A principal is usually assessed alone. Anyone researching them assesses the whole household, because that is where the record set is thinnest and the connections are published for free.
Why one person cannot be protected in isolation
Exposure records are relational. People-search platforms do not publish a person, they publish a person and their associates. The relatives section is a standing instruction on how to rebuild a link that has just been removed. A shared address reconnects a household. So does a landline, a jointly held company, or a family member who has never thought about any of this.
The result is that reducing one person's footprint while leaving the people around them untouched does not close the path. It moves it one step sideways. That is the structural reason this engagement is scoped as a household instead of a principal with optional extras.
The staff are part of the surface
An assistant publishes a calendar. An estate manager lists an employer. A driver's own footprint carries a residential area. None of it looks sensitive in isolation. All of it points back to the same place. Household staff are in scope for the same reason family members are: their exposure resolves to the principal's routine.
Where the exposure comes from
- People-search platforms publish names, addresses, ages and relatives, assembled from public and commercial sources and refreshed on their own cycle.
- Data brokers hold records that are not publicly viewable but are commercially available, which is a different problem with a different remedy.
- Public registers (company filings, property records, electoral rolls) vary by country in how much they expose and how much can be suppressed.
- Breach corpora attach old passwords, phone numbers and addresses to names. They do not expire.
- The household's own publishing is usually the easiest thing to change and the last thing anyone looks at.
For the mechanics behind this, why social engineers target the executive's family sets out how the side door gets used.
One year, scoped as a household. The engagement asks what an adversary could assemble about this family, which person they would come through, and what the office can actually cut.
Where this fits in family office security
Most family office security programmes are built around systems and around people who are physically present. An IT provider hardens the office network and the devices. A security adviser handles residence, travel and, where it applies, close protection. Both are necessary. Neither reaches the open record. The reason is structural.
Mandate. An IT provider or an internal security function is engaged for the office's estate: its systems, its accounts, its staff in their working capacity. A principal's private life is not part of that estate. The relatives named on a people-search profile, the spouse's own footprint, the residence on a property register — none of it is an office asset. Nothing in the engagement authorises anyone to go looking at it.
Lawful basis. This boundary catches people out. It applies most sharply to staff. An employer cannot rely on an employee's agreement as a sound basis for compiling a file on their private life, because an employee is not in a position to refuse freely. That is precisely why this engagement takes authorisation from each person directly, never from the office that pays for it. The consent model is not our preference. It is the only footing the work can sit on.
Method. The work is investigative rather than technical. It runs against third-party platforms and registers, outside the family office entirely. Each person and each source is worked manually. It produces an evidenced map of who holds what, and who could use it.
So this engagement is additive. It does not replace a family office security review, an IT provider or a protective adviser. It covers the layer they structurally cannot, then hands findings back in a form the rest of the programme can act on. The same argument, drawn for a corporate security team instead of a family office, is set out in why threat hunting stops at the company edge.
Why this is not what your security suite already does
Most family offices already run a security suite, and most of them already have credential and dark-web monitoring inside it. Keep it. We are not selling that again. But there are two things it structurally cannot do.
Monitoring is seeded. You hand it a list of identifiers to watch: the names, the addresses, the email accounts the household knows about. That list is the household’s own memory of its exposure, and what is missing from it is the whole problem. The personal address used on a company filing in 2011. The maiden name still sitting on an old electoral roll. The alias on a forum nobody has opened in a decade. The dormant email that no longer receives anything but still works as an account-recovery route. None of that is on the list, so none of it is watched.
An adversary has no list. They begin with a name and follow whatever surfaces, which is rarely what the family would have nominated as important. That asymmetry is the point: the household monitors what it remembers, and the person researching it works from what is findable. Those two sets are never the same, and the gap between them is where an approach gets built.
The second gap is combination. A suite reports items. An address here, a breach hit there, each judged on its own and each looking harmless. It does not report that the address, the named relative, the company filing and the school in the background of a photograph describe a routine when read together, or that four unremarkable facts are precisely the four a caller needs to sound like they are already inside the family. Reading fragments as a set is analysis. How separate fragments resolve into one picture covers the mechanism.
So the credential work here runs at full depth. It sits underneath the analysis instead of standing in for it. One authoritative investigation, unseeded, used to establish which approaches this family is actually open to. The ongoing watch stays with the office.
What the engagement covers
One map of who is who across the household: which identifiers, accounts, addresses and entities belong to whom, and how each resolves back to the office.
Every person around the principal — family, household staff, advisors — ranked by how usable they are as a path to the principal or to the money.
What a caller could credibly claim to know. The details that make an approach to a bank, an adviser or the office itself sound like it comes from inside.
When the household is most approachable: travel, transactions, succession, a new appointment, a public moment. The periods where an unusual request reads as normal.
A full investigation per consenting person: which identifiers sit in breach corpora and traded sets, which accounts they still open, which recovery paths they defeat.
Which people-search platforms and broker categories carry a record for each person, what removing each would take, and in what order.
The surface re-checked on a defined cadence, so new listings, fresh breach hits and rebuilt links are caught while the engagement is live.
A record the family office can hold: what was found, what it enables, what can be reduced, and what remains open by design.
What we produce
| The Family Office Identity Framework | The durable deliverable: one maintained map of the household as a single identity, with every person, identifier and entity placed and linked. |
| Routes and Pretext Assessment | Which person around the principal is the usable approach, what a caller could credibly claim to know, and which windows in the year make an unusual request read as routine. |
| Per-Person Findings | For each consenting person: public footprint, credential and dark-web exposure, and what each of them enables. |
| Source Inventory & Removal Plan | Every source found to hold a household member, with the removal route for each, sequenced and costed so the work can be commissioned. |
| What Cannot Be Removed | The exposure that will persist whatever is commissioned, and why, stated plainly with nothing left to implication. |
| Year-End Position | The surface as it stands at the close of the term, with what has rebuilt and what would need continuing attention. |
Who has to agree per person · first-party
Every adult in scope authorises the work on their own behalf. A principal cannot commission an investigation into an adult relative. We will not run one on their instruction.
- Where a family member declines, we scope around them and state what that leaves open rather than working around the consent.
- Household staff are included on the same basis, as individuals who have agreed, not as an extension of an employment relationship.
- Scope involving anyone under 18 is agreed with the parent or guardian at intake.
This is slower than the alternative. It is also the only defensible version of this work. That is why the engagement is scoped at intake rather than sold as a fixed bundle.
What this engagement is not stated up front
- Not a security audit. No penetration testing, device forensics or network assessment.
- Not account access. We do not take over, operate or monitor anyone's accounts.
- Not removal execution. The Pack scopes and sequences the removal work; filing it is a separate engagement, priced per person.
- Not a removal guarantee. Property registers, court filings and press coverage generally cannot be removed on request.
- Not a monitoring service. Re-verification runs on a defined cadence; the continuous, automated watch stays with the office’s own security suite.
- Not physical security. Where a finding indicates a credible physical threat, that is a matter for law enforcement and specialist partners. We say so.
The household ends the year with a fully documented surface, a costed plan for reducing it, and a clear statement of what cannot be reduced at all.
The household scoped once
The principal, the family and the staff read together, so removal is never commissioned for one person while the record set of another rebuilds it.
Evidence the office can hold
Every source found, what it holds, and what removing it would take. The family office keeps the underlying record, not a summary.
Where we go next
Exposure rebuilds on the brokers' cycle. The Guardian retainer keeps the surface under management, with Guardian Executive scoped for family offices and the advisors around them.
For the operating company
Where the concern extends to a business instead of a household, a Corporate Audit maps the organisational footprint instead.
Data broker removal and other engagements the Pack scopes
The Pack maps the household and prices the work. Each engagement below is commissioned separately, on findings, so a family office pays for removal it has already seen the case for.
| Data broker removal — The Eraser €3,800 per person | The execution layer. People-search opt-outs and data broker erasure requests filed and escalated by hand, per platform, then re-verified at 90 days. This is what the Pack’s removal plan commissions. |
| Presence Reduction Brief €450 | A bespoke cleanup guide and a drafted removal-request pack where the office would rather run the first pass with its own staff. |
| Family Member Exposure Check €750 per person | Further people beyond the four, on the same individual-consent basis and read against the principal’s exposure. This is footprint mapping at Mirror level: it does not include the credential and dark-web investigation the five inside the Pack receive. |
| OPSEC Hardening Session €600 | A working session on the habits that regenerate exposure, which is usually where a household’s footprint comes back from. |
| Crypto & Financial Exposure Scan €1,200 | Where holdings create a targeting profile of their own, separate from the household’s public record. |
| Pre-Transaction Privacy Audit €1,500 | Ahead of a sale, a raise or an appointment that will put the household in front of new readers. |
| Guardian Executive from €9,600/year | After the year, where the household wants the reduced surface kept under management instead of re-audited from scratch. |
Family office privacy and security, in detail
What family office security usually covers, and what it misses
A family office security programme typically covers network and endpoint security, access control, travel and residence security, and vendor due diligence. What it rarely covers is the household's public record: what people-search platforms publish, what brokers hold commercially, and what the family and its staff have made findable themselves. That layer sits outside the office's systems and outside its physical perimeter, which is exactly why it survives every review of both.
Data broker removal for family offices
Removal splits in two, and the Pack scopes both before either is commissioned. People-search platforms are directly observable: we can see a listing, name the platform and say what removing it takes. Data brokers holding records commercially are not visible from outside, so we identify the categories likely to hold a household of this shape and say plainly that we cannot confirm which ones do. The output is a costed, sequenced plan, per person and per source, because a household's records do not share a single opt-out. Execution is then commissioned separately: the Eraser where we file and escalate on someone's behalf, or a drafted request pack where the office would rather run the first pass itself.
Why family offices are researched at all
A family office concentrates wealth, decision authority and personal information in a small, under-resourced team. Anyone building an approach (a fraud attempt, an impersonation, a pretext call to a bank or an adviser) starts by assembling what is already public about the principal and the people around them. Reducing that material is the part of the problem that can actually be reduced. Why family offices are targeted covers the reasoning in full.
How much can realistically be removed
On the people-search layer, a meaningful share. The 2024 Consumer Reports Data Defense study found manual opt-outs removed roughly 70% of listings over four months, ahead of the best-performing automated service at 68%, while a 2025 PoPETs study measured subscription tools clearing 48.2% of identified records. Manual execution is the measured ceiling. It is not a guarantee. It reaches people-search sites rather than the wider commercial broker layer. What the studies actually measured →
Succession, appointments and other open windows
Households are researched most successfully when something is changing: a generational handover, a new adviser, a new principal at the office. The people involved are new to each other, which makes an unusual request harder to read as unusual. Succession as a recurring exposure window sets out the pattern and where it recurs.
Family Office Privacy FAQs
No. A family office security review usually covers systems: networks, devices, access controls and the office's own IT. This engagement covers the layer outside those systems, which is what the household has made public. We do not perform penetration testing, device forensics or network assessment. We do not take over accounts. Where a finding calls for that work, we say so and refer it.
The principal plus up to four family members, together with the household staff whose own exposure points back to the residence or the routine. Each consenting person is investigated in full, covering public footprint and credential exposure both. The results are read together as one targeting surface: who is the usable route to the principal, what a caller could credibly claim to know, and which moments in the year make an unusual request look routine. Every source holding a record is inventoried and the removal work is scoped and sequenced on the findings. The removal itself is commissioned separately, per person. It is scoped as its own one-year engagement from €8,500 and does not require a core service first.
Monitoring watches the identifiers you gave it. That list is the household's own memory of its exposure, and the gaps in it are the point: the address on a 2011 company filing, the maiden name on an old electoral roll, the dormant email that still opens an account. An adversary has no list. They start with a name and use whatever surfaces, which is rarely what the family considers important. The second difference is combination. A suite flags items one at a time. It does not tell you that four harmless facts together let a caller sound like they are already inside the household. Keep the monitoring you have. This is the layer above it.
Yes. Most people do not expect this part. Every adult in scope authorises the work on their own behalf. A principal cannot commission an investigation into an adult relative. We will not run one. Where a person declines, we scope around them and say plainly what that leaves open. Scope involving anyone under 18 is agreed with the parent or guardian at intake.
Because the record set is relational. People-search platforms publish relatives sections that rebuild a link the principal has already removed, a shared address or landline reconnects the household. An assistant or estate manager can be the softest route to the same information. Reducing one person's exposure while leaving the people around them untouched leaves the path open.
The Pack answers that question precisely, source by source, before anyone is asked to pay for removal. On the people-search layer a meaningful share comes down: the 2024 Consumer Reports Data Defense study found manual opt-outs removed roughly 70% of listings over four months, ahead of the best-performing automated service at 68%. Manual execution is the measured ceiling, not a guarantee. Property registers, court filings and press coverage generally cannot be removed on request, and the assessment says so rather than leaving it to be discovered later.
Exposure rebuilds, because brokers re-acquire records from public and commercial sources on their own cycle. Households that want the surface kept under management continue on the Guardian retainer, where Guardian Executive is the tier scoped for family offices and the advisors around them. Continuing is a decision at the end of the engagement, not a condition of starting it.