What you publish can tell someone how to attack you.
Zarn scans what your organisation publishes online and flags the details that could help someone plan an attack on your people or your sites. Then it gives you safer wording to replace them.
A hostile reconnaissance review used to mean hiring a specialist consultancy for weeks. Zarn does it continuously, at a fraction of the cost.
Built by former law enforcement and protective security practitioners. Aligned to NPSA security-minded communications.
See what a hostile actor sees, before they do.
Published statement reveals control room sightlines and loading bay coverage
Why this score: Describes what a named facility can see and which entrances it covers, on a public page.
Our new control room gives the team and covers the approach to the site.
Our new facility improves how the team coordinates day to day operations across the site.
Hostile reconnaissance often starts with what you publish.
Before anyone plans an attack on a venue or a person, they look for information. Your website, staff pages, event listings, press releases, job adverts, photos and documents are easy to read and easy to piece together. Sometimes one line gives a detail away. Sometimes it takes several pages read side by side. Zarn looks for both.
- People
- Names, roles, contact details and personal context that help someone target or impersonate a member of staff.
- Sites and access
- Layouts, entrances, loading bays, control areas and security arrangements.
- Routines and timings
- Event schedules, shift patterns, deliveries and procedures that show where and when attention is thinnest.
- Images, documents and metadata
- Photographs, plans and attachments that show more than the caption says, plus file data most people never see.
Finding it is half the job. The wording is the other half.
Most tools stop at a list of problems. Zarn goes on to give your communications team the wording to use instead. Each finding shows the text that was flagged, why it matters, how it could be used, and safer wording to replace it. The guidance is anchored to NPSA security-minded communications and written from our own counter-hostile reconnaissance experience.
Each finding is scored on potential harm, usefulness to a hostile actor, how specific the exposure is and how confident we are in it. Findings are AI-assisted and reviewed by your team. Zarn supports qualified human judgement and does not replace it.
- Scan
- Give Zarn a web page, an image, a document or a draft. It reads it the way someone planning an attack would.
- Review
- Each finding is scored so you can see what to deal with first, and your team confirms what is a real risk.
- Reword
- Zarn suggests safer wording and your team decides what to publish.
- Monitor
- Pages you choose are checked again weekly, monthly or quarterly, and changes are flagged.
Built by people who have done this job.
Zarn's founders have backgrounds across law enforcement and protective security. Our specialisms include Behavioural Detection, Counter-Hostile Reconnaissance and Security-Minded communications (SMC). We built Zarn because we saw this gap in operational work, not because we were looking for somewhere to use a technology.
Martyn's Law and the security of information
The Terrorism (Protection of Premises) Act 2025, known as Martyn's Law, received Royal Assent on 3 April 2025. It requires those responsible for certain premises and events to reduce the risk of physical harm from acts of terrorism and, for larger premises and all qualifying events, their vulnerability to them.
For enhanced duty premises and qualifying events, where 800 or more people may be present, staff included, section 6 lists four kinds of public protection measure. The fourth is:
the security of information in relation to the premises or event
The person responsible must assess those measures, keep them under review and document them. Standard tier premises, with 200 to 799 people, have a different set of duties and are not covered by this one.
Parliament has already recognised that public information about premises can help someone preparing an attack. The same Act changes licensing law so that plans on public registers can be limited to exclude information likely to be useful to that person (section 34). What you publish about a venue is information about that venue. Zarn helps you see what your public pages, documents and images give away, and gives you safer wording to replace it. Reports and monitoring give you a dated record of what was found and what changed, which can support your own assessment. It does not replace it.
Zarn is not a compliance product and does not make anyone compliant. The Home Office, the SIA and NaCTSO do not endorse third-party products in respect of compliance, and the Government's stated intent is that duty-holders can comply without buying specialist services. The main duties are not yet in force, and the implementation period is at least 24 months from Royal Assent. Read the Home Office statutory guidance and take independent advice on your own position.
Last reviewed September 2026. Contains public sector information licensed under the Open Government Licence v3.0.
Built for organisations with people and places to protect.
- Venues and event operators
- Estates and business districts
- Corporate security teams
- Critical infrastructure and CNI-adjacent sites
- The defence and government supply chain
- Communications, HR and public affairs teams in sensitive organisations
If you look after many sites, Zarn can sit alongside the security services you already deliver. Talk to us about partner access.
Access is controlled, on purpose.
The same information that helps you find exposure could help someone plan an attack, so we check who we give it to.
- Request
- Tell us who you are and what you want reviewed.
- Verify
- We check your work email, your organisation, and that you own or have authority over the domains.
- Scope
- We agree what to scan and monitor and how often. Pricing depends on how much you want covered, so we agree it at this point.
- Onboard
- You get an invite, create your account, and we walk through your first review with you.
Request access
Tell us who you are and what you would like reviewed. We verify every request before anyone gets an account.
Questions people ask.
Is Zarn a cyber security product?
No. Zarn looks at physical security risk. It reads what you publish and does not test your networks or systems.
Does Zarn make us compliant with Martyn's Law?
No. The Home Office, the SIA and NaCTSO do not endorse third-party products in respect of compliance, and we do not present Zarn as one. Zarn helps you see and reduce what your public information gives away, which is relevant to the security of information duty. Take independent advice on your obligations.
How is it different from a tool that collects online data?
Those tools show you data. Zarn tells you what matters, how it could be used, and what to write instead.
Who can request access?
Organisations with a real protective security need, and only for domains they own or have authority to review.
Does a request guarantee access?
No. We verify every request and check it is a suitable use.
What does it cost?
It depends on how many pages, images, documents and drafts you want reviewed and monitored. We agree it with you when we scope access.