Integrations / Breach monitoring (Have I Been Pwned)

Dark-web / breach monitoring

Breach monitoring (Have I Been Pwned)

Instead of finding out about a credential breach when someone else exploits it, Nexus checks your domain against Have I Been Pwned and turns a hit into a tracked security finding.

How it works

  • Checks a verified domain against the HIBP breached-domain API (requires a paid HIBP API key and a domain verified in that HIBP account)
  • A new account-in-breach hit creates a deduplicated finding and raises a high-severity Security alert with a clear remediation instruction — it becomes a tracked task, not a report nobody reads
  • Runs on a recurring schedule (daily by default, per tenant) in addition to an on-demand scan
  • Also includes a free Pwned Passwords k-anonymity check — only a SHA-1 prefix is ever sent, never the plaintext password — usable with no API key at all

Live — real HIBP API calls once a key and verified domain are configured, feeding the same alert pipeline as every other finding; the free password-check tool needs no configuration.

See Breach monitoring (Have I Been Pwned) inside Nexus.

Join the design-partner cohort and we'll show you exactly how your existing stack folds into the console.