What the term usually means
Services sold under this name watch places where stolen data turns up: collections of passwords from past breaches, paste sites where copied text is posted, and, for some providers, closed forums and marketplaces. They match what they find against the addresses and domains they are watching.
What we read
LeakTrace reads monitored breach databases and paste sites, and checks for keys left in your own website's code. We do not crawl criminal forums, we do not buy data, and we do not log in to anything. Every assessment is human-verified before it is released.
What gets checked
For a firm, the starting point is its domain: every address at that domain is checked against breach records. When there is a match, the finding names the breach, when it happened and what kinds of data were in it, so the firm can decide which passwords to change first.
One check, or a daily re-check
A one-time check answers whether your addresses are in known breach records today. That answer ages fast: new breaches are disclosed every week and old collections are re-shared. For firms we monitor, the check is repeated daily, so a new appearance is reported soon after it becomes public, not months later.
What monitoring does not do
- It does not prevent a breach at another company.
- It does not remove data from breach collections once it is copied.
- It cannot see every source: some data is traded privately and never becomes visible.
What it does is shorten the time between an exposure and the password change that closes it.
Questions to ask any provider
- Which sources do you read, by type?
- How often is each address re-checked?
- Does a person review a finding before it is sent?
- What exactly will I receive, and what do I do with it?