Skip to main content

Sources and services

Two entity types complete the pivot graph: where a credential leaked from (the source) and what it opens (the service). Both have directory pages and detail views, and both are reachable from any exposure row.

Sources — where it leaked

Sources lists the breaches, combolists, and stealer compilations seen in your exposed credentials. Open one to see which of your identities it exposed.

Source names are always shown, on every plan — a breach's existence is public knowledge, and knowing which breach touched you is the minimum actionable fact.

Typical uses:

  • A new breach makes the news — open its source page and know in seconds whether it touched you, and who exactly.
  • An identity's risk posture lists its breach sources — pivot into one to see who else from your organization is in the same dump.

Services — what it opens

Services lists the hosts your credentials were captured for — your own applications, a SaaS tool, a consumer site. Open one to see:

  • which of your identities are exposed on it,
  • from which machines the credentials were captured,
  • how fresh each capture is.

This is the fastest way to answer "who needs a reset on this app?" — one service page is a complete, dated reset list.

Password reuse — the blast radius

From any infostealer-sourced credential, the password reuse pivot lists the other accounts sharing that password. One capture on one machine can compromise every service where the password was reused; the blast-radius view turns "we reset the leaked account" into "we reset every account that password opens".

Rollups are computed over your exposures

The Sources and Services directories (like Identities and the Overview rollups) are derived from the exposure records loaded for your domain — the same slice the Exposures table shows, framed as "seen in your exposures". They are a lens over your findings, not an index of the entire dark web.