Exposures
Exposures is the record-level view: every exposed credential the reputation feed holds for the selected monitored domain, searched live. Two kinds of record share the table:
- Infostealer captures, logins pulled from an infected machine's browsers by malware.
- Breach & combolist records, credentials from breach dumps and compiled lists.
The KPI cards at the top split the total between the two.
Reading a row
Each row shows the identity, meaning the exposed email or username, the exact service the credential was for, the source, dates, and a masked password tail. Click any row, or Tab to it and press Enter, to open the record's own page.
The service is only known for an infostealer capture. A breach or combolist row shows "—" in the Service column; its breach is in the Source column, and searching for the breach's name still finds the row.
The record page
A record opens as a page of its own in place of the table. Its address is a link you can bookmark, reload or send to a colleague (Copy link). Previous and Next step through the rows of the list you opened it from, and Back to Exposures returns to that list with its search, facets, sort and page as you left them. Next steps only through the records already loaded: while the feed holds more, the position reads 12 of 225 loaded, and on the last loaded record Next is off and the page says so. Load more on the list fetches the next batch.
A record that belongs to someone else on a domain that is not verified yet opens only from the list: its link does not carry the person's address, so it cannot be looked up on its own.
For an infostealer-sourced credential, the page adds two sections:
- Infected device, the machine the malware ran on: OS user, serial, country, IP, antivirus, and the rest of the device dossier.
- Password reuse, the blast radius of other accounts sharing that password.
Tracking status: Active or Resolved
Every record has a Status, on every plan. It is Active until someone on your team marks it Resolved, for example after a password reset.
- Admins change it from the Status card on the record page, with an optional note, or tick several rows and use the bar above the table. Reopen sets a record back to Active.
- The card's History lists each change: who made it, when, and the note.
- Members and viewers see every status read-only.
- The Exposed credentials card shows how many records the team has resolved, next to the feed's total. The Overview's Resolved tile shows the same count as M of N.
- To resolve all of one person's records at once, open them under Identities and use Mark all resolved (see identity risk).
- On a domain that is not verified yet, a colleague's record shows its status and date only, and only your own records can be changed.
- A status that could not be loaded reads Unknown, never Active. If a credential is captured again, it arrives as a new record, Active.
A status belongs to the record under the domain you are viewing, so a record seen under two of your domains is tracked separately under each.
Search and facets
The search bar autocompletes across identities, services, and sources. Facets narrow by source and freshness. On the Free plan the facets are Pro-locked. The status facet (All, Active, Resolved) is on every plan. Text search and pagination stay live.
Searching for a whole email address, or filtering by an identity, asks the
reputation feed about that one address directly, so the table lists every
record for it, not only the ones in the batch loaded so far. An address pasted
with straight or curly quotation marks (" ' “ ” ‘ ’) or the double
guillemets « », a trailing comma, a typographic apostrophe or fullwidth
characters finds the same records as the address typed plainly. If that lookup
is not available (for example, the address is outside the domains you may
search), the table says it is showing matches from the loaded batch only.
Masking, passwords are never fully shown
Umbra never displays a full password. Only the last characters of a password are ever exposed:
- Free shows identities and emails in full, so who is exposed is always readable, but masks password fragments entirely.
- Pro shows the real password tail, enough to recognize which password it was, and adds a client-side redact toggle, off by default, so you can screen-share safely.
What Free sees here
On Free, the table lists only records older than 30 days: added to the feed more than 30 days ago, and dated more than 30 days ago. Findings added to the feed in the last 30 days appear as a locked teaser strip, their exact count for the domain and an upgrade CTA rather than the records. The delay is stated in a banner, not hidden.
The teaser and the row labels use different dates. The teaser counts by the date the feed added a record; a row's Fresh label reads the record's own date, the only date a row carries. A record the feed added this week can carry a date from years ago, so the two figures need not match.
The 30-day figure on Pro
On Pro, the header states the same figure the Free teaser shows: "N exposures added to the feed in the last 30 days", counted by the feed for the whole domain, not for the batch loaded so far. When that count is not available, the line is left out rather than showing a guess.
Zero is a result
A monitored domain with nothing exposed shows a positive "No exposed credentials found" state, from the moment it is registered. See the first run.
Switching domains
When more than one domain is authorized, the Domain switcher in the header changes which domain the view searches. It defaults to your own email domain. The domain you pick stays selected as you move between Overview, Identities, Exposures, Devices, Sources and Services, for as long as the browser tab is open; a new tab starts on your own domain again.