Request

Supported types are username, name, email, hostname, mac_address, ip_address, org_alias, bin, cve, domain, password, hashed_password, vin, address, and phone.
The route is OEM-credited. A cve query can return vulnerability intelligence rather than credential records.

Data controls

  • Do not display or log raw passwords.
  • Hashes can still be sensitive and should be access-controlled.
  • Do not use returned credentials to access another service.
  • Store source, breach date, ingestion date, tenant, and incident disposition.
  • Apply retention and deletion requirements before enabling collection.
  • Restrict free-form searches that could retrieve unrelated personal data.
An empty or 404 response means no result was returned for the query; it does not prove that no exposure exists.