This result only reflects the records currently available in the index. It is not proof that no exposure exists. Save the criterion to monitor future matches.
When you submit a domain or company name, the browser sends it to the AdverseMonitor API for a read-only lookup against the existing index. The lookup does not probe threat-actor infrastructure, and the scanner does not notify the organization you searched. The result reflects records already stored in the production index.
What we check
The lookup searches the threat records currently stored in the production index for the submitted domain or organization string. Available records can include ransomware and other dark-web-related categories, but source availability and historical depth vary. A zero result is not proof that no exposure exists.
What the free scan will not tell you
The free lookup returns category counts only. Paid plans can show available source evidence for a matching record. AdverseMonitor does not check whether a specific email address, password or credential was exposed. The free lookup is also rate-limited to three queries per IP per day to keep the index responsive for serious users.
What a positive hit actually means
A non-zero result is not the same as "you have been breached today." Three common patterns:
Possible credential exposure. A source may contain an address tied to your domain. Verify the record, identify the account, and follow your credential-reset and authentication-log review process.
Forum chatter. A post may mention the company, a staff member, or possible access. Read the source and compare it with internal evidence before assigning severity.
Leak-site listing. A ransomware operator may have named the organization. Treat the listing as a high-priority investigation lead, verify the identity and source, then activate the appropriate incident-response and legal contacts under your plan.
How is the free scan different from your paid monitoring?
The free scan is a point-in-time lookup against the existing index. Paid monitoring repeatedly checks configured criteria and provides matching source evidence in the dashboard. Collection latency varies by source. Free scans are capped at three per IP per day.
Which sources does the scanner check?
The scanner checks records currently stored in the production index. Source availability, category coverage, historical depth, and collection latency vary.
Will my domain be flagged as suspicious if I scan it?
The browser sends the submitted value to the AdverseMonitor API for the lookup and rate limiting. The lookup does not contact threat-actor sites. If you allow analytics cookies, analytics receives fixed event names. Those events do not include the submitted value, returned categories, returned count, or error text.
What do I do if the scan finds my organization?
Review the available source evidence before deciding what happened. If the record can be tied to an account or system, follow your incident plan for credential changes, log review, containment, legal analysis, and escalation. The right time window and response depend on the evidence and your environment.
How current is the data?
The scan reflects records already present in the production index. Collection latency varies by source, and no complete or instantaneous coverage is claimed.
Can I scan a domain I do not own?
The scanner performs a read-only lookup against the AdverseMonitor index. Only submit a domain or organization name when you are authorized to assess it.