Ads — Unauthorised Advertiser Detection
Ads watches paid search results for a keyword — typically your brand or product name — and flags any advertiser whose destination isn't on your approved-domains list.
Setting it up
Add a keyword (e.g. your brand name, or "<brand> login") and a list of
domains you're comfortable seeing bid on it — your own domains, and any
approved affiliates or resellers. Everything else that shows up as a paid
result gets flagged.
Why this exists as its own product, not part of Domains
Domains & Typosquat Monitoring catches attackers
who register a lookalike domain. But a real, damaging pattern doesn't
require registering anything at all: an attacker builds a phishing page on a
free hosting platform — Google Sites, Notion, GitHub Pages, Vercel, dozens of
others — and simply pays for a Google Ad pointing at it. There's no domain
registration event for Certificate Transparency to catch, because the
underlying domain (sites.google.com, notion.site, ...) has existed for
years and belongs to a legitimate company.
Ads is the one product watching the ad itself, so it's the one place this attack shape gets caught. Any ad landing on a known free-hosting platform is flagged automatically, regardless of your approved-domains list — a brand's real checkout or login flow essentially never lives on a free site-builder subdomain.
AI-confirmed evidence
A flagged ad's destination is crawled and passed through the same Claude-Vision-based content classifier used elsewhere in Kansyn, so a finding comes with an actual read of the page — not just "this domain wasn't on your list." When a free-hosting-platform hit is also AI-confirmed as active phishing or brand impersonation, it's raised to critical severity immediately.
From finding to takedown
A flagged ad can be turned directly into a Takedown —
carrying the full destination URL (including path), since on a shared host
like sites.google.com, the path is what actually identifies the phishing
page, not the domain.