Domain scan checks the built-in database for all known breaches affecting this domain.
With HIBP API key, queries live breach data for all emails @domain.
Searches known paste sites (Pastebin, GitHub gists, paste.ee) for your organization's
data using public HIBP paste API and open intelligence sources. Pastes containing
credentials, internal IPs, or email lists may indicate active data exfiltration.
Uses k-Anonymity: only the first 5 characters of the SHA-1 hash are sent to HIBP.
Your actual password never leaves your browser. This is the same method used by
1Password, LastPass, and Firefox Monitor. Zero privacy risk.