Compliance Evidence
Demonstrate concrete controls against known compromised passwords to your auditors.
Password breaches · 1 credit per lookup · no monthly fee
How it works
One call, structured answer
Compliance Evidence runs on the password breaches lookup at 1 credit per lookup. Same API key, same JSON shape as every other Encrata lookup.
- k-anonymity: the password never leaves the user's device
- Blocks the exact credentials attackers use in stuffing lists
- 1 credit per check, screen every registration and reset
- A single API call satisfies auditors asking for compromised-password controls
Log every check
Instrument every password event to emit a log entry: timestamp, event type, screening verdict, and the count when found. Route the stream into your SIEM or evidence store, and the control documents itself, no quarterly evidence-gathering scramble, just a query that returns the audit trail on demand.
Audits closed in a sentence
Auditors distinguish between controls that exist and controls that demonstrably operate: the log stream proves operation continuously. When the assessor asks how you prevent compromised credentials, the answer is one sentence and one query, 'every password event is screened against known breach corpora; here are this quarter's checks.'