Exposure Center · Password Check
Coming soonFree~1 minWe check this without ever seeing your password. Here's how.
Your password is hashed inside your browser. Only the first five characters of that hash leave the device; the matching happens locally against a range of hundreds of candidates. This is k-anonymity — the design, not a promise.
The password itself is never transmitted, never logged and never stored — not by us and not by the range service. Only a five-character hash prefix is sent.
Result appears here: compromised or not found, plus what to do about it.
Only the outcome is saved if you ask us to. The password is discarded the moment the check returns.
Every number on this page is produced by the rules on our Methodology & Trust page: cited claims only, no biometrics, no third-party scraping, no storage of pasted content. Unfamiliar term? The cited glossary explains each one.