DisclosureLens
Pivot across every regulator's breach feed

Every breach.
Every angle.

Every formally-filed breach disclosure — SEC 8-K, 18 US state AGs, HHS OCR, EU DPAs, ransomware leak sites — extracted into one schema, one feed. Filter and pivot across severity, industry, threat-actor tactics, and compliance timelines.

Compliance officers, underwriters, breach counsel, and security researchers run on the same canonical record — the patterns individual regulator portals don't show you, surfaced.

casework — $449/month after a 14-day free trial. Cancel any time; the record itself stays free to read.

DisclosureLens — breach intelligence
LIVE FEEDwhat regulators reported · last 30 daysopen analytics →
Indexed · 30d
353
Daily run-rate
11.8
Top source
State AG 95%
MediumVirta Health Corp. and Virta Medical, PCTX AG · 606 affected · Identity (basic), Government IDHighBIMBO BAKERIES USA, INC.TX AG · 3,982 affected · Financial account, Identity (basic)MediumBIMBO BAKERIES USA, INC.CA AG · Government ID, Identity (basic)
28 sources reporting in the last 30 days · coverage growing weekly
Why one source isn't enough

On March 12, 2024, MarineMax told the SEC it had been breached — and that it “does not maintain sensitive data” in the affected environment. Three weeks later an amended 8-K confirmed a cybercrime group had exfiltrated customer and employee personal information. Neither filing gave a number. 92% of SEC 8-K cyber filings omit it. The count came four months after the leak-site post, in state AG notices — and only by reading all three sources together do you get the incident.

Leak postday 0 · rhysida
SEC 8-Kday 2 · no count
State AGday 128 · the count
Six patterns the regulator portals don't show you

Built for the analyst the portals didn't plan for

Information asymmetry
SEC tells investors almost nothing

In our corpus, 92% of SEC 8-K cyber filings omit the number of people affected — and 99% of SEC cyber filings overall do. State notices carry the counts and data types the 8-K leaves out. Both views, merged.

Early warning
Leak sites post months before regulators

In our corpus, leak-site posts precede regulatory filings in roughly 9 of 10 cross-linked incidents, and where both exist for one incident the filing follows the criminal post by a median of 107 days. DisclosureLens correlates both feeds and computes the gap on every record.

Compliance clocks
Filed late · 15 frameworks, one view

SEC 4-day, HIPAA 60-day, GDPR 72-hour, plus the state-AG clocks. Elapsed days computed against each statute — one overdue-clock summary per record, verbatim citation one click away.

Entity scorecards
Five-year breach record for any entity

Per-entity compliance scorecard — totals, per-jurisdiction flags, severity-weighted score, clocks-missed timeline. Downloadable as a signed PDF for audit packets.

Risk analytics
Frequency × severity, per-vertical

Vertical × severity heatmap, repeat-offender index, FAIR-aligned notification-exposure fit per industry. comparable_incidents, underwriting_brief, freq_severity_curve under /v1/analytics.

Audit-grade PDFs
PAdES-B signed, tamper-evident

Every scorecard, compliance report, broker letter, and incident evidence package is PAdES-B signed with byte-range tamper detection + cert fingerprint in the footer. EU AI Act Art. 50 disclosure on every page.

Inside a real package →
Recently shipped

Enough to build on

Full changelog →

Push delivery, a sync cursor, bulk export and a public schema — the pieces you need to keep your own copy current without scraping ours.

Four audiences, one schema

Built for

Journalists — see the per-state pages at /breach-notifications. Free dashboard tier, no credit card.
We track the sources, not just the records

Feed News

When a regulator takes a feed offline, relocates it, or restores it, we report it — and keep a live status on every source we collect.

ResearchThe Discovery-Date Audit · 2026
The Breach Letter Has Three Dates. The Law's Clock Runs on One. We Audited Which One Gets Filed.

Every US breach-notification deadline runs from the day the organization discovered the incident — but a notification letter routinely dates three different events: the attack, the first alarm, and what the investigation later found. We audited the discovery date behind 32,572 filings. Where a state collects it as a form field, it is exact — 3,781 of 3,781 re-checked against the source. Where it must be read out of letter prose, roughly one date in eight is the wrong event entirely, and the errors are not small: the corrections we applied moved dates by a median of 92 days, three times the length of a typical 30-day notification window.

Read the report →
WatchFeed status · Illinois AG
Illinois Keeps a 5,300-Record Breach Register. No Search Engine Has Ever Seen It.

Illinois runs a live breach-notification register — 5,319 records and growing by nearly a thousand a year — behind a wall that turns away every crawler, archive, and AI on the internet. A person can read it. A machine cannot. We obtained the register; here is what's inside.

Read the report →
ResearchThe Silent Majority · 2024 cohort
The Silent Majority: What Happens After Ransomware Gangs Name a Company

We followed every US organization posted on a ransomware leak site in 2024 — 3,106 criminal claims naming 2,747 organizations — into the regulatory record. More than four out of five never appeared in the channels we observe, and where a claim and a filing are linked to the same incident, the filing followed the criminal post by a median of 107 days.

Read the report →
ResearchState of Breach Disclosure · H1 2026
H1 2026 State of Breach Disclosure: A Record Half the US Didn't Drive

Ransomware gangs published more victims in the first half of 2026 than in any half-year on record — 4,993 organizations. For the first time in our measured record, America contributed none of the growth.

Read the report →
ResearchThe Federal Breach Log · 2010–2025
The Stolen Laptop Has Almost Disappeared From America's Healthcare Breach Log

In HHS's own tickboxes, breaches reported as theft, loss or improper disposal fell from 159 in 2010 to 12 in 2025 — a 92% collapse while the register itself more than quadrupled. Devices reported stolen, lost or improperly disposed of fell 94%. Paper fell too, on the same breach types, but less, and by 2025 the two were level: the last physical thing in a healthcare breach is now as likely to be a folder as a laptop. Some of that is a change in what gets stolen. Some of it is a change in what the law requires anyone to report at all.

Read the report →
ResearchThe Washington Clock · 2020–2026
The Washington Clock: The State Published the Deadline Data. We Read It.

Washington law gives a breached organization 30 days to tell the Attorney General. Alone among the breach registries we track, Washington also publishes the arithmetic — a days-elapsed column on 1,606 of the 1,629 notices it has received. Read against the state's own deadline, 82.6% of notices for breaches discovered under the 30-day rule arrived late, and the median took 77 days. In 2024, the Attorney General proposed cutting the deadline to three days — a bar the state's own record shows has been met six times since the rule took effect.

Read the report →
DarkFeed status · Maine AG
Someone Faked a Discord Breach. Maine Turned Off America's Best Breach Database.

Maine's attorney general pulled the nation's most-cited breach registry offline after two hoax filings. Six weeks on, it's still dark — and our complete 5,913-record copy is preserved.

Read the report →
RestoredFeed status · Montana AG
Montana's Breach Feed Vanished Behind a Bot Wall for Six Weeks. It's Back.

A zone-wide Cloudflare challenge locked every automated reader out of Montana's breach portal in June. Six weeks later we cleared it with a stealth browser — and never lost a filing.

Read the report →
WatchFeed status · Hawaii OCP
Hawaii's Breach List Keeps Getting Shorter. We Saved the Notices It Deleted.

Hawaii's public breach registry quietly shrank from 138 rows to 55, dropping years of older notices while the live feed kept reading healthy. We recovered the 84 filings it erased — several now survive in the open only in our copy.

Read the report →
What cross-source data reveals

Even after cross-source enrichment, the HIPAA 60-day clock is fully computable for under 2% of OCR filings — and where it is, nearly half ran late. And corpus-wide, when an entity is breached again, about 4 in 10 re-breaches land within 90 days of the first. Observed in corpus, not a forecast; figures shift as sources are added.

When extraction confidence dips, we read it again

High-stakes fields carry their own escalation thresholds — threat-actor and malware attribution at 0.85, affected counts and industry tags at 0.66 — and a below-threshold field triggers a harder second extraction pass before publication. Named attributions additionally face an adversarial verify pass. Per-field confidence scores on every record.

Disclosure-aware AI

meta.ai_assisted: true on every API response and PDF footer. EU AI Act Art. 50-compliant ahead of the Aug 2, 2026 enforcement date.

Held to the standard we hold regulators to

If DisclosureLens has a material security incident, the disclosure lands in our own feed with source.type = self_disclosure and a 14-day post-mortem.

Free for the public interest

Free for journalists, researchers, and security teams

Full dashboard · full corpus history · no credit card. Attribution requested when republished. Signing in adds an API key, 3 watched entities, 3 saved filters and a daily bulk NDJSON export — all free. The dashboard itself is never rate-limited for reading; the free API key is 5 req/min, a taste rather than a feed. Signed PDF deliverables (scorecards, benchmark letters, incident evidence packages) sit in the paid tier.

Get an API key