No fabricated attribution. Every fact comes with its source; what we can't confirm we show as unavailable.
@ present → email breach check · otherwise → domain attack surface. ·
The password is hashed in your browser; only the first 5 characters of the hash reach the server (k-anonymity). The password itself is never sent anywhere.
When a service doesn't respond we don't tell you «you're clean» — because we don't know. Instead we clearly return unavailable. Your email is used for a single lookup — never stored anywhere.
Sources: XposedOrNot + LeakCheck (breach), HIBP Pwned Passwords (k-anonymity), Hudson Rock (infostealer), certspotter + crt.sh, MX/SPF/DMARC (DNS), Shodan InternetDB, skopnix coverage, and the weekly Shodan AZ snapshot. All keyless/free — your email and password are never stored.