The Practice

Detect the Threat Before It Acts

Every planned, targeted attack requires surveillance. D3 Secure's Protective Intelligence practice exploits that unavoidable step — detecting and disrupting hostile surveillance before an attack is set in motion, through trained human teams and the AI that extends them. Beyond detection, the practice applies defensive counterintelligence — denying hostile services and competitors the access they need to penetrate the people and organizations we protect.

01
Service

Surveillance Detection Training & Services

D3 Secure trains individuals and teams to recognize and disrupt hostile surveillance across the adversary attack cycle, well before an attack is set in motion. Services scale from foundational awareness training through deployed surveillance detection teams during elevated-risk windows to persistent, retainer-based coverage for enterprise and UHNW clients. Every engagement is grounded in a formal Attack Vulnerability Assessment (AVA) that identifies where a specific person, route, or facility is vulnerable to a planned, targeted attack by a credible threat. A Train-the-Trainer track lets client organizations build and sustain the capability internally.

Our Methodology — Deter · Detect · Disrupt

D3 surveillance detection operations deliver three compounding benefits — deterrence, detection, and disruption — each reinforcing the other to raise an adversary's risk to the point where proceeding is no longer viable, and they move on to a softer, easier to access target.

01

Methodology

Deter

D3 surveillance detection support ranges from overt to discreet to covert to clandestine. The less time and place predictable a principal is, the more surveillance an adversary must conduct — meaning more time exposed on the street, and greater risk of compromise.

If an adversary suspects surveillance detection assets are in play, the risk-versus-benefit calculation shifts heavily against them, and they are likely to select a softer target. Deterrence deepens when unpredictability is introduced in the principal's pattern of life: varying routes, timings, modes of transport, and visible security profile. Each change forces the adversary to conduct additional surveillance — more time on the street, greater exposure. In either case, the protected principal benefits.

02

Methodology

Detect

Surveillance detection teams and technical assets are deployed to specific locations at specific times to identify individuals, vehicles, and objects whose presence and behaviors match the modus operandi of hostile surveillance.

The foundation of our surveillance detection operations is the vulnerability assessment — where we identify areas of mandatory travel, areas of concern, and most importantly, attack sites. From there, we work backwards to identify the hostile surveillance locations adversaries must use to collect intelligence on their target. SD teams occupy their surveillance detection locations before the adversary occupies theirs. The adversary, believing they are invisible, walks directly into coverage.

Hostile surveillance detection does more than identify potential threats — it narrows the universe of likely attack methodologies, since certain types of terrain and environments are more conducive to certain types of attacks. Where an adversary is looking reveals a great deal about when and how they may strike.

03

Methodology

Disrupt

Early detection enables early action — altering the principal's route or schedule, enhancing their security posture, or requesting law enforcement support. Each of these measures disrupts the adversary's attack planning cycle, introduces doubt, and increases risk.

When the risk of proceeding exceeds the potential gain, most adversaries will seek out a more accessible, less protected target. The cumulative effect of sustained surveillance detection operations raises the adversary's cost of attacking to the point where they will redirect their efforts elsewhere. The adversary must decide whether to continue, shift to a different target, or abort. Each disruption extends the adversary's planning timeline and increases the probability they will make a fatal error.

02
Technology — Patent Pending

KORPR

KORPR is an AI-enabled, multi-modal surveillance detection system that detects the pre-attack behavior of hostile surveillance against a specific person or facility. It is built on a privacy-by-design principle — surveillance detection without identity resolution: no stored video, no facial recognition, and no identity tracking, retaining only anonymous visual fingerprints for a threat-justified window before automatic purge. This distinguishes KORPR from mass-surveillance platforms and positions it for security-conscious commercial, government, and defense applications. The system is under active development and patent-pending, with market entry anticipated in 2027.

The Concept

Enhancing Human Judgment

Surveillance detection is, fundamentally, a human intelligence discipline. Trained observers bring contextual judgment, behavioral pattern recognition, and real-time adaptive reasoning that no automated system can replicate. However, humans cannot be everywhere 24/7 — and there is a practical ceiling on how much coverage any organization can sustain financially.

KORPR solves this. Named for the ravens of Norse mythology — Odin's Huginn (Thought) and Muninn (Memory), who always flew together — KORPR combines real-time behavioral analysis with a longitudinal behavioral memory. One without the other is blind. Real-time analysis without a baseline is noise. A baseline without active intelligence is inert.

KORPR combines both — continuously and simultaneously — whether watching over a principal in transit or a fixed location.

Patent Pending — USPTO
Seeing What Others Miss

KORPR monitors for behavioral indicators of pre-attack or hostile surveillance across multiple sensors simultaneously, building an anonymous behavioral picture over time and surfacing patterns that would otherwise require multiple human assets to detect. Alerts are delivered to operators with context — not raw data. The system facilitates decision-making. The decisions remain human.

The Dormant-Record Mechanism

KORPR recognizes when a previously observed presence — a vehicle, an object, or a recurring behavioral pattern — reappears after an interval consistent with initial surveillance, final surveillance, and pre-attack deployment. It does this without identifying anyone: entities are held only as anonymous visual fingerprints for a threat-justified window, then purged. Longitudinal re-detection across long time gaps, without identity resolution, has not previously existed in a deployable system.

Correlation-Based Detection

KORPR does not simply flag anomalous behavior in isolation. It determines whether observed behavior — at a specific location, at a specific time — is consistent with what an adversary engaged in operational surveillance would do. Correlation with the principal's movement and known areas of concern is the primary detection test.

Three-Layer Architecture

A multi-sensor array and edge compute layer tracks presences in real time. Domain-specialized AI subagents — analyzing human behavior, vehicle dynamics, aerial threats, digital signals, and pattern-of-life analysis — feed structured intelligence into a central fusion agent that maintains the anonymous, longitudinal behavioral picture.

Deployment

Two Modes. Identical Hardware.

03
Service

Defensive Counterintelligence

Detection protects against attack; counterintelligence protects against penetration. D3 Secure helps clients deny hostile intelligence services, insiders, and competitors the access they need to collect against the people, information, and decisions that matter most. The same discipline that detects an adversary's surveillance, turned inward, hardens the organization itself — identifying how a hostile actor would penetrate it, and closing those avenues before they are exploited.

The Problem

The Intelligence Gap

Many executive and dignitary protection programs operate on an assumption that is both understandable and dangerous: that if a credible threat develops, local law enforcement or intelligence services will learn about it (in advance) and provide early enough warning to preempt an attack on principal.

This is a dangerously false assumption. These agencies are over-tasked, understaffed, and focused on broader national security priorities. Even if they acquire credible threat information, the process of vetting, analyzing, and disseminating that information takes time — time that may not exist.

01

External Warning May Not Come In Time

Duty to warn is not the same as ability to warn. Law enforcement and intelligence agencies are chronically under-resourced, over-tasked, and have other priorities. You are not their priority.

02

OSINT Is Not Intelligence

Open-source information only becomes intelligence when it is analyzed, corroborated, and placed in context. Sophisticated adversaries leave little or no open-source footprint. The more serious the threat, the less reliable OSINT becomes.

03

Serious Adversaries Evade Traditional Collection

With no communications to intercept, conventional SIGINT and HUMINT collection comes up empty. For these adversaries, detecting their pre-attack surveillance is not one option among many — it may be the only option.

Clients

Who We Serve

D3 Secure serves a select roster of clients for whom security is not a routine line item but a fundamental operational imperative.

Executives & Dignitaries
Senior Executives, Diplomats & Government Personnel

Chief executives, board directors, and senior leadership at high-profile corporations, as well as diplomats, government officials, and their families living or working in complex or elevated-threat environments domestically and abroad.

Private
Ultra-High Net-Worth Individuals

Private individuals and family offices for whom their public profile, wealth, location, or personal circumstances create elevated risk requiring discreet security assistance.

Institutional
Organizations in Elevated-Risk Sectors

Defense contractors, pharmaceutical companies, AI and technology firms, and financial institutions that could become the focus of ideological, grievance-based, competitive, or state-sponsored targeting.

Infrastructure
Critical Infrastructure

Facilities and operations where access control points, force protection measures, security protocols, and response patterns are likely to be the focus of hostile surveillance or pre-attack reconnaissance.

Get Started

Do the work now.

Vulnerability assessments, route mapping, identifying attack sites and hostile surveillance locations — this is not expensive. But it does require time, expertise, and discipline to do it before you need it. Because when you need it, it may be too late to build it. The same holds for people: assess and select the right talent before you need it, not in the middle of a crisis.

Request a Consultation