What problem does it solve? Investigators and security teams need to know which services an identity was registered with and whether its credentials are circulating, but breach data is fragmented across curated sources, commercial databases, and unverified combolists that are easy to misinterpret. ## Core Features & Use Cases - Service Enumeration: Turn an email address into a map of registered services, registration dates, and recovered usernames using Have I Been Pwned and record-level sources like DeHashed, IntelX, and Snusbase. - Safe Password Checking: Verify whether a password is in circulation via the Pwned Passwords k-anonymity range API without ever transmitting the credential. - Source Grading and Pitfall Detection: Distinguish verified breaches from combolists, recycled dumps, and scraped data relabelled as breaches, with a four-level confidence grading scheme. - Use Case: During an executive protection review, check a VIP's email against HIBP, recover a forgotten username from an old forum breach, pivot it into a handle search, and grade each finding with provenance before writing the report. ## Quick Start Ask the agent to check what breach exposure exists for the email address a.mercer@example.com and interpret the results.