FAQ
FAQ
The questions teams ask most before getting started. Need something not covered here? Talk to us.
What does Clonedown detect?
Phishing pages, lookalike and typosquatted domains, fake mobile apps, paid-ad impersonation and other brand and trademark abuse across the open web, app stores and ad networks.
How fast are takedowns?
Most confirmed threats are actioned within hours. Median response time is under 15 minutes from detection to the first abuse report, and confirmed phishing URLs can be deindexed from search before the host even responds.
Is the deindexing success rate really 100%?
For verified phishing URLs submitted to Google’s Trusted Copyright Removal Program, yes — confirmed submissions are removed from search results. Host-level takedown timing still depends on the provider.
Do I have to manage takedowns myself?
No. Detection, evidence and reporting are automated on every plan. The Managed plan adds our 24/7 disruption team and manual toolset, so the whole process runs without your involvement.
How is Clonedown priced?
Pay as you go is $30 per takedown. Monthly is $1,500/mo per brand, Managed is $4,000/mo per brand with unlimited takedowns and support, and Enterprise covers multiple brands — see Pricing for the detail.
Can it connect to our existing security tools?
Yes. A documented API streams detections into your SIEM or SOAR and lets you trigger actions from your own tooling. Clonedown also works with Cloudflare, Google Safe Browsing, AbuseIPDB, Spamhaus, Netcraft and more.
How do you handle cloaking?
Attackers often cloak phishing content to hide it from scanners. Clonedown uses automated and manual techniques to defeat cloaking so hidden threats are still detected and documented.
How do you actually find threats?
We scan widely: DNS and certificate (SSL/CT) data, search engines, reverse image search, recursive crawling of suspicious pages, our own historical threat database, parasite-SEO abuse on high-authority sites, host and subdomain enumeration, and continuous discovery of newly registered lookalike domains.
Do you cover chat and messaging platforms?
Yes. Beyond websites, apps and ads, we detect and act against impersonation and scams on chat and messaging providers (such as Telegram, WhatsApp and Discord), where a growing share of fraud now originates.
Is there a real team, or is it all automated?
Both. Automation handles detection, evidence and the bulk of takedowns. Behind it, a professional disruption team works 24/7 on escalations, uncooperative providers and the cases automation cannot close on its own.
Which countries and regions do you cover?
All of them. We operate across every geography with no regional restrictions, and the platform and reports are available in multiple languages.
What reporting do I get?
Advanced reports show threat trends over time, a breakdown of active and resolved threats, and the top abusive hosting providers, registrars and networks targeting your brand — all filterable and exportable.
Can I make my own pages harder to clone?
Yes — the Clonedown SDK is an optional add-on you embed on your site. It hardens your pages against copying and shows you exactly which visitors accessed them. See the SDK page for detail.