July 21, 2026 · Protective Intelligence · 3 min read
By TPS Advisory Team
WATCHFLOOR: Continuous Protective Intelligence for the People You Protect
A principal's risk changes every week. A new breach lands. A data broker re-lists a home address that took months to remove. A person who made threats last year resurfaces under a new account. Unrest flares near a site the principal visits on Thursday. Each of these is knowable in advance. The problem is volume: for every signal that matters, there are thousands that do not, and a person reading feeds cannot keep up across an entire book of principals.
WATCHFLOOR is our answer. It is a protective-intelligence system that watches continuously, filters the noise, and gives your team one clear read per principal.
How It Works
The system ingests signals across social platforms, news, public-safety events, and breach and broker exposure, for each principal and the household around them. Every flagged item then passes a two-tier AI triage: a first model filters the raw volume, and a second judges what is left, with its reasoning attached. In a recent demo period, six keyword flags produced five confirmed threats and one suppression. Your analysts read five items, not six thousand.
What survives rolls into a single posture tier per principal, weighted toward recent activity, with a recommended action attached. The output is a read your team acts on, not another feed to monitor.
What It Watches
Six lanes: direct threats and hostile chatter, fixated and repeat actors, area threats near home and office, destination risk for travel, household and family exposure, and a weekly posture read that ties it together.
Built for Security Firms
WATCHFLOOR is multi-tenant and white-label. Your firm runs its own book of principals under its own name, cleanly separated from every other tenant. Operators work the console, firm administrators manage the book, and principals see a clean portal or a single secure link.
See Where a Principal Stands Today
The product page includes a free exposure snapshot. Enter a name, email, and city, and it checks live breach exposure and shows the first thing to close. No account is required, and we keep only the email address.
See WATCHFLOOR for yourself
The product page walks through the console, the triage, and the posture read, and the free snapshot shows a principal's current exposure in seconds.
July 21, 2026 · Communications Security & TSCM · 5 min read
By TPS Advisory Team
Message Encryption Is Not Communications Security
On June 26, the FBI published a public service announcement with a plain warning: Russian intelligence services are stealing Signal users' message histories, and they are doing it without touching the target's phone.
The mechanism is worth understanding because nothing about it is technical. The attacker sends a message posing as Signal support and claims a mandatory verification step is required. The target is walked through enabling Signal's backup feature and then asked to paste in the backup recovery key. That key lets the attacker restore the target's message history on a device the attacker controls. The FBI attributes the campaign to Russian intelligence services, tracked as UNC5792 and UNC4221, and names the targets: current and former government officials, military personnel, political figures, and journalists. The same day, Ukraine's Security Service described a coordinated campaign of support-impersonation messages aimed at officials and citizens across Ukraine, Europe, and the United States.
This was not the first warning. In February 2025, Google's threat intelligence team documented the same groups abusing Signal's linked-devices feature. A malicious QR code, disguised as a group invite, silently added an attacker-controlled device to the target's account. From that point, every message the target sent or received was delivered to the attacker in real time.
Here is the detail that matters for anyone who moved sensitive conversations onto a secure messaging app: in every one of these cases, Signal's encryption worked exactly as designed. Nobody broke it. Nobody needed to.
What the encryption actually covers
End-to-end encryption protects the message in transit. Between the moment a message leaves one device and the moment it arrives on another, nobody in the middle can read it. That guarantee is real, it is strong, and it is the reason Signal and WhatsApp were the right choice for sensitive communications in the first place.
But a conversation does not live only in transit. It lives in the message history, which a backup recovery key can restore anywhere. It lives on every device linked to the account, including one added by a QR code scanned in the wrong context. It lives behind the account itself, which can be taken through social engineering without any software vulnerability. And it happens in a physical room, which no app has ever claimed to secure.
Each of those is an attack path that leaves the encryption untouched. The campaigns above used the first two and the third. The fourth is the oldest one in the book, and it did not go away because the messages got encrypted.
Where the false assurance comes from
The gap is not carelessness. It is a category error that almost every organization makes: treating the secure app as the communications security program, rather than as one control inside it.
The pattern is familiar. A deal window opens, or a board matter turns sensitive, and the instruction goes out: take it to Signal. The instruction is sound. What rarely follows is the rest: who verifies the recovery settings on each participant's account, who audits the linked-devices list, what the procedure is when "support" reaches out, and what room the calls actually happen in. The app was assessed once, informally, by reputation. The posture around it was never assessed at all.
An attacker reads that gap the way the FBI advisory describes: do not attack the encryption, attack the person and the account layer around it. The morning-hours timing noted in the Ukrainian advisory is the tell. These campaigns are engineered around human attention, not software flaws.
What a communications security posture includes
The fix is not exotic and most of it costs attention rather than money.
Account hardening on every participating device. Registration lock enabled, backup settings deliberately chosen, an app-level screen lock in place, and the recovery key stored where no message thread can reach it.
A linked-devices audit on a schedule, not once. The list is short and takes a minute to read. An unfamiliar entry is a finding, not a curiosity.
A standing rule for support contact. No legitimate platform support asks for a recovery key, a PIN, or a verification code. Any message that does is treated as hostile and reported, not answered.
Device discipline for the meeting window itself. What is on the phone, what the phone can sense, and whether it belongs in the room at all during the conversations that matter most.
The room, assessed. For recurring sensitive discussions, a technical surveillance countermeasures sweep answers the question the app cannot: is this space clean enough for this conversation.
None of this argues against Signal. Signal remains the right transport for sensitive traffic, and the encryption is not the weak point. That is precisely the reason the attacks have moved to the layers around it.
When to do this work
The honest timing is the same as for most protective work: before the sensitive period, not during it. A deal window, contested litigation, a leadership transition, or a rising public profile all raise the value of the conversations and the attention paid to them. Verifying the account layer takes days. Building the habit of a linked-device audit takes one calendar entry. Sweeping the room where the quarterly discussions happen takes one visit. All of it is cheaper and quieter than working out, after the fact, how a confidential position reached the other side of the table.
Triangle Point Solutions runs communications security assessments for executives and the teams around them: the account and device layer, the meeting-window discipline, and the physical sweep of the rooms where sensitive conversations actually happen. Tell us your stack, and we can help audit it for deficiencies and improvements. If your organization moved its most sensitive traffic to a secure app and stopped there, a scoped review of what sits around that app is the logical next step.
Running sensitive conversations through a secure app?
We assess the layers around it: the accounts, the devices, and the rooms where the conversations actually happen. A scoped review, no obligation, and a clear read on where your posture stands.
April 8, 2026 · TSCM & Executive Privacy · 4 min read
By TPS Advisory Team
5 Moments When a TSCM Sweep or Executive Privacy Review Is Justified
Most organizations do not think seriously about surveillance or privacy exposure until something feels unmistakably wrong. A leak appears in the wrong hands. A sensitive conversation seems less private than it should have been. A key executive starts noticing anomalies across travel, meetings, or devices. By then, the discussion is already reactive.
That is usually the wrong time to begin. In most environments, the better question is not whether a problem has already been proven, but whether the operating conditions justify a prudent review before exposure becomes visible.
Technical surveillance countermeasures and executive privacy reviews are not about paranoia. They are disciplined responses to elevated risk conditions, especially in environments where confidential information, sensitive relationships, or leadership mobility create opportunities for compromise.
Here are five moments when that kind of review is often justified.
1. After an office move, renovation, or occupancy change
Any physical change to a workspace creates new uncertainty. Contractors, installers, furniture crews, IT vendors, cabling changes, conference room upgrades, and access overlap all widen the number of hands that have touched the environment.
Most organizations think about operational disruption during a move or renovation. Fewer think carefully about what happens to privacy assumptions when walls open up, devices are moved, systems are reinstalled, and third parties cycle through the space.
This is one of the clearest moments to reassess. Even when no single event appears suspicious, the combination of physical access, configuration drift, and incomplete oversight creates a legitimate reason to validate the environment.
2. During sensitive litigation, transactions, or internal investigations
The risk profile changes when the stakes change.
Litigation, mergers and acquisitions, internal investigations, regulatory matters, executive disputes, and other high-consequence events create incentives that do not exist during normal operations. In these moments, firms often lean heavily on cybersecurity controls, legal privilege, and process discipline. Those are important, but they do not eliminate the possibility of exposure through physical, acoustic, or adjacent vectors.
When the value of information rises, so does the value of obtaining it quietly.
A prudent review at this stage is less about assuming foul play and more about acknowledging that ordinary controls may not be sufficient for extraordinary circumstances.
3. Around executive transitions, conflict, or terminations
Leadership change tends to create both friction and noise. Access shifts. Responsibilities move. Trust narrows. Conversations that were once routine become more sensitive, and sensitive conversations often happen quickly, across mixed environments, with less structure than usual.
Executive departures, partner disputes, terminations, board conflict, and succession events are all moments when privacy assumptions deserve a second look. These are also the periods when organizations are most likely to underestimate quiet exposure because they are focused on the visible operational problem in front of them.
If the context includes strained relationships, contested decisions, or unusual information sensitivity, a scoped review is often justified.
4. When work starts moving fluidly across office, home, travel, and vehicle environments
For many executives and advisors, sensitive work no longer lives in one place. Conversations move from office to residence, from airport to hotel, from vehicle to temporary meeting room, from personal device to enterprise platform and back again.
That mobility creates convenience, but it also expands the privacy surface dramatically. An executive privacy review is often warranted when the environment itself has become fragmented. Even if the main office is well understood, the real risk may be emerging from the way high-value conversations and materials travel across inconsistent settings, third-party spaces, unmanaged accessories, or mixed personal and professional workflows.
In these cases, the issue is not only whether a workspace is secure. It is whether the executive operating pattern is creating avoidable exposure.
5. When there are small anomalies that remain unexplained
Not every anomaly means compromise. Battery drain alone is not evidence. Audio glitches alone are not evidence. Interference, odd device behavior, or one-off coincidences do not automatically justify dramatic conclusions.
But clustered anomalies deserve respect.
When unexplained leaks, unusual awareness by outsiders, recurring device irregularities, or strange environmental signals begin to stack up, the right response is neither denial nor theatrics. It is a calm, evidence-driven assessment.
Organizations get into trouble when they dismiss soft indicators because no single one feels conclusive. In practice, the pattern matters more than the isolated event.
What a justified review should actually look like
A legitimate TSCM sweep or executive privacy review should be scoped, discreet, and grounded in context. It should not resemble gadget-driven theater or generic “spy detector” theatrics. It should be informed by the actual environment, recent changes, threat posture, and operational realities of the client.
The goal is not to create fear. The goal is to reduce uncertainty in moments when the cost of being wrong is high.
That may mean validating a newly changed office, assessing executive exposure across travel and residence patterns, or examining an environment after sensitive operational changes. The right review is not triggered by panic. It is triggered by context.
Wondering whether your environment warrants a review?
We work with executives, legal teams, and security leadership to scope discreet, context-driven assessments. No obligation, no theater — just a clear conversation about whether a review makes sense for your situation.
April 22, 2026 · Executive Privacy & Physical Security · 5 min read
By TPS Advisory Team
Why CEOs and HNWIs Need Physical Security Reviews Before a Triggering Event
Sam Altman’s San Francisco home was attacked twice in forty-eight hours this month. The first attempt, on April 10, involved a Molotov cocktail and led to attempted-murder and arson charges. The second, on April 12, came from a passing vehicle. Different suspects, different methods, same address.
Most coverage is framing this as a story about anti-AI sentiment or political risk. That framing is not wrong, but it is incomplete. The more useful story — for anyone responsible for a principal’s safety — is quieter. The attacks were preceded by months of escalating public visibility, a consistent residence, a recognizable routine, and a broadly known profile. The event drew attention. The exposure came first.
This pattern is not new, and it is not limited to technology CEOs. It is the same pattern we see before most serious physical security incidents involving executives, founders, and high-net-worth individuals. The principal’s profile changes faster than the protective posture around them. By the time that gap is obvious, the decisions are reactive, the timeline is short, and the options are narrower than they should be.
Exposure is usually built slowly
Executive security failures rarely begin as emergencies. They begin as drift.
Visibility rises. The principal takes a board seat, closes a funding round, speaks on a panel, grants a feature interview, or becomes adjacent to a controversy. None of these are problems in themselves. Individually, they are signs of success. Cumulatively, they shift the principal from a private person with a public role into a recognizable public figure.
Posture, meanwhile, does not move. The residence is the same. The commute is the same. The vendors are the same. The assistant still opens calendar invites from unfamiliar senders. Household staff turn over quietly. Contractor access from a renovation two years ago was never fully revoked. A domain registration from 2018 still lists a home address. A property LLC was set up correctly, but the pool service company’s invoice still goes to the principal by name.
None of these are dramatic. Each one, on its own, is ordinary. Together, they form a map.
What actually leaks
The most common assumption we encounter is that entity ownership solves exposure. It does not. It solves one layer. Real exposure leaks through the layers underneath it.
Service accounts. Utilities, deliveries, cleaners, landscapers, pool services, HOA communications, pet sitters. Most of these bill to a name, keep a name on file, or sit in inboxes that are searchable.
Vendors and contractors. Past renovations, installers, alarm technicians, IT consultants, event photographers — all of whom retain some combination of address, access schedule, and photograph.
Public and semi-public records. Permits, voter rolls, campaign contributions, court records, school board sign-ins, boat registrations, real-estate tax appeals. Not uniformly public, but broadly assemblable.
Routine visibility. When the principal arrives at the office, where they eat lunch, which gym they use, which schools the children attend, which flight routes they prefer, which charity events they reliably attend.
Staff and household. Social media posts by nannies, drivers, or housekeepers. Geotags on photos. Mentions in casual interviews. Shift patterns visible to anyone watching.
Online-to-physical crossover. A podcast interview that names a neighborhood. A profile piece that describes a morning run. A real-estate feature photographed from the street. A donor bio on a charity website that lists a town.
Any one of these is low-signal. Together, for a motivated observer, they are enough to reconstruct a principal’s weekly pattern with uncomfortable accuracy.
Why the review comes before the event
A physical security review, done well, is not a hardware audit. It is an assessment of the gap between the principal’s current profile and the current posture around them. It looks at residence and perimeter, office access, travel predictability, event exposure, household and vendor interfaces, and the privacy surface that translates most directly into physical risk.
The point is not to make the principal invisible. That is neither possible nor desirable for someone who needs to lead a company, raise capital, or represent a family office in public. The point is to remove the unnecessary predictability. To close the seams that have opened quietly. To decide, in calm conditions, which exposures are worth accepting and which ones should be reduced.
This work is usually less disruptive than it sounds. Most findings are small adjustments to routines, vendor arrangements, records, and access. A handful are structural. None are permanent fortresses.
When to do this
The clearest moment to conduct a physical security review is before anything visible has happened. Specifically: when the principal’s profile has changed meaningfully in the last twelve months, when the household has added staff or complexity, when public exposure has increased, when litigation or controversy is present or anticipated, or when a comprehensive review has simply never been done. Any of these individually is a reasonable trigger. Several together is a clear one.
The poor time to do this work is after an incident. Not because it cannot be done — it can — but because decisions made under pressure are rarely the decisions a principal would have made with six months of lead time.
A closing note
The two attacks on Altman’s home will not be the last of their kind this year. The conditions that produce them — rising public visibility, political friction, a consistent residence, a recognizable pattern — are widely distributed. Most of the people those conditions apply to do not think of themselves as targets. They do not need to. They only need to recognize that their profile has changed and their posture has not, and to close that gap before someone else notices it first.
Has the profile of someone you protect changed in the last year?
TrianglePoint works with principals, family offices, and corporate security teams to assess where visibility, routine, access, and physical exposure have drifted out of alignment. Discreet, scoped, and designed to be completed before a visible incident forces the conversation.