DRANEXA Exposure Intelligence
TRUST MODEL

Observed, sourced, sanitized.

V1 admits only verified, non-fabricated, non-sensitive, non-retired breach entries from the public HIBP breach catalogue. Spam lists, malware/stealer-log records and raw breach payloads are excluded.

Source contract

Dranexa uses the public breach catalogue and its domain filter. It does not use HIBP Domain Search for arbitrary organizations because that workflow requires proving control of the domain and can return breached aliases.

Confidence

Every admitted V1 event is marked as a verified-source observation because the source entry must be HIBP-verified and pass Dranexa's deterministic admission rules. Confidence describes source/admission quality, not the severity of an incident.

Privacy

No email addresses, passwords, password hashes, session data, tokens, cookies, or raw breach payloads are persisted in the public database.

Indexing

A report is eligible only when at least one admitted event is persisted after a successful source observation. Runtime indexing remains globally disabled until the release canary explicitly enables it.