brandguard 🛡

Who is impersonating your brand in the package ecosystem? A live typosquat & impersonation monitor for AI agents & brand owners.
MCP serverx402 pay-per-callnpm + PyPI + GitHubUSDC · Baseno API key

Give it your brand name and get back the npm packages, PyPI projects and GitHub repos that typosquat or impersonate you — each risk-scored — plus a ready-to-review takedown / trademark notice draft. The notice is yours to file: brandguard reports, it does not act as your lawyer.

What it does

🔍 Surfacebuilds the impersonation surface of your name: omissions, doubling, homoglyphs (o→0, l→1), separators, deceptive -js / -sdk / -official affixes
📂 Sourceschecks the public npm registry, PyPI and GitHub for listings using those names
⚖ Scoringflags hits not owned by your declared official accounts; LIKELY_ABUSE / SUSPECT / LIKELY_OK
📝 Draftgenerates a trademark/impersonation notice draft for you to review and file

Free API

GET /scan?brand=acme&official=acme-inc
# top 5 findings, risk-scored

Or connect over MCP at POST /mcp. Tools: scan_brand, draft_takedown.

Pay-per-call (x402)

The /pro/scan route runs the full multi-source scan and returns takedown drafts. Your agent pays $0.15 USDC per call automatically over x402 — no sign-up, no API key. Settles on Base to the operator wallet.

GET /pro/scan?brand=acme&official=acme-inc   # 402 -> pay -> full report + drafts