Reference public breach database
Outside EULong-standing public index of known data breaches, maintained for over a decade. Several billion credentials indexed.
Your IT lead β or your provider β has every right to ask detailed questions before entrusting your company's monitoring scope to a third-party tool. This page answers the most important ones. If your question isn't answered here, write to us at contact.
We only collect the data strictly needed for monitoring: your email address, your domain, and the addresses you want to protect. Nothing else.
You can delete your account and all associated data at any time, directly from your dashboard. Permanent deletion within 30 days β no questions asked.
We make money from paid subscriptions, not from selling your data. No ad partnerships, no brokers, no AI trained on your information.
KryptaScope only queries public databases or commercial APIs under contract. We don't scrape any sites, use any unofficial dumps, or participate in any underground markets. Each source is listed below with its operator and access method.
Long-standing public index of known data breaches, maintained for over a decade. Several billion credentials indexed.
Commercial source of breaches and combo lists, covering breaches that public databases miss.
Open breach-indexing project, used as a complement to cover some recent breaches.
Third-party aggregated database, used to cross-check results from the other sources.
Public database of malware and malicious URLs. Used to detect whether a monitored domain is involved in known malicious activity.
Database of phishing and malware URLs, used to check the reputation of detected look-alike domains.
Technical measures in place to protect your data. KryptaScope does not yet have ISO 27001 certification: it's a goal, not an achievement.
KryptaScope login passwords are hashed with bcrypt. No one at KryptaScope can read or recover your plaintext password β not even us.
The database is hosted in the European Union (Ireland). To query breach data, some monitored email addresses are sent to sources located outside the EU; those transfers rely on Standard Contractual Clauses and are set out in the DPA, available on request.
User sessions rely on server-signed tokens. The signing key is separate from the database key and held separately.
KryptaScope NEVER stores leaked passwords. We only store leak metadata: source name, date, types of exposed data, and a boolean "password exposed: yes / no".
All API keys (data sources, Stripe, Resend) are stored in server-side environment variables. No keys are exposed to the browser.
Paid features are protected at two levels: client-side (visual disabling) and server-side (database rejection). No sensitive action can be triggered by bypassing the frontend.
KryptaScope is a French application that processes personal data under the GDPR. Here is our position.
KryptaScope acts as a processor under Article 28 GDPR for the data you entrust to us (employee email addresses, incident data). You remain the data controller. A Data Processing Agreement (DPA) is available upon request.
Performance of the contract (Art. 6.1.b) for the data necessary to operate your account and the monitoring you request.
Your data is kept for the duration of your subscription. When you close your account, all personal data is permanently deleted within 30 days, except for items required by law (invoices: 10 years).
Data subjects can exercise their rights of access, rectification, erasure, portability and objection. We answer within the 30-day legal deadline. Write to us at: contact.
The questions we hear most often during the evaluation phase.
Yes. A GDPR Data Processing Agreement (DPA) compliant with Article 28 is available upon written request. We sign it before any production deployment.
In the eu-west-1 region of our database provider (Ireland, EU). Application servers (Vercel) may serve requests from multiple regions but the primary database stays in the EU.
If KryptaScope suffered a breach affecting your data, we would apply the same obligation we automate for our clients: notification within 72h to the relevant data controllers, and to the CNIL if the conditions of Article 33 are met.
No. We are a young product and formal certifications are a mid-term goal, not an achievement. This page documents what we actually do in the meantime. If your requirements mandate a certification, we can discuss it.
You can export your complete GDPR register as a PDF from your dashboard at any time. In case of business cessation, we commit to providing a 90-day window for you to retrieve your data.
Some elements are public (security score formula, sensitive account catalog, data source list β all documented on this page and the Methodology page). For a full infrastructure audit, contact us directly.