Internet Due Diligence
See what the internet already knows about you.

There is a version of you you have never met.

You didn't write it.

It was assembled.

From accounts you forgot you opened.

From leaks of companies you trusted.

From records filed by law, in your name.

From brokers who sold you, and never asked.

It is scattered across the internet right now.

★★★★☆
“Great biryani, will be back.”
Andheri West, 14 Mar 2016
C
Cricket Sunday guy
+91 XXXXX XXXXX
breach_export_2018.csv
name@example.com|rk_1991|91XXXXXXXXX|a8f3e2c19d
@rk_1991
GitHubReddita gaming forum
from a 2019 delivery record
402, Sunrise Apartments,
Andheri West, Mumbai 400053
Your facefound on 6 websites
domaina-side-project.com
registered2014-06-28
registrarGoDaddy, Tempe AZ
Calls on 56 of the last 60 days
carrier, SIM origin and activity are all public

And it is still being written.

Scroll

Someone with your email and your phone number could assemble all of this in a few minutes.

You should see it first.

Built to check your own presence. No password. Nothing to log into.

Internet Due Diligence is a product concept from TSS Consultancy.

Let's find you.

Use the email address and phone number you actually use online. We'll follow where they lead.

Pre-filled for the demonstration identity — just press Show me.

Presentation only. Nothing is being searched.

sagar@tssconsultancy.com+91 98700 56050

Sagar.

Assembled from one email address and one phone number. Everything that follows is public, or has been made public by someone else.

Scroll
sagar@tssconsultancy.com
+91 98700 56050

We started with two things.

Not a name. Not a password. Not a login. The two identifiers you hand to a delivery driver, a hotel desk and a loyalty form without thinking.

s
sagar bhai+91 98700 56050
5
5th July Sagar Sir+91 98700 56050
A
Aj Sagar Tanna+91 98700 56050
s
sagar khanna tss consultancy+91 98700 56050
T
Trackwizz Sagar Tanna+91 98700 56050
and more — Sagar mumbai · sagar tanna tss · sagar tanna tanna software · sagar

This is how other people have you saved.

Ten ways your number sits in strangers' phones. One records the date someone met you. One calls you brother. You typed none of them. Anyone who queries this number inherits all ten — including who is close enough to you to drop the surname.

Fact. Caller-identification name history for +91 98700 56050. Current: “sagar tanna”.

fintechbiznews.com×12 · 100%indianstartupnews.com×9 · 99.9% entrepreneur.com×7 · 99.8%m.economictimes.com99.5% incubees.com99.7%fintelekt.com×2 · 99.6% viestories.com×2 · 98.3%ciol.com98.2% and 24 more domains

Your face is on 32 websites.

Seventy-three matches to one photograph, eighteen above ninety per cent, across thirty-two domains. Enough frames, angles and lighting for a face model — which is the raw material a voice-and-video impersonation now needs.

Probabilistic. Face matching returns leads, not proof. The eighteen high-confidence hits are strong; the tail should be verified by hand.

TSS Consultancy Pvt Ltd
Founder & CEO, TrackWizz — Apr 2008 to present · 18 yrs 3 mths
Estimated salary ₹30La public source's guess
Stanford GSB — Seed Transformation Program, Jan 2019–Dec 2021
Atharva College of Engineering — B. Information Technology
St Sebastian Goan High School

Your school, your college, and an income figure you never disclosed.

School, college, executive programme, tenure to the month. And an income estimate published beside your name as though you had confirmed it. Whether it is accurate matters less than who reads it and what they decide you are worth.

Self-reported roles and schools from public profiles. The salary is an estimate — which is the point. It's out there whether it's right or not.

Age: 23*one source's estimate
sagartanna1983a username you chose in 2018

The internet has two answers for your age. One is a security question.

One source estimates twenty-three. A username you chose in 2018 suggests 1983. Date of birth is a standard identity check on a bank helpline — and you published a candidate for it yourself, in a username, eight years ago.

Inference on both sides — which is why the evidence is shown, not just the answer.

★★★★★
“Excellent Thali”
Panchavati Gaurav, NM Joshi Marg, Lower Parel — 23 Dec 2016, 6:21 PM
★★★★★
“Quality of Food is exceptional , very upcoming”
Invento, Senapati Bapat Marg, Lower Parel — 1 Oct 2018, 2:04 AM

Two reviews put you on a street corner.

Two hundred metres apart in Lower Parel, two years apart, one posted at 2:04 in the morning. Cross them with the office address from the registry filing and the overlap is not a neighbourhood. It is a building.

Fact: the reviews, posted by a Google profile tied to this identity. Inference: the neighbourhood they point to.

6 yrs+activeJiocarrierGujaratSIM issued0times recycledNot spamscore 0
a call made or received on 56 of the last 60 days · outgoing volume “high” over 30 days

Your number answers questions you were never asked.

Six years on the same number. Never recycled. A call on fifty-six of the last sixty days. To a fraud team deciding whether a caller is really you, those facts read as proof of identity — which is precisely why they are worth stealing.

Gujarat is where the SIM was issued — not where you live. Everything else says Mumbai. One source even tags the number “likely a business”. The contradictions are flagged, not resolved for you.

trackwizz.comMay 2014
trackwizz.netMay 2014
onlinepex.comJun 2014
altreas.comAug 2015
altreas.netAug 2015
helpwithclothes.comMay 2016
smileandgive.comMay 2016
vijals.comOct 2016

Eight domains. One of them is a person's name.

Between 2014 and 2016 this email registered eight domains through the same registrar. Seven are companies and causes. The eighth is a first name — and it reappears three sections from here, in a government filing, as a person living at your address.

corporate registry record
710, 7th Floor, Trade World ‘C’ Wing
Mumbai 400013, Maharashtra
Sagar Tanna Chandrakantyou
Vijal Sagar Tannavijals.com
Chandrakant Tanna Laljibhaisame address
Sameer Tanna Chandrakantsame address
Tulsi Sameer Tannasame address

One email. One office. Five people.

Your email is filed in a corporate registry against five individuals at one address. Four of them are not you. Two share your patronymic. One matches a domain this same email registered in 2016.

Fact: five records, one shared address, one matching domain. Inference: that these are family. We show you the reasoning. Someone building a pretext would simply assume it and be right often enough.

All of it, from two identifiers.

Everything so far, as one picture. Every line is a reason a fragment was attributed to you — and a route someone else could walk in the opposite direction.

Goodreads0 books, 0 reviews · still public
MyFitnessPalsilent since 16 Jul 2018
Adobeactive · Google, password, OTP
Microsoft Teamstwo accounts: work and personal
Pinterest · Gaana · Envatoemail registered
Apple · SurveyMonkey · Placeitemail registered
The Economic Timesemail registered

Seventeen doors, and you stopped watching most of them.

A Goodreads profile with nothing on it, still carrying your name. A fitness account silent since 2018 and still open. Every dormant account is a live password-reset route into this email, and nobody is watching any of them.

An empty account is not harmless. It confirms the identifier is live, and it is one more door left unlocked. Every one of these is listed in full below.

May 2017Zomatoemail
Oct 2017MyHeritageemail, password
Jul 2018Zoomcaremail, phone, handle, password
Dec 2018IIMJobsemail, name, phone
Jul 2019MGM Resortsemail, name, address
Aug 2020Paytmemail, name, phone
Aug 2021Public Business Dataemail
Sep 2021Epikemail, personal data
Dec 2023Hathwayemail
Feb 2024DemandSciencename, phone, address, employer, LinkedIn
Apr 2025Credential-stuffing listsemail
what one leaked row looks like
sagar@tssconsultancy.com|sagar|9870056050|DemoPass!2018synthetic — not a real password

Eleven times, your details left the building.

Three carried password data. Not plaintext — but in the same row as your email, your phone and a reusable handle, which is all a credential-stuffing run needs to try you against every service you still use.

The password above is a placeholder. The real records held a bcrypt and a SHA-1 hash. A real product would never display either. What matters is the shape of the row.

May 2017first leak — Zomato
Oct 2017a password hash leaves MyHeritage
Jun 2018you create a fitness account
Jul 2018Zoomcar leaks your phone with it
Jul 2018the fitness account goes quiet — and stays
2019–21your address joins the trail
2023–24a full profile is assembled for marketers
Apr 2025your email enters credential-stuffing lists
todayactivity on your Google account

Nine years, and the last entry is today.

The first leak was May 2017. The most recent activity is dated today. Nothing on this page has expired, and nothing on it is going to.

None of this required breaking anything. Which is why it is fixable.

No password was guessed. No system was breached. No law was broken. Two identifiers, public sources, and a few minutes. The only unusual thing that happened here is that you were shown the result.

You cannot unpublish a registry filing or recall a breach. You can break the chain — and the chain only has four links.

Move the second factor off the phone number
An authenticator app or hardware key instead of SMS. This one change makes a successful SIM swap worth nothing, which breaks step three of the chain above.
20 minutesstops the takeover path
Set a port-out PIN with the carrier
Jio will lock the number against transfer without a separate code — one the registry cannot supply and a helpline agent cannot be talked past.
one phone callcloses the verification gap
Retire the three leaked passwords and close the dormant accounts
MyHeritage, Zoomcar and the credential-stuffing lists. Then close Goodreads and MyFitnessPal, which do nothing for you and remain live reset routes.
one eveningremoves 3 of 11 exposures
Split the anchor
One address currently carries your company, your domains, your family filings and your personal logins. A separate identifier for banking and recovery means no single lookup returns all of it again.
a weekendprevents the next report

Nothing here needs a security team or a budget. The reason the chain works is not that it is sophisticated — it is that nobody had looked.

Now go through it yourself.

Every platform, domain and breach we connected to your two identifiers. Tap any one to see exactly what it holds — and to open it.

17platforms discovered
12name variations
32sites with your face
8domains registered
11breach exposures
9.1years of presence

KYC asks whether you can prove who you are. Internet Due Diligence asks the question nobody else is asking — what does the internet already know?

Demonstration for an internal product concept, prepared with the consent of the subject. Content is drawn from a TrackWizz Next report dated 17 Jun 2026 and from public and breach-derived sources. Relationship labels, age and location readings are inferences and are marked as such; face matches are probabilistic; the password shown is synthetic. No live search or third-party request is made by this page.