Our raw material is stolen data. That obliges us more, not less.
Where the data comes from, how fast it arrives, and how the people inside it are protected. Documented here, in the open, because trust in this product starts with its supply chain.
10 collection surfaces on one pipeline
Eight of the ten are ours end to end, crawled by collectors we operate. The other two, the vulnerability records and the threat indicators, are open catalogues: published by other people and read free directly from them rather than resold to us.
Stealer log channels
Primary distribution channels where infostealer output is first dropped, captured before resale and aggregation.
Underground forums
Access-broker, fraud and leak communities across the underground, kept with their screenshots and attachments after a moderator purges the thread.
Telegram
Sale channels, combolist rings and victim announcements, indexed with attachments and media. Forwards of one message count against where we first read it.
Discord servers
The coordination layer: invite-only servers, their channels and threads, with the files that moved through them kept retrievable after the message is gone.
XMPP networks
The negotiation layer of the underground, where the escrow opens and the price is agreed, and the channel almost nobody indexes.
Criminal marketplaces
Access, data, cards and infrastructure, listed and priced. Goods re-advertised after failing to sell collapse onto the original record.
Paste-site drops
Credential, key and record drops posted to paste services, captured ahead of the expiry that was meant to make them disposable.
Ransomware leak sites
Victim listings, countdowns and proof packs, timestamped and archived through deletion, because a pulled entry usually means negotiation started.
Vulnerability sources
CVE registries, EPSS, CISA KEV, vendor advisories and exploit trackers, merged per CVE.
Threat indicator catalogues
Open catalogues of malicious infrastructure: addresses, domains, URLs and file hashes published as hostile, read from their publishers at source and merged per indicator so one address carried by several of them stays one record.
Nothing off these surfaces reaches a query in the state it arrived. Each record is classified first, and a fair amount of what that layer computes is deliberately never handed back. The enrichment layer, and what it withholds .
We read the underground; we don't translate it
Global feeds translate the underground; we read it natively, in whatever language a source is written in. Beside the map: what each surface actually contributed over the trailing quarter, counted rather than estimated.
GLOBAL COLLECTION FOOTPRINT
worldwide · multilingualWorld map. 14 monitored source communities marked across the globe, wired into one distributed collection network. Each marker below can be focused for its name and the venues counted there.
COLLECTED VOLUME BY SURFACE
TRAILING 90 DAYS
The per-surface breakdown is served live and could not be reached just now. It is published in full, with the counts behind it, on the collection page. We would rather show you nothing here than a distribution nobody measured.
The four commitments
We observe; we never participate
We collect what criminal marketplaces expose to their own audiences. We do not trade, solicit, or commission the theft of data. Our collection posture is documented for customers under NDA.
Victim data is evidence, not a commodity
Reaching it takes a named account holding the module, every query against it is attributable and written to the activity log, and we verify that an organization is entitled to monitor what it asks about before granting the role. Retention limits and the deletion path are on the legal basis page.
We audit access to our own data
Every search, by every user and including our own staff, is recorded in the Activity log. Org admins see who searched what, and when. "Even we watch ourselves" is a control you can inspect.
Legal basis, in writing
Processing leaked third-party personal data demands a documented lawful basis, retention limits and subject-rights handling. Ours is public; read the legal basis page.
Stale threat intel is trivia
The value of a leaked-credential record decays by the hour. We publish our pipeline latency instead of asking you to assume it.
CREDENTIAL VALUE DECAY
conceptual · hours after capture~7 min
typical time from log batch capture to searchable index
24/7
continuous collection; the underground doesn't keep office hours
Live
pipeline telemetry published on the status page
Your competitors will learn about the leak from the invoice.
Learn about it from the log batch.
NDA-friendly briefings · global coverage · no slideware