Data & Ethics

Our raw material is stolen data. That obliges us more, not less.

Where the data comes from, how fast it arrives, and how the people inside it are protected. Documented here, in the open, because trust in this product starts with its supply chain.

01Source categories

10 collection surfaces on one pipeline

Eight of the ten are ours end to end, crawled by collectors we operate. The other two, the vulnerability records and the threat indicators, are open catalogues: published by other people and read free directly from them rather than resold to us.

Stealer log channels

Primary distribution channels where infostealer output is first dropped, captured before resale and aggregation.

Underground forums

Access-broker, fraud and leak communities across the underground, kept with their screenshots and attachments after a moderator purges the thread.

Telegram

Sale channels, combolist rings and victim announcements, indexed with attachments and media. Forwards of one message count against where we first read it.

Discord servers

The coordination layer: invite-only servers, their channels and threads, with the files that moved through them kept retrievable after the message is gone.

XMPP networks

The negotiation layer of the underground, where the escrow opens and the price is agreed, and the channel almost nobody indexes.

Criminal marketplaces

Access, data, cards and infrastructure, listed and priced. Goods re-advertised after failing to sell collapse onto the original record.

Paste-site drops

Credential, key and record drops posted to paste services, captured ahead of the expiry that was meant to make them disposable.

Ransomware leak sites

Victim listings, countdowns and proof packs, timestamped and archived through deletion, because a pulled entry usually means negotiation started.

Vulnerability sources

CVE registries, EPSS, CISA KEV, vendor advisories and exploit trackers, merged per CVE.

Threat indicator catalogues

Open catalogues of malicious infrastructure: addresses, domains, URLs and file hashes published as hostile, read from their publishers at source and merged per indicator so one address carried by several of them stays one record.

Nothing off these surfaces reaches a query in the state it arrived. Each record is classified first, and a fair amount of what that layer computes is deliberately never handed back. The enrichment layer, and what it withholds .

02Coverage

We read the underground; we don't translate it

Global feeds translate the underground; we read it natively, in whatever language a source is written in. Beside the map: what each surface actually contributed over the trailing quarter, counted rather than estimated.

GLOBAL COLLECTION FOOTPRINT

worldwide · multilingual

World map. 14 monitored source communities marked across the globe, wired into one distributed collection network. Each marker below can be focused for its name and the venues counted there.

Los AngelesMexico CityNew YorkSão PauloLondonLagosJohannesburgMoscowDubaiMumbaiSingaporeHong KongTokyoSydney
14 monitored communities distributed collection network collection density · indicative

COLLECTED VOLUME BY SURFACE

TRAILING 90 DAYS

The per-surface breakdown is served live and could not be reached just now. It is published in full, with the counts behind it, on the collection page. We would rather show you nothing here than a distribution nobody measured.

03Collection ethics

The four commitments

We observe; we never participate

We collect what criminal marketplaces expose to their own audiences. We do not trade, solicit, or commission the theft of data. Our collection posture is documented for customers under NDA.

Victim data is evidence, not a commodity

Reaching it takes a named account holding the module, every query against it is attributable and written to the activity log, and we verify that an organization is entitled to monitor what it asks about before granting the role. Retention limits and the deletion path are on the legal basis page.

We audit access to our own data

Every search, by every user and including our own staff, is recorded in the Activity log. Org admins see who searched what, and when. "Even we watch ourselves" is a control you can inspect.

Legal basis, in writing

Processing leaked third-party personal data demands a documented lawful basis, retention limits and subject-rights handling. Ours is public; read the legal basis page.

04Freshness

Stale threat intel is trivia

The value of a leaked-credential record decays by the hour. We publish our pipeline latency instead of asking you to assume it.

CREDENTIAL VALUE DECAY

conceptual · hours after capture
0%25%50%75%100%0h12h24h36h48h60h72haggregated feeds land hereindexed & alertingat ~7 min~11% of value left

~7 min

typical time from log batch capture to searchable index

24/7

continuous collection; the underground doesn't keep office hours

Live

pipeline telemetry published on the status page

Your competitors will learn about the leak from the invoice.

Learn about it from the log batch.

NDA-friendly briefings · global coverage · no slideware