Provider check temporarily unavailable

We will not turn a provider error into a “safe” result.

SafetyKit’s public breach lookup is paused until a licensed, authenticated server-side provider is configured and its privacy, retention, rate-limit, and failure behavior pass review. This page does not collect or submit an email address.

What changed

The prior client-side integration could receive an authorization or rate-limit error and display “no breaches found.” It also could not support the privacy claim shown on the page. That path has been removed.

What a future check must show

Provider coverage, check time, positive matches, unavailable or rate-limited states, retention, and a reminder that no known match is not proof an account is secure.

Secure the account now

  • Use a unique password for your email account and replace any reused passwords.
  • Turn on a passkey or the strongest available multifactor authentication.
  • Review recovery addresses, trusted devices, forwarding rules, and recent sign-ins.
  • Treat unexpected password-reset, payment, and verification-code messages as suspicious.