What you publish can tell someone how to attack you.

Zarn scans what your organisation publishes online and flags the details that could help someone plan an attack on your people or your sites. Then it gives you safer wording to replace them.

A hostile reconnaissance review used to mean hiring a specialist consultancy for weeks. Zarn does it continuously, at a fraction of the cost.

Built by former law enforcement and protective security practitioners. Aligned to NPSA security-minded communications.

See what a hostile actor sees, before they do.

app.zarn.ai/organisations/northbridge/findings/001
ZarnNorthbridge Events Group
Example
Findingsnorthbridge-events.example
23 findings
HighSecurity Posture ExposureFinding 1 of 23

Published statement reveals control room sightlines and loading bay coverage

Score
68/100

Why this score: Describes what a named facility can see and which entrances it covers, on a public page.

Source: northbridge-events.example/news/new-control-roomLocation: Paragraph 2 of page text
Flagged content

Our new control room gives the team and covers the approach to the site.

Why it matters
Tells a reader what the control room can see and which entrances it covers.
Possible hostile use
Helps someone judge where staff attention is focused, and where it may not be.
Safer alternative wording

Our new facility improves how the team coordinates day to day operations across the site.

Recommended mitigation
Replace specific sightline and coverage detail with a general statement of purpose.
Why it works
Describes what the facility is for, not what it can see.
Other findings in this review
HighAccess Control Exposure
Site access detail visible on a public venue plan
64/100
MediumRole or Seniority Exposure
Staff directory exposes reporting structure and named security contacts
52/100
Scores help you prioritise review. They are not a prediction of an attack.

Hostile reconnaissance often starts with what you publish.

Before anyone plans an attack on a venue or a person, they look for information. Your website, staff pages, event listings, press releases, job adverts, photos and documents are easy to read and easy to piece together. Sometimes one line gives a detail away. Sometimes it takes several pages read side by side. Zarn looks for both.

People
Names, roles, contact details and personal context that help someone target or impersonate a member of staff.
Sites and access
Layouts, entrances, loading bays, control areas and security arrangements.
Routines and timings
Event schedules, shift patterns, deliveries and procedures that show where and when attention is thinnest.
Images, documents and metadata
Photographs, plans and attachments that show more than the caption says, plus file data most people never see.

Finding it is half the job. The wording is the other half.

Most tools stop at a list of problems. Zarn goes on to give your communications team the wording to use instead. Each finding shows the text that was flagged, why it matters, how it could be used, and safer wording to replace it. The guidance is anchored to NPSA security-minded communications and written from our own counter-hostile reconnaissance experience.

Each finding is scored on potential harm, usefulness to a hostile actor, how specific the exposure is and how confident we are in it. Findings are AI-assisted and reviewed by your team. Zarn supports qualified human judgement and does not replace it.

Scan
Give Zarn a web page, an image, a document or a draft. It reads it the way someone planning an attack would.
Review
Each finding is scored so you can see what to deal with first, and your team confirms what is a real risk.
Reword
Zarn suggests safer wording and your team decides what to publish.
Monitor
Pages you choose are checked again weekly, monthly or quarterly, and changes are flagged.

Built by people who have done this job.

Zarn's founders have backgrounds across law enforcement and protective security. Our specialisms include Behavioural Detection, Counter-Hostile Reconnaissance and Security-Minded communications (SMC). We built Zarn because we saw this gap in operational work, not because we were looking for somewhere to use a technology.

Martyn's Law and the security of information

The Terrorism (Protection of Premises) Act 2025, known as Martyn's Law, received Royal Assent on 3 April 2025. It requires those responsible for certain premises and events to reduce the risk of physical harm from acts of terrorism and, for larger premises and all qualifying events, their vulnerability to them.

For enhanced duty premises and qualifying events, where 800 or more people may be present, staff included, section 6 lists four kinds of public protection measure. The fourth is:

the security of information in relation to the premises or event

The person responsible must assess those measures, keep them under review and document them. Standard tier premises, with 200 to 799 people, have a different set of duties and are not covered by this one.

Parliament has already recognised that public information about premises can help someone preparing an attack. The same Act changes licensing law so that plans on public registers can be limited to exclude information likely to be useful to that person (section 34). What you publish about a venue is information about that venue. Zarn helps you see what your public pages, documents and images give away, and gives you safer wording to replace it. Reports and monitoring give you a dated record of what was found and what changed, which can support your own assessment. It does not replace it.

Zarn is not a compliance product and does not make anyone compliant. The Home Office, the SIA and NaCTSO do not endorse third-party products in respect of compliance, and the Government's stated intent is that duty-holders can comply without buying specialist services. The main duties are not yet in force, and the implementation period is at least 24 months from Royal Assent. Read the Home Office statutory guidance and take independent advice on your own position.

Last reviewed September 2026. Contains public sector information licensed under the Open Government Licence v3.0.

Built for organisations with people and places to protect.

  • Venues and event operators
  • Estates and business districts
  • Corporate security teams
  • Critical infrastructure and CNI-adjacent sites
  • The defence and government supply chain
  • Communications, HR and public affairs teams in sensitive organisations

If you look after many sites, Zarn can sit alongside the security services you already deliver. Talk to us about partner access.

Access is controlled, on purpose.

The same information that helps you find exposure could help someone plan an attack, so we check who we give it to.

Request
Tell us who you are and what you want reviewed.
Verify
We check your work email, your organisation, and that you own or have authority over the domains.
Scope
We agree what to scan and monitor and how often. Pricing depends on how much you want covered, so we agree it at this point.
Onboard
You get an invite, create your account, and we walk through your first review with you.

Request access

Tell us who you are and what you would like reviewed. We verify every request before anyone gets an account.

Use your work email. We check it against the domains you list.

One per line. Only domains your organisation owns or has authority to review.

Helps us verify your request faster.

We check every request before we create an account.

Questions people ask.

Is Zarn a cyber security product?

No. Zarn looks at physical security risk. It reads what you publish and does not test your networks or systems.

Does Zarn make us compliant with Martyn's Law?

No. The Home Office, the SIA and NaCTSO do not endorse third-party products in respect of compliance, and we do not present Zarn as one. Zarn helps you see and reduce what your public information gives away, which is relevant to the security of information duty. Take independent advice on your obligations.

How is it different from a tool that collects online data?

Those tools show you data. Zarn tells you what matters, how it could be used, and what to write instead.

Who can request access?

Organisations with a real protective security need, and only for domains they own or have authority to review.

Does a request guarantee access?

No. We verify every request and check it is a suitable use.

What does it cost?

It depends on how many pages, images, documents and drafts you want reviewed and monitored. We agree it with you when we scope access.