oxHaus Exposure
Find the company identities and portal accounts that appear in exposure data.
oxHaus Exposure checks licensed breach and infostealer sources for email addresses at your verified domain and accounts on your company login portals. Each finding shows the source, the dates that apply and what the evidence does and does not show, and becomes a tracked fix.
Exposure is in development. Until it is released, the same assessment is available as part of a security engagement.

How an assessment works
01
Add the domain
Add the exact domain and any login hosts to assess, and choose corporate identity matching, portal account matching or both. Nothing is checked at this stage.
02
Prove control
Publish the TXT record we issue at _oxhaus-verify on that domain, or submit a delegated mandate for review. The record is single use, bound to your organisation and expires.
03
Run the assessment
We query the sources in your plan for that exact scope and report coverage per source, including any check that did not complete.
04
Review and fix
Review each finding, record business context, assign fixes to owners and retest. Identities stay masked unless a permitted person reveals one, and every reveal is logged.
Illustrative assessment
Example workspace. The company and findings shown here are fictional.
| Identity | Relationship | Source | First observed by oxHaus |
|---|---|---|---|
| j•••@kopano.example | Corporate-domain identity | Source A | 12 Mar 2026 |
| l•••@kopano.example | Corporate-domain identity | Source B | 3 Feb 2026 |
| c•••••r7 | Portal account match | Source A | 19 Jan 2026 |
Illustrative
How findings are labelled
- Corporate-domain identity
An address at your verified email domain
It does not confirm that the person still works for you or owns the account.
- Portal account match
An account on one of your verified login hosts
It may belong to a customer, partner or member of staff.
- Coverage
Complete, partial, unavailable or not checked, for each source
No matches means none were found in the sources checked, not that none exist.
- Priority
Urgent, high, routine or informational
Set by a versioned rule from evidence type, age, recurrence and your business context. It is not an incident severity.
What an assessment does not do
- A match in a source is not proof that your systems were breached.
- It is not a penetration test and never tries a credential against any system.
- No matching records means none were found in the sources checked. It does not cover every possible exposure.
- Passwords, tokens and cookies are removed at ingestion, before anything is stored.
- Nothing company-specific is checked until control of the domain is proven or a mandate is approved.
Start a security discovery.
Describe the domains, portals and people you want covered. Discovery records the scope and who can authorise it before anything is checked.
