Skip to content
LeakLens

About

Security tools that respect you first.

LeakLens started with a simple frustration: checking whether your data appeared in a breach shouldn't require handing over your email to yet another company, creating an account, or paying a subscription. Every tool on this site is free, requires no signup, and is engineered so that what you type stays yours.

How our tools work

  • The breach checker reduces your email to its domain in memory, matches it against a curated index of major verified incidents, builds your report, and discards everything. Nothing touches disk or logs.
  • The password checker runs entirely in your browser. It uses k-anonymity: only a 5-character fragment of a SHA-1 hash leaves your device, making reconstruction mathematically infeasible.
  • Network tools (DNS, IP, header scanning) run server-side so third-party providers see LeakLens' infrastructure asking, not your home connection.

Where breach data comes from

Our corpus tracks over fifty of the largest, best-documented breaches in history, compiled from public security research, official disclosures and reputable industry reporting. Each entry lists dates, scale, exposed data types and severity. We deliberately exclude rumoured incidents that lack credible sourcing. It complements, but does not replace, per-address services; treat any match as an instruction to rotate credentials, not as a complete audit of history.

How the site sustains itself

Hosting and running these services costs money. LeakLens is funded through unobtrusive advertising that only loads after you explicitly opt in via the cookie banner, plus optional reader support. There are no premium tiers, paywalls, or "pay to see your own results" mechanics, and there never will be.

Principles

  1. No stored queries. Lookups live in memory only.
  2. No dark patterns. No fake countdowns, no email gates, no upsells.
  3. Education first. Tools are paired with guides explaining the underlying concepts.
  4. Lawful use only. Built for self-audits, brand checks and defensive research, misuse violates our terms.

Who maintains LeakLens

LeakLens is built and edited by Noah Clanman, a security-focused developer who has shipped privacy tools used by journalists and researchers. Editorial choices, which breaches are indexed, how body-marker detection is validated, when a guide is updated, are made by the editor, not by automated scraping. You can review the open-source implementation on GitHub and audit how each tool handles input.

We publish under a real name and a reachable contact address because trust in security advice depends on accountability. Corrections are credited; responsible disclosures are acknowledged within 72 hours. If a claim here misleads you, tell us and we will fix it with a dated revision note on the affected guide or tool page.

Editorial policy & review process

  • Original research, not aggregation. Guides are written from primary sources, provider documentation and our own testing of public APIs, not spun from other blogs. Each guide cites its scope in the introduction and states its limitations explicitly.
  • Hands-on verification. Tool behaviour is tested against known true-positive and true-negative cases before publication: username probes against handles we control, header scans against configurations we intentionally harden, and breach matching against disclosed incident timelines.
  • Continuous updates. Every guide shows a published and an updated date. We re-review guides after material changes in browser behaviour, DNS standards or breach disclosure norms. Tool descriptions and rate limits are revised when upstream provider behaviour changes.
  • No pay-for-coverage. No advertiser can buy placement in a guide, a tool result or a breach record. Affiliate links, if ever added, will carry rel="sponsored nofollow" and a plain-language disclosure at the point of use.

Methodology for breach inclusion

An incident is indexed only when it meets two criteria: credible public reporting from the affected organization, a regulator or reputable independent investigation, and a description of affected scale and data types sufficient to produce actionable advice. Rumoured dumps without corroboration are excluded even if widely shared. For each included incident we record the discovery window, scale, exposed data types and severity so users can assess urgency without panic.

The index currently covers 57 major incidents and is growing as disclosures are vetted. Each record notes whether passwords, financial data or identity documents were among exposed fields. The distinction between "email leaked" and "email plus reusable password leaked" determines the advice that follows.

How we test, and how you can verify

Every tool page documents its trade-offs in public: which public APIs receive which inputs, what timeout and retry budget applies, and what happens when a provider is unreachable. The password checker states upfront that only a 5-character hash fragment leaves the browser; the username search marks platforms known to fluctuate as inconclusive rather than guessing.

If you are technically inclined, open your browser DevTools while using any tool: network requests are inspectable, and lookup endpoints return JSON with the same field names shown in the interface. Rate limits are in-memory and per-IP; swapping in a central Redis for global enforcement is documented in the repository for deployers who need it.

Transparency, funding and independence

LeakLens costs money to host and costs nothing to use. Funding comes from consent-gated advertising, ads render only after you click "Accept" on the cookie banner, and from optional reader support, if a SUPPORT_URL is configured. There are no premium tiers, no "pay to reveal your results" walls, and no sale of query data, because queries are not retained at all. This model is stated plainly so reviewers and readers can see what incentives do and do not exist.

Contact and corrections

Editorial feedback, data corrections with a public verifiable source, or security reports with reproduction steps are welcome via the contact page. We respond to human-written inquiries, usually within two business days, and publish fixes with updated timestamps so readers can see what changed. See also our privacy policy, terms of use and full guide library.

Last reviewed: August 2026. LeakLens is an independent project and is not affiliated with any breached service, breach-search vendor or people-search broker referenced in guides or breach records. Trademarks belong to their owners.

Questions, corrections or responsible-disclosure reports? Reach us via the contact page. See also our privacy policy and terms of use.