Free Security Exposure Check
Run non-invasive checks on passwords and public domain configuration. The result is an initial indicator, not a replacement for an audit, vulnerability assessment or penetration test.
Password Breach Check
Check whether a password has appeared in known data breaches. The password is not stored or sent in plaintext.
How the password is protected
Your browser computes the SHA-1 hash locally. Only the first 5 hash characters are sent using the k-anonymity model; the final comparison happens in your browser.
Source: Have I Been Pwned – Pwned Passwords. A match means the password appears in known breach data, not that a specific account was compromised.
Enter only the domain. We analyse publicly verifiable configuration such as email authentication, HTTPS, TLS and security headers without running invasive tests.
Publicly verifiable domain configuration including SPF, DKIM, DMARC, MX, HTTPS/TLS and security headers, plus a separate password check using k-anonymity.
No. The tool uses publicly reachable information and configuration and does not run exploits or penetration tests.
No. The complete hash is calculated in your browser and only a 5-character prefix is used for the k-anonymity lookup.
No. It only means the public checks performed are in good condition. It does not cover endpoints, identity, cloud, application vulnerabilities or internal configuration.
The Exposure Check is a public, non-invasive review. An authorised penetration test evaluates vulnerabilities and attack paths within an agreed scope.