Every breach.
Every angle.
Every formally-filed breach disclosure — SEC 8-K, 18 US state AGs, HHS OCR, EU DPAs, ransomware leak sites — extracted into one schema, one feed. Filter and pivot across severity, industry, threat-actor tactics, and compliance timelines.
Compliance officers, underwriters, breach counsel, and security researchers run on the same canonical record — the patterns individual regulator portals don't show you, surfaced.
casework — $449/month after a 14-day free trial. Cancel any time; the record itself stays free to read.

On March 12, 2024, MarineMax told the SEC it had been breached — and that it “does not maintain sensitive data” in the affected environment. Three weeks later an amended 8-K confirmed a cybercrime group had exfiltrated customer and employee personal information. Neither filing gave a number. 92% of SEC 8-K cyber filings omit it. The count came four months after the leak-site post, in state AG notices — and only by reading all three sources together do you get the incident.
Built for the analyst the portals didn't plan for
In our corpus, 92% of SEC 8-K cyber filings omit the number of people affected — and 99% of SEC cyber filings overall do. State notices carry the counts and data types the 8-K leaves out. Both views, merged.
In our corpus, leak-site posts precede regulatory filings in roughly 9 of 10 cross-linked incidents, and where both exist for one incident the filing follows the criminal post by a median of 107 days. DisclosureLens correlates both feeds and computes the gap on every record.
SEC 4-day, HIPAA 60-day, GDPR 72-hour, plus the state-AG clocks. Elapsed days computed against each statute — one overdue-clock summary per record, verbatim citation one click away.
Per-entity compliance scorecard — totals, per-jurisdiction flags, severity-weighted score, clocks-missed timeline. Downloadable as a signed PDF for audit packets.
Vertical × severity heatmap, repeat-offender index, FAIR-aligned notification-exposure fit per industry. comparable_incidents, underwriting_brief, freq_severity_curve under /v1/analytics.
Every scorecard, compliance report, broker letter, and incident evidence package is PAdES-B signed with byte-range tamper detection + cert fingerprint in the footer. EU AI Act Art. 50 disclosure on every page.
Inside a real package →Enough to build on
Full changelog →Push delivery, a sync cursor, bulk export and a public schema — the pieces you need to keep your own copy current without scraping ours.
Register an endpoint and get a signed POST when a matching record lands, instead of polling for it. Three endpoints on the free tier; the signing secret is derived rather than stored, so you can look it up again instead of losing it.
Read more →/v1/incidents now takes updated_after with a cursor, matching what /v1/disclosures already offered. Mirror the corpus by storing the updated_at of the last row you wrote and passing it back — filing dates lag ingestion by months for archive-backfilled sources, so they never worked as a sync cursor.
Read more →Streaming NDJSON of the full corpus, open to every signed-up account at four runs a UTC day. It was briefly paid-tier only; that gate is gone.
Read more →Built for
Per-framework clock tracking, late-disclosure leaderboards, signed compliance reports.
Open →Frequency × severity heatmap, repeat-offender index, benchmark letters. Pre-fills underwriting submissions.
Open →Entity-keyed five-year scorecard, named-entity treatment per Fair Report Privilege, signed PDF.
Open →Near-real-time feed, 20+ facets, OpenAPI schema, free tier — full corpus history, no card.
Open →Feed News
When a regulator takes a feed offline, relocates it, or restores it, we report it — and keep a live status on every source we collect.
Every US breach-notification deadline runs from the day the organization discovered the incident — but a notification letter routinely dates three different events: the attack, the first alarm, and what the investigation later found. We audited the discovery date behind 32,572 filings. Where a state collects it as a form field, it is exact — 3,781 of 3,781 re-checked against the source. Where it must be read out of letter prose, roughly one date in eight is the wrong event entirely, and the errors are not small: the corrections we applied moved dates by a median of 92 days, three times the length of a typical 30-day notification window.
Read the report →Illinois runs a live breach-notification register — 5,319 records and growing by nearly a thousand a year — behind a wall that turns away every crawler, archive, and AI on the internet. A person can read it. A machine cannot. We obtained the register; here is what's inside.
Read the report →We followed every US organization posted on a ransomware leak site in 2024 — 3,106 criminal claims naming 2,747 organizations — into the regulatory record. More than four out of five never appeared in the channels we observe, and where a claim and a filing are linked to the same incident, the filing followed the criminal post by a median of 107 days.
Read the report →Ransomware gangs published more victims in the first half of 2026 than in any half-year on record — 4,993 organizations. For the first time in our measured record, America contributed none of the growth.
Read the report →In HHS's own tickboxes, breaches reported as theft, loss or improper disposal fell from 159 in 2010 to 12 in 2025 — a 92% collapse while the register itself more than quadrupled. Devices reported stolen, lost or improperly disposed of fell 94%. Paper fell too, on the same breach types, but less, and by 2025 the two were level: the last physical thing in a healthcare breach is now as likely to be a folder as a laptop. Some of that is a change in what gets stolen. Some of it is a change in what the law requires anyone to report at all.
Read the report →Washington law gives a breached organization 30 days to tell the Attorney General. Alone among the breach registries we track, Washington also publishes the arithmetic — a days-elapsed column on 1,606 of the 1,629 notices it has received. Read against the state's own deadline, 82.6% of notices for breaches discovered under the 30-day rule arrived late, and the median took 77 days. In 2024, the Attorney General proposed cutting the deadline to three days — a bar the state's own record shows has been met six times since the rule took effect.
Read the report →
Maine's attorney general pulled the nation's most-cited breach registry offline after two hoax filings. Six weeks on, it's still dark — and our complete 5,913-record copy is preserved.
Read the report →A zone-wide Cloudflare challenge locked every automated reader out of Montana's breach portal in June. Six weeks later we cleared it with a stealth browser — and never lost a filing.
Read the report →Hawaii's public breach registry quietly shrank from 138 rows to 55, dropping years of older notices while the live feed kept reading healthy. We recovered the 84 filings it erased — several now survive in the open only in our copy.
Read the report →Even after cross-source enrichment, the HIPAA 60-day clock is fully computable for under 2% of OCR filings — and where it is, nearly half ran late. And corpus-wide, when an entity is breached again, about 4 in 10 re-breaches land within 90 days of the first. Observed in corpus, not a forecast; figures shift as sources are added.
High-stakes fields carry their own escalation thresholds — threat-actor and malware attribution at 0.85, affected counts and industry tags at 0.66 — and a below-threshold field triggers a harder second extraction pass before publication. Named attributions additionally face an adversarial verify pass. Per-field confidence scores on every record.
meta.ai_assisted: true on every API response and PDF footer. EU AI Act Art. 50-compliant ahead of the Aug 2, 2026 enforcement date.
If DisclosureLens has a material security incident, the disclosure lands in our own feed with source.type = self_disclosure and a 14-day post-mortem.
Free for journalists, researchers, and security teams
Full dashboard · full corpus history · no credit card. Attribution requested when republished. Signing in adds an API key, 3 watched entities, 3 saved filters and a daily bulk NDJSON export — all free. The dashboard itself is never rate-limited for reading; the free API key is 5 req/min, a taste rather than a feed. Signed PDF deliverables (scorecards, benchmark letters, incident evidence packages) sit in the paid tier.