02

Useful by design. Restrained by default.

An exposure checker should answer a narrow question without becoming another source of sensitive information. These controls define what the registry accepts and what it refuses.

Accepted

Email addresses submitted for an exposure search and basic request metadata required to operate and protect the service.

×

Not accepted

Passwords, authentication tokens, MFA codes, recovery codes, payment information, or the contents of private accounts.

01

Exposure searches

The email address entered into the checker is used to compare the request against indexed exposure records and to protect the integrity of the service. Search results do not reveal raw breach records or passwords.

02

Retention

Search activity is retained only for the active assessment period and its approved reporting window. It is not used for advertising, marketing profiles, or sale to third parties.

03

Security controls

The registry’s public event interface rejects fields that resemble passwords, credentials, secrets, tokens, OTP values, or MFA codes. Administrative results are isolated behind restricted access.

04

Your choices

If you reached the registry through an organizational security exercise, contact your internal Security or Privacy team for questions about participation, access to results, and deletion procedures.