Emver
Emver
Profiden+ Blog
Risk & Compliance

Data Breach Check API

Check an email address or mobile number against known breach corpora and return the breaches, the data types exposed and recency, a signal for account-takeover risk and step-up authentication.

Response
Real-time
Inputs
0 required · 2 optional
Consent
Not required
Billing
Per successful call
POST /v1/data-breach-check
Sandbox · Production
  1. Your application sends

    • Email address
    • Mobile number
  2. Profiden API

    Validates the request, queries the source, normalises the answer and logs the call. Billed only on success.

  3. Verified with

    Authoritative source

  4. You receive

    • Found in breaches
    • Number of breaches
    • Most recent exposure
    • Data types exposed
data-breach-check Full reference

What the Data Breach Check API does

Send the identifier; receive the breach count, the most recent exposure date and the categories of data leaked (passwords, phone, address). Nothing from the breach itself is returned.

Benefits of the Data Breach Check API

Has this email or phone appeared in known credential leaks?

ATO prevention

Step up authentication for exposed credentials.

Customer protection

Prompt password resets where it matters.

Use cases

Data Breach Check API use cases

Where the Data Breach Check API is typically called, and what it settles there.

Login and account recovery

Risk-based authentication signal.

Onboarding

Part of the digital footprint picture.

How the Data Breach Check API works

Request and response details, environments and a ready-to-import collection are in the developer console at console.profiden.com.

01

Authenticate

Call with your organisation API key. Sandbox and production use the same contract.

02

Send the inputs

as a JSON body. Optional fields sharpen the match.

03

We verify at source

Profiden queries the authoritative record, normalises the answer and logs the request.

04

Act on the result

A verification status plus the fields listed above, in the same response envelope as every other API.

Built for the DPDP Act 2023

Consent recorded · Payloads not retained beyond your retention window · Every request traceable

Encryption in transit and at rest
Data processed in India
Per-request audit trail
Masked identifiers in responses

Data Breach Check API: frequently asked questions

What teams ask before adding the Data Breach Check API to their integration.

Never. Only the fact of exposure and the categories involved.

Related APIs

APIs that usually run alongside the Data Breach Check API, on the same key.

All APIs

Get access to the Data Breach Check API

Tell us your use case and expected volume. We set up the organisation, share per-call pricing and issue keys.