Version 1.0 · Last updated: 31 August 2026
Previous versions are archived and available on request at [email protected].
This policy describes how Stealed collects the compromise data that feeds its detection corpus. It is published so that anyone, whether a customer, a partner, a data subject or an authority, can verify the conditions of that collection.
It is dated and versioned. Every previous version is archived and retained. No change is made without updating the version number and the date.
Stealed collects login credentials that have already been compromised and already been distributed by third parties. This data falls into three categories:
A "login" is not necessarily an email address: depending on the service it may be a phone number, an identification number or an internal identifier. It may therefore, in some cases, constitute particularly sensitive data.
Each record carries exposure metadata: the source, the collection date, recurrence and, for infostealer logs, metadata about the compromised machine.
Sources are the circulation spaces where this data is published by third parties. As of this version, their status is as follows.
| Channel | Status | What it is |
|---|---|---|
| Semi-public messaging channels | Active | Channels behind an access barrier, invitation or subscription, where actors publish stolen files in bulk |
| Criminal forums and marketplaces | Being integrated | Spaces where stolen databases are published, exchanged or sold |
| Tor network | Being integrated | ".onion" sites distributing leaks |
| Other already-public sources | Being integrated | Leaks published openly on the web, repositories and accessible compilations |
Each source is assessed against the framework, already-distributed data, no inherently sensitive site, no vulnerability exploited, before being connected.
Any extension to a new category of sources is subject to an update of this policy, published thirty days before it takes effect, and notified to customers and partners, who may terminate without penalty.
Any extension of the collection methodology to a new category of sources or a new access method is subject to prior written, dated and reasoned legal validation. It is implemented only after that validation, a record of which is retained and disclosable to the supervisory authority on reasoned request.
Stealed declares, and undertakes that this declaration remains accurate:
Each source and each collection channel is documented in a record setting out its access method, the date it was opened, the nature of the data circulating there and the basis on which Stealed accesses it. The record is kept up to date and retained for the duration of the source's monitoring, plus five years.
Tools, software and third-party providers involved in the collection chain are subject, before any use, to a written verification covering how they operate, the lawfulness of their use, and the absence of any functionality designed or specially adapted to access an automated data processing system without authorisation. No tool is put into service before that verification is complete.
The verification is renewed at each major version change of the tool, at each change in how it accesses sources, and in any event once a year. Its outcome is recorded in a dated internal register, disclosable to the supervisory authority and to any judicial authority on request.
Files received are placed in temporary storage, then indexed. Only the compromised credential and minimal metadata are indexed and used. Source files are deleted after indexing, unless an identified need for re-analysis exists, in which case their retention is limited, justified and entered in the register.
Indexed data is attached to the perimeters for which a deed of mandate has been executed. No data is disclosed outside that attachment.
Data attached to the perimeter of an organisation that is not a customer is neither used, nor disclosed, nor made visible.
Disclosure follows a push model. No customer, partner or third party accesses the corpus as a whole. There is no open search engine, no public lookup and no ability to search on a third party.
The password is masked by default, in the interface as in the API. Reading it in clear is possible in a single case, subject to three cumulative conditions detailed in the security policy, and every read is logged. Some compromised machine metadata is disclosed as investigation context; the compromised machine frequently being personal equipment, its disclosure is limited.
Building and maintaining the corpus is a processing activity for which Stealed is the controller. Its basis is the legitimate interest of ensuring the security of networks and information systems, within the meaning of Article 6(1)(f) and Recital 49 of Regulation (EU) 2016/679, which expressly covers providers of security technologies and services.
The corresponding legitimate interest assessment is documented, dated and reviewed annually. The data protection impact assessment provided for in Article 35 of the same regulation is kept up to date.
How individuals are informed, retention periods and how to exercise rights are described in the privacy policy.
This policy is binding on Stealed. It forms part of the contractual set and prevails as to the origin of the data and the sources monitored. Failure to comply with it constitutes a contractual breach.
It describes the state of collection as at the date of its version. It anticipates no future practice and cannot be relied on to justify a practice it does not describe.