How it works, from the source to the alert.
What we collect, how we match it against your perimeter, and what you receive at the end.
From raw leak to qualified alert.
Two kinds of leak in, one format out, and an alert only when it concerns you.
Own collection
Telegram, forums, marketplaces, paste sites. No broker, no purchased data.
Normalisation and deduplication
A credential seen fifteen times is one leak, not fifteen alerts.
Correlation with your perimeter
DNS-verified domains, validated keywords. Nothing beyond.
Alert where you work
E-mail, Slack, Teams, signed webhook, SIEM.
- 500M
- credentials per day
- 14B+
- unique credentials indexed
- < 60 min
- from publication to availability
- < 5 min
- to open a workspace
Three correlation angles
Every leak is matched against your proven perimeter from three angles. You receive what concerns you, nothing else.
- Telegram
- forums
- marketplaces
- paste sites
- acme.com
- *.acme.com
- "acme"
Which employee is already compromised?
Credentials whose e-mail address is on your domains, and the sites where they leaked.
- login
- j.doe@acme.com
- url
- https://sharepoint.example.com/login
- source
- infostealer · lumma
Which user of my services signs in with a stolen access?
Credentials whose login URL points at your services: customers, partners, contractors.
- login
- [email protected]
- url
- https://vpn.acme.com/sslvpn
- source
- combolist · ulp
Which contractor, project or brand shows up in a leak?
Your keywords spotted in leak URLs, even when your domain is not there.
- login
- [email protected]
- url
- https://acme.example.com/portal
- source
- infostealer · redline
Whatever the source, the same record.
A credential from a combo list or from an infostealer log arrives in the same format, with its circulation metrics. That is what makes filtering, sorting and prioritising possible.
- login
- [email protected]
- url
- https://vpn.acme.com
- type
- infostealer · lumma
- sources
- 4
- occurrences
- 5
- first_seen
- 2026-03-06
- last_seen
- 2026-04-14
- validity
- probably valid
- Distinct sources
- How many different sources it was found in.
- Occurrences
- How many times it appeared, all sources combined.
- First and last seen
- The exposure window, from first to last sighting.
- Validity indicator
- The more a credential circulates, the more likely it is still valid.
A demo on your perimeter, not on a demo dataset.
Console tour, API integration, leaks detected on your domains, live.
- [✓] No NDA
- [✓] No commitment
- [✓] No installation