See which of your addresses are in breach records
An address at your firm lands in breach records when a service it was used with loses its user list. If the password that went with it still opens something, a stranger can sign in as you. We read from outside which of your shared addresses are listed, and from which breach.
Attackers use AI to find openings. We use it to find yours first, and a person checks every finding before your assessment is released.
What a listed address means, and what we read.
A reused password is still one of the first ways into a firm, and a list of real addresses is where the attempt starts.
Addresses such as info@ and admin@ are read by several people, printed on your website and often the sign-in for your domain, your website or a payments portal. We check whether each appears in monitored breach databases.
For each listed address, the breach that listed it and its date, so your IT provider knows which password to change and where it was used.
We do not look up your people on the free reading. In the paid assessment you give us the staff addresses to check, and we check only those.
Change the password wherever that address is a sign-in, to one used nowhere else, and turn on two-step sign-in for it. On its own, two-step sign-in defeats a reused password.
Measured on 30 September 2026.
Measured across the firms we have assessed in Canada and the United States, not a national census. The method is in the study.
The outside view, in plain words.
Next to the people you already work with.
Keeps your systems running and does the fixes. We give them an independent list to act on, with the check that proves each fix. We are paid by no one who sells the fixes, so every finding is independent.
Tries to break in and needs access. We read only what is already public, from outside, and log into nothing.
Feeds your premium and eligibility. We show you the same outside view first, in plain words, so you walk into renewal knowing the answers.
See which of your addresses are listed, before someone signs in with one.
The External Exposure Check: your outside reading, with what we found and a check you can run yourself. No access, nothing tested.