# Document exposure within your program's scope.

[Document exposure within your program's scope.](https://leakradar.io/en/use-cases/bug-bounty)

Reviewed: 2026-09-09

Find credential records associated with authorized assets and prepare a contextualized disclosure that follows the program's rules.

Create a free account to start investigating.

## A match is the beginning of your assessment.

An address or service in a leak can help orient your research. Its presence alone does not establish a valid vulnerability. Keep the authorized scope, source context and program policy alongside your findings.

Make the evidence understandable to the person handling your report.

## From scope to a clear disclosure

### Check the program scope

Confirm the authorized assets and the policy for leaked credentials before starting your search.

### Research the relevant assets

Use domain or other available search modes to examine records associated with those assets.

### Prepare your disclosure

Record the context, explain what remains uncertain and mask sensitive details for the recipient.

## What you can work with

### Focused searches

Use the relevant domains and filters to keep your investigation tied to authorized assets.

### Material you can revisit

Save useful queries and use available exports to organize your research notes.

### A clearer handoff

Present the affected asset, source information and observation context in a report the program can assess.

## Access that fits your work

Start with a free account, then choose the plan that fits your datasets, monitoring, exports and team.

Get notified via Email, Slack, Discord, Telegram or Webhook when new exposed credentials match your monitored domains or email addresses.

Illustration with fictional data.

## Before you get started

### Does finding a credential guarantee a bounty?

No. Eligibility and rewards depend on the program's policy and its assessment. A leak record alone does not guarantee acceptance.

### What should I include in the report?

Include the authorized asset, relevant source context and a clear account of your observation. Follow the program's rules for handling sensitive information.

## Start with a well-defined scope.

Sign in to research the assets covered by your program.

## The data behind LeakRadar

Investigate exposed accounts across stealer logs, combolists, raw leak files and dark web forums. Inspect plaintext passwords when available in the source.

645,193,048,776 lines across indexed leak files. File lines, not a count of unique accounts.

Updated: 2026-09-14T23:24:37.940Z

## Explore the source behind a match

### Stealer logs

Connect a captured login to its service URL, username and password to understand which access is exposed.

[API documentation](https://docs.leakradar.io/#tag/Search-Email)

### Combolists

Find email/password and username/password pairs, including records without a service URL.

[API documentation](https://docs.leakradar.io/#tag/Search-Combolists)

### Raw leak files

Search the text of leaked files, database dumps and unstructured records beyond normalized credential fields.

[API documentation](https://docs.leakradar.io/#tag/Raw-Search)

### Dark web forums

Search indexed forum posts for mentions of your organization and examine the discussion's source context.

[API documentation](https://docs.leakradar.io/#tag/Dark-Web-Search)

## Plaintext passwords, with their account context

Inspect the exposed password alongside the account and, for stealer logs, its service URL. When the source includes plaintext, that detail helps your team scope password resets and investigate exposed access.

Compare plans for plaintext access and included unlock points.

## Access that fits your work

Start with a free account, then choose the plan that fits your datasets, monitoring, exports and team.

Get notified via Email, Slack, Discord, Telegram or Webhook when new exposed credentials match your monitored domains or email addresses.

## Sources and access

- [How our data is organized](https://leakradar.io/en/methodology)
- [Trust center](https://leakradar.io/en/trust)
- [Alternatives](https://leakradar.io/en/alternatives)
- [Compare plans](https://leakradar.io/en/#pricing-plans)
