Request
Supported types are
username, name, email, hostname, mac_address, ip_address, org_alias, bin, cve, domain, password, hashed_password, vin, address, and phone.
cve query can return vulnerability intelligence rather than credential records.
Data controls
- Do not display or log raw passwords.
- Hashes can still be sensitive and should be access-controlled.
- Do not use returned credentials to access another service.
- Store source, breach date, ingestion date, tenant, and incident disposition.
- Apply retention and deletion requirements before enabling collection.
- Restrict free-form searches that could retrieve unrelated personal data.
404 response means no result was returned for the query; it does not prove that no exposure exists.