Handling data that is sensitive by definition
Exposure data is useful to defenders and to attackers alike. The platform is built so it only ever reaches the first group.
How we protect breach intelligence data
These controls are part of the platform architecture, not optional add-ons.
Data protection
Masked Evidence by Default
Exposed credentials are displayed masked. Access to full values is restricted, deliberate and logged — never the default view.
Tenant Isolation
Every organization’s data is segregated at the application layer. Cross-tenant access is denied by design and covered by security review.
Encryption in Transit
All traffic to the website and platform is encrypted with TLS. Internal service traffic is confined to a private network.
Audit Logging
Security-relevant actions — sign-ins, evidence access, exports — are recorded for customer audit and investigation.
Access & operations
Multi-Factor Authentication
Platform accounts support TOTP-based MFA, with single active challenge enforcement to resist session abuse.
Role-Based Access Control
Permissions follow least privilege. Administrative capabilities are separated from analyst workflows.
Hardened API Access
API access is token-scoped and rate-limited at the edge. Abuse paths are continuously reviewed.
Security Review Gate
Changes touching authentication, tenant data or external calls pass a mandatory security review before release.
Report a vulnerability
We welcome good-faith security research into the StealerHunt website and platform.
If you believe you have found a security issue, report it through the contact form with enough detail to reproduce it. Please do not access other organizations' data, degrade the service, or publicly disclose before we have had a reasonable opportunity to fix the issue.
We confirm receipt, keep you informed of remediation progress, and credit researchers who wish to be named.
Questions about security or compliance?
Request our security documentation pack as part of your evaluation.