How it works, from the source to the alert.

What we collect, how we match it against your perimeter, and what you receive at the end.

From raw leak to qualified alert.

Two kinds of leak in, one format out, and an alert only when it concerns you.

01

Own collection

Telegram, forums, marketplaces, paste sites. No broker, no purchased data.

02

Normalisation and deduplication

A credential seen fifteen times is one leak, not fifteen alerts.

03

Correlation with your perimeter

DNS-verified domains, validated keywords. Nothing beyond.

04

Alert where you work

E-mail, Slack, Teams, signed webhook, SIEM.

SOURCES
Dark Web Markets
Telegram Channels
Infostealer Logs
Underground Forums
Paste Sites
ingest
24/7
Stealed
Stealed
ENGINE
REST API
SIEM
SOAR
analyze
Internal Insight
External Insight
→ *.acme.com
→ api.acme.com
Keyword Insight
→ acme.example.com
→ example.com/acme/
Alerts
500M
credentials per day
14B+
unique credentials indexed
< 60 min
from publication to availability
< 5 min
to open a workspace

Three correlation angles

Every leak is matched against your proven perimeter from three angles. You receive what concerns you, nothing else.

Criminal sources
  • Telegram
  • forums
  • marketplaces
  • paste sites
Your proven perimeterDNS OK
  • acme.com
  • *.acme.com
  • "acme"
01 · Internal Insight

Which employee is already compromised?

Credentials whose e-mail address is on your domains, and the sites where they leaked.

login
j.doe@acme.com
url
https://sharepoint.example.com/login
source
infostealer · lumma
[✓] Match: e-mail domain
02 · External Insight

Which user of my services signs in with a stolen access?

Credentials whose login URL points at your services: customers, partners, contractors.

url
https://vpn.acme.com/sslvpn
source
combolist · ulp
[✓] Match: login host
03 · Keyword Insight

Which contractor, project or brand shows up in a leak?

Your keywords spotted in leak URLs, even when your domain is not there.

url
https://acme.example.com/portal
source
infostealer · redline
[✓] Match: keyword

Whatever the source, the same record.

A credential from a combo list or from an infostealer log arrives in the same format, with its circulation metrics. That is what makes filtering, sorting and prioritising possible.

One format outJSON
url
https://vpn.acme.com
type
infostealer · lumma
sources
4
occurrences
5
first_seen
2026-03-06
last_seen
2026-04-14
validity
probably valid
Every credential comes with its circulation metrics
Distinct sources
How many different sources it was found in.
Occurrences
How many times it appeared, all sources combined.
First and last seen
The exposure window, from first to last sighting.
Validity indicator
The more a credential circulates, the more likely it is still valid.

A demo on your perimeter, not on a demo dataset.

Console tour, API integration, leaks detected on your domains, live.

  • [✓] No NDA
  • [✓] No commitment
  • [✓] No installation