Platform

Threat Intelligence · Detect & respond

We analyze your domain and tell you how many of your accounts are already circulating in stealer logs, public lists and known breaches. With the module on, every affected email address becomes a task with an owner, a playbook and evidence inside your remediation plan.

The count of exposed accounts is already in the free plan, no credit card needed.

What it is

Corporate credential exposure monitoring.

Leaked credentials are exposed usernames and passwords of your company that are already in third-party hands, almost always without anyone inside having done anything wrong. They get there by three paths that do not go through your network: a laptop with an infostealer inside, the breach of a service someone on your team used years ago, or a combo list recycled on a forum.

The problem arrives weeks after the theft, when someone uses those credentials and walks in with a correct username and password, with no exploit and no alert going off. Nobody inside the company checks every week which addresses of the domain have shown up on a new list, and the exposure stays open until someone looks.

The cost shows up when someone warns you from outside: an invoice diverted to another bank account, a customer who received an email from you that you never wrote, or a supplier whose payment details were changed in the middle of a thread. By then the credential has been circulating for a while and, if it came out of an infected machine, the session cookies are circulating with it.

3

published severity rules

6

fields stored per credential

30

days that mark critical severity

12

months of evidence validity

What it is
Monitoring of your domain's credential exposure in stealer logs, public lists and known breaches, with a rotation task for every affected account inside your remediation plan.
Who it is for
Companies of 10 to 250 employees with their own email domain and nobody inside who checks every week which addresses have shown up on a new list.
Where it fits
In the Pro and Max plans. In Free, leaked credentials are shown only as a count, without detail: you see the number of exposed accounts, and each account's record is unlocked with the module.
What we need
The company's email domain. Nothing else: no agents, no access to your email, no credentials of yours. The query runs from our infrastructure against an external index.
Cadence
Check the date of the last sweep in the portal and your account's schedule. Each account's history lets you tell new records from earlier appearances.

What each sweep looks at

Three sources of exposure and six fields per credential.

Each run takes your company's main domain and searches by email domain against a commercial index of exposed credentials.

Stealer logs
The dump from an infected machine: passwords saved in the browser and session cookies.
Third-party breaches
The SaaS someone on your team used with their work email and that suffered a breach.
Public lists
Aggregated username/password pairs from old breaches that get recompiled and recirculated on forums.
The affected identity
Which address of your domain appears and who has to rotate the password.
Plain text or hash
The factor that weighs most in severity: in plain text the password appears unhashed; its current validity is not checked.
The source type
Telling malware on an endpoint from an old breach changes the response completely.
The entry date
How long the credential has been exposed and whether the originating infection is recent.
Breach dates
When the source provides them, they place the origin of the exposure in time.
Associated services
Where the credential has been seen in use, to know where else to sign out.

The query covers anyone with an address on your domain, even if their account is not published anywhere on your website. The call goes out from our infrastructure and your browser never talks to the source.

Severity

Three rules decide the urgency of each finding.

All three are published so you can challenge them: urgency depends on whether the password is usable as is and on when it entered the feed.

Critical

Plain text and recent stealer log

Applies when the password travels in plain text, comes from a stealer log and entered the feed 30 days ago or less. The combination deserves priority review. The feed entry date does not by itself prove when the machine was infected.

High

Plain text or stealer log

Applies to plain text from any source and to any stealer log, regardless of age. The origin and the format of the record justify reviewing the account and the machine, even if the dump is years old. The rotation task opens all the same, with its owner and its playbook.

Medium

Old exposure without either condition

Applies to exposure older than three years that meets neither of the two conditions above. It is residual risk, usually from old breaches with the password hashed. It stays on the list because a reused password opens the door on another service.

What a single address reaches

A corporate credential rarely stays in the mailbox. From a single address with the password in plain text you reach the invoice history and suppliers' bank details, whatever hangs off that identity through single sign-on, the apps that person authorized with one click and the open sessions. That is why the playbook adds closing sessions and reviewing the machine of origin.

What each sweep leaves behind

The record, the rotation task and the aggregates.

01

The account record

Severity, main source, first detection, the services where the credential has been seen in use and the event history with its source and date. New appearances accumulate here and the worst severity seen is kept.

02

The rotation task

One action per affected account, inside the same remediation plan where the scanner's findings already live, with its owner and its playbook: rotate the password, close the active sessions and review the services where it has been seen in use.

03

Dashboard and aggregates

Four counters in the header, the table ordered by severity and date, and the aggregates for management: infected endpoints, exposure window in days, affected services and the split of appearances by source. It is the material to explain the exposure to the board or to the insurer.

Sample exposed account · Sample data

Account
c•••@company.example
Severity
Critical in the example
Why
Plain-text record · stealer log origin · imported 9 days ago
Current validity
Not checked
Action
Rotate the password, close active sessions and review the machine of origin
Evidence
Source and dates available in the record

Where it fits in the platform

Every closed rotation counts as evidence.

A leaked credential and a weakness in your public surface are the two ways in without breaking anything, and both live in the same file. The finding is mapped to ISO 27001:2022 A.5.17 and A.5.7 and to Article 21(d) of NIS2. Every closure records actor, IP and the state before and after, and leaves associated evidence valid for twelve months.

Limits

What this module does not do.

Check the scope before turning on the module and coordinate with your team the actions that fall to them.

An empty result is not a guarantee

It means you do not appear in the indexed sources. No credential monitoring covers everything that circulates through private forums and markets.

It rotates nothing on its own

It opens the task with an owner and a playbook. The password change and the closing of sessions are carried out by your team or your identity provider.

It does not check whether the credential is still valid

Access is not tested with the leaked password. The exposure is reported, and attempting to use it is out of scope.

Only accounts on the corporate domain

The query is by email domain. Your team's personal accounts are out of scope, even if they appear in the same breach.

It does not read your email

There is no agent, no connected mailbox and no access to your systems. The search runs by domain against an external index of exposed credentials.

The information has a date

The date of the last sweep is visible in the portal. New exposure can appear between reviews.

In Free you only see the count

The free plan counts the exposed accounts. The details (which account, whose it is, since when and what to do about it) are unlocked in Pro.

Sized for companies of 10 to 250

With exposure volumes far above what is usual at that size, it is worth talking about a custom scope.

Plans

Threat Intelligence comes with Pro and Max.

The count of exposed accounts is in the free plan. The details (which account, whose it is, since when and what to do about it) are unlocked in Pro and stay in Max.

Free

To see your real risk before deciding anything.

€0

No cost · No card.

Everything to get looking:

  • Continuous scan External surface, 24/7
  • Posture and risk map Real-time CyberScore
  • Leaked credentials Counted, no detail
Start free

Base

For companies that want the whole platform without a security team of their own.

€190 / month

Self-serve · No commitment.

Everything in Free, plus:

  • Integrations Microsoft 365, Google Workspace and cloud
  • AI risk Apps with permissions over your data
  • Prioritized backlog Monthly remediation
  • 1 domain Continuously scanned
Get Base

Pro

For teams that need every sensor active and an expert behind it.

€990 / month

Advisor on escalation · No commitment.

Everything in Base, plus:

  • Security advisor On escalation, with SLA
  • Threat Intelligence Exposed credentials, under watch
  • Recurring pentesting Authenticated, report reviewed by Axyom
  • MDR 24/7 Up to 20 managed devices
  • Up to 5 domains All continuously scanned
Get Pro

Max

For high exposure or compliance demands.

€1,990 / month

Dedicated advisor · No commitment.

Everything in Pro, plus:

  • Dedicated security advisor A fixed person, monthly session
  • Priority response Incidents
  • Compliance by framework Downloadable evidence and attestation
  • Audit support Customer questionnaires and due diligence
Contact sales

FAQs.

What is a stealer log and why does it matter so much?

It is the dump of data an infostealer steals from an infected machine: passwords saved in the browser, session cookies and form data, sold in batches. When a corporate credential shows up inside one, that person's machine was infected, without any breach at the company.

Is changing the password enough?

Not when the credential came out of an infected machine: session cookies usually travel with the password and allow someone in without authenticating again. That is why the playbook adds closing the active sessions and reviewing the machine of origin, on top of rotating the password.

Do you monitor the team's personal accounts?

The query is run on the company's email domain, so it covers any corporate address even if it is not published on your website. Employees' personal accounts are out of scope, even if they show up in the same breach.

Do you have access to our email?

We only need the domain, and the query is made against an external index of exposed credentials. Nothing is installed and nobody reads your email. The call goes out from our infrastructure, so your browser never talks to the source.

Does it count as compliance evidence?

The finding is mapped to ISO 27001:2022 A.5.17 and A.5.7 and to Article 21(d) of NIS2, and it counts in the same file as the rest of your security. Every closure records actor, IP and the state before and after, and leaves associated evidence valid for twelve months.

Choose how to start.

On your own

Analyze your domain and start with your security posture. Then connect your systems and turn on the capabilities you need.

With our team

Tell us what you need to protect and which requirements you have. We will review the scope and the right plan with you.

Start now.