No agent installed
No software to deploy on your workstations or servers. KryptaScope works only from the outside, exactly like an attacker. Zero intervention on your IT.
No access to your systems
We never request credentials to your mailboxes, servers, Active Directory, hosting provider, or internal tools. Everything we see is what the Internet sees.
No proxy, no tunnel
No redirection of your network traffic. No eavesdropping. No man-in-the-middle. Requests go from our servers to public sources (DNS, SSL registries, published breach databases) — never to your customers or employees.
No password stored
We detect that email + password pairs have been publicly leaked, but we only store metadata (yes/no, source, date). The password itself is never kept. Same for hashes.
Non-nominal public scan
The /scan page, available without an account, returns only aggregated counters (number of leaks, severity, admin presence). No email exposed, no breach name displayed, nothing an attacker could put to use. The rule is enforced server-side: no named detail ever reaches the browser until the domain has been tied to a verified account.
European hosting
Database hosted in the European Union. Application servers may handle a request from more than one region, but no customer data is stored outside the EU. Error monitoring and product analytics are routed through our own domain: no data is sent directly to a third party from your browser.
Data deletable on request
1-click cancellation from the dashboard. On written request, complete deletion of data associated with your account within 30 days, with written confirmation. Data retained for legal obligation (billing) is anonymised at the end of the retention period.