CIPHERCUE

Continuous infrastructure observation, sourced from public records.

Find the European accounts still running foreign infrastructure.

CipherCue observes the public-facing technology, DNS posture and services of European organisations, day after day, and keeps the history. Sovereign EU vendors use it to find accounts overdue an EU-resident alternative.

91 technologies

counted across the European organisations in the public directory, from CMS and CDN to email security gateways and identity providers. Every one is an observed fact, read from public HTTP, DNS and certificate records, and tracked over time.


Email security

reCAPTCHA 1,876
Proofpoint Email Protection 1,368
OneTrust 629
Barracuda Email Protection 564

CDN & edge

Cloudflare 4,487
Fastly 904
CloudFront 556
Akamai 150

Hosting & servers

nginx 3,250
HTTP Server 2,919
IIS 364
Azure 187

SaaS & productivity

Microsoft 365 Mail 6,718
Google Workspace Mail 1,546
Facebook Pixel 709
Insight Tag 376

Analytics & tags

Google Analytics 6,932
Google Tag Manager 4,576
Meta Pixel 709
Adobe Analytics 271

CMS & frameworks

WordPress 5,941
Next.js 504
Drupal 324
HubSpot CMS 141

Every foreign incumbent has a European alternative.

CipherCue pairs the infrastructure it observes with the 39 EU-headquartered vendors in its directory: 10 categories across 14 countries. When an account is observed on a foreign incumbent, the sovereign options are already listed.

Open the European vendor directory →
Category Replaces European vendors Listed
EDR & XDR foreign endpoint and detection platforms DectarIE· WithSecureFI· ESETSK 7
IAM & SSO foreign IAM platforms UbisecureFI· EvidianFR· Nexus GroupSE 5
SIEM & observability foreign SIEM and log analytics platforms SecureVisio (product of Esecure Sp. z o.o.)PL· LogpointDK· CrowdSecFR 4
Email security foreign email security gateways LibraCyber (formerly Libraesva)IT· RetarusDE· MailfenceBE 4
IGA & PAM foreign identity governance and privileged access platforms OmadaDK· WALLIXFR· IDEEDE 4

A primary source behind every observation.

CipherCue only surfaces what any internet user can observe. Each category of observation carries the public record it was read from, so a negative assertion is always traceable.

Read the methodology →

Technology fingerprint HTTP response
DNS & email policy DNS · DMARC/SPF/MX
Subdomains & certificates CT logs
Open services TCP perimeter scan
Hosting attribution ASN / rDNS
CISA-listed software CISA KEV + date

Built for sovereign European cybersecurity vendors.

Request access, or browse what CipherCue already observes.

Request access European directory