QHCybersecurity for independent real estate

Know what scammers can exploit before they do.

QuillHatch is the plain-English health check for agents and small brokerages without a dedicated IT team. Find the gaps behind your domain, then get a calm, prioritized plan to close them.

No passwords. No scare tactics. Just the next right step.

Sample field noteQH / 001

Domain review

yourdomain.com
Prioritized

Email protection

DMARC policy needs attention

Review

Certificate

Valid · 74 days remaining

Healthy

Next best step

Publish a stricter DMARC policy

A readable report, not a scan dump.

Live email protection check

Start with the public guardrails.
No password needed
We check SPF, DKIM, DMARC, HTTPS reachability, SSL certificate health, and WordPress exposure on your domain. Your result gets a stable link so you can reload it while you decide what to fix.

Results are a focused public-record, HTTPS, certificate, and platform-fingerprint check, not a complete security audit. DKIM custom selectors need your provider’s documentation.

The useful version of secure

A calm answer to the questions that keep you up at night.

You do not need another dashboard full of red warnings. You need to know what a scammer could use, what deserves attention first, and what can wait.

01

Email identity

Start with the live domain check below. We read SPF, DKIM, and DMARC — the public guardrails that help stop impostors from borrowing your address.

Live now
02

Public-facing site

SSL health, certificate timing, and WordPress software that can quietly become an entry point.

Exposure check
03

Leaked credentials

A careful look at breach data connected to your domain, with practical next steps if something surfaces.

Breach watch
A plain-English field guide

Security basics for a smaller team

You do not need to become a security specialist to make your business harder to disrupt. Start by understanding why small companies get swept into broad attacks, then take a few practical steps that improve your resilience.

01 / The pattern

Why small businesses get targeted

Small businesses are not targeted because they are unimportant. They are often included in broad, automated searches. Automated scanning and AI-assisted impersonation or phishing make it cheap for threat actors to look for many companies at once.

Limited IT capacity and exposed email or website weaknesses can create openings. A smaller team may also have less time to spot unusual requests, rotate access, or recover from a disruption.

02 / The disruption

Ransomware, without the mystery

Ransomware is a type of criminal disruption that can lock access to systems or data and pair that disruption with an extortion demand. Common entry points include phishing, stolen credentials, exposed services, or unpatched software.

The impact is disruption and extortion as well as financial pressure: missed work, unavailable files, pressure on staff, and difficult decisions during an already stressful event. Preparation does not make a business invulnerable, but it can improve resilience and make the next safe decision clearer.

Practical fixes

Eight small habits that add up.

Start with the accounts and systems your team relies on every day. The best plan is the one people can follow when work is busy.

01

Turn on MFA

Use multi-factor authentication on email, finance, admin, and remote-access accounts.

02

Test your backups

Keep tested backups of important data in a separate place, and practice restoring a few files before you need them.

03

Apply updates promptly

Keep operating systems, browsers, websites, plugins, and security tools current.

04

Use least privilege

Give each person only the access they need, and remove access when roles change.

05

Make reporting easy

Tell staff how to report a suspicious message or mistake quickly, without blame.

06

Strengthen email authentication

Set up SPF, DKIM, and DMARC so recipients can better distinguish your mail from impostors.

07

Keep HTTPS and SSL healthy

Renew certificates on time and fix website warnings before visitors are trained to ignore them.

08

Write an incident plan

Keep a short list of who to call, what to isolate, how to communicate, and where recovery steps live.

What QuillHatch does today

A useful starting point, not a promise to prevent ransomware

QuillHatch checks public email and domain protections, public-facing site signals, and leaked-credential exposure connected to a domain. The paid report and monitoring path turn those signals into prioritized, plain-English next steps.

That is different from general preparedness: QuillHatch does not prevent ransomware, replace incident response, or claim to be a complete security audit. Phishing simulations are not available today; they remain separate roadmap work.

Keep learning

These external guides add context to the checklist. They are general preparedness resources, not QuillHatch scan results.

Coming soon

Authorized phishing simulations

Loading roadmap details…

How QuillHatch works

Small inputs. Specific answers. Ongoing awareness.

Built for the moment between “I should probably check that” and calling an expensive consultant.

Conservative recommendations, clearly explained
01

Tell us where to look

Enter your business domain and email provider. No passwords, installs, or technical setup.

02

Get the useful version

Receive a prioritized review in plain English: what matters, why it matters, and the safest fix.

03

Stay ahead of changes

Monthly rechecks watch for new exposure, altered email protection, and certificates nearing expiration.

A small line item for a big peace of mind

Security guidance that fits the way you actually work.

Monthly watch

$29–39 / month

A prioritized first report, monthly rechecks, and an alert when the risk picture changes.

Prefer a one-off look? Reports are $49–99.

Run the check

Start with the question

Could someone fake an email from your business right now?

Give QuillHatch your domain. We will show you what is exposed, what to fix first, and what to keep watching.

Check your domain