moment it goes live.
$19 /mo · when live
Join waitlist →

Deadlines don't wait.
Neither should you.

These are real enforcement dates with real fines. BossBot Shield covers all of them.

Jan 2025
DORA — Digital Operational Resilience Act
Immutable ICT incident logs required for all financial entities in EU. 4-hour major incident notification. ZeroTrace covers the logging layer.
$5M fine · financial sector
Jan 2026
NIS2 Directive — First Enforcement Wave
2026 is the first year of real NIS2 enforcement across EU. 24h early warning + 72h full incident notification required. Covered entities: digital services, managed services, health, energy (50+ employees).
$10M fine · essential entities
AUG 2, 2026
⚠ EU AI Act — Article 12 Automatic Logging
Any business using AI in high-risk decisions (HR, credit, healthcare, education) must have automatic, tamper-proof logs of every AI decision. Logs must be kept minimum 6 months. Most SMBs have nothing in place.
$15M or 3% turnover
Sep 2026
UAE Financial AI Compliance Stack
CBUAE September 2026 deadline for unified audit trail layer in financial AI systems. 61% of UAE organizations currently have fragmented logs not meeting the standard.
GCC market opportunity
2026-27
Brazil AI Bill (PL 2338/2023)
Brazilian AI Act expected to pass 2026-2027. Requires audit trail documentation, explainability records, and incident reporting to ANPD. LGPD enforcement already active: BRL 98M+ fines issued in 2025 alone.
LATAM market · BRL 50M max fine

One standalone module.
Three inside plans. Three on the waitlist.

This is the honest map of what you can pay for right now on the security side, and what you can't yet.

// inside plans
Growth+ / Scale
Phishing simulation, anti-impersonation and DSAR intake ship as part of the Growth+ and Scale plans, alongside the core CRM + WhatsApp platform.
  • 🎣 Phishing simulation
  • 🛡 Anti-impersonation
  • 🤖 DSAR intake (Art. 12(3) window)
  • Full CRM + WhatsApp automation
See plans →
// waitlist
Coming back
These modules are paused while broken integrations are rebuilt. We are not taking payment for them until they work again.
  • 🕵️ Dark Web Monitoring (HIBP API down since 2026-07-18)
  • 📊 Threat Dashboard (final UI build)
  • ⛓ ZeroTrace Professional / Business (wallet funding pending)
Join waitlist →

Cancel anytime · No long-term contracts · Contact us for team or government pricing