What Every Plan Includes
The full data set ships on every tier. No feature gating, no surprise upsells for the core capabilities security teams need every day.
Compromised credential detection
Stolen employee passwords from stealer logs, third-party breaches, and combo lists. Stealer log records include the malware family (LummaC2, RedLine, StealC, Vidar) and infection source. Hashed passwords cracked to plaintext where possible.
Full-text search across leaked files from ransomware attacks
Search the actual contents of leaked ransomware dumps for your company name, employee names, or internal project codenames.
Webhook and email alerts
Push findings into your SIEM or SOAR via JSON webhook. Or get HTML email alerts for security teams without an integration layer.
Full API access
Every endpoint and every data source available via REST API. Plus the Claude Code plugin for plain-English queries from your terminal.
How Plans Scale
Plans scale with the size of your monitoring estate and the speed and depth of coverage you need. We'll scope the right tier for your environment on the demo call.
Watchlist size
Number of domains, subdomains, and assets you can monitor. Scales from small portfolios up to enterprise estates with dozens of subsidiaries.
API query quota
Monthly API call volume for ad-hoc investigations, SIEM enrichment, and bulk pivots. Higher tiers support automation-heavy workflows.
Alert latency
Time from when a finding is indexed to when the alert reaches your inbox or webhook. Tightens at each tier.
Premium dark web market coverage
Coverage of premium, restricted, and invitation-only forums and markets. Available on higher tiers.
Included domain takedowns
Annual quota of typosquat and phishing infrastructure takedowns handled by our team. Higher tiers include more; additional takedowns available as add-ons.
