sentinel
breaches you can verify — and publish without breaking the law
an index of data breaches from public sources and third-party apis. a result for an address goes only to that address — never onto the screen of whoever typed it.
nothing is shown before confirmation — not even “no hits”. the address is not stored if the link goes unused for 15 minutes. the query is hashed in the browser (sha-1, 6-char prefix).
in production this step is the only moment the address exists in a log — as a salted hash, dropped after 24 h.
record contents are never shown: no passwords, no test results, no document numbers. you see the dataset name, publication date and data classes — enough to know what to change.
what actually leaked in 2025–2026, from third-party data, with the uncertainty stated
- 1–249 staff
- 70,5%
- 250–999 staff
- 13,5%
- 1000+ staff
- 15,9%
- source
- proton, 2025
the date is the dataset publication date in the monitored source, not the intrusion date. “unconfirmed” means no statement from the entity — we publish with that label, after contacting them first.