Security Audits
Measure how many employees are using exposed passwords across the whole organization.
Password breaches · 1 credit per lookup · no monthly fee
How it works
One call, structured answer
Security Audits runs on the password breaches lookup at 1 credit per lookup. Same API key, same JSON shape as every other Encrata lookup.
- k-anonymity: the password never leaves the user's device
- Blocks the exact credentials attackers use in stuffing lists
- 1 credit per check, screen every registration and reset
- A single API call satisfies auditors asking for compromised-password controls
Audit with bulk checks
Run the audit with the bulk endpoint: hash the workforce's passwords via your IdP or directory export, submit the hashes, and compute the exposure rate. De-duplication is built in, so shared passwords surface as an additional finding. Keep the raw results access-controlled, the aggregate is for the report, the individual hits are for remediation.
A number that moves budgets
The number transforms the conversation: 'twelve percent of staff use breached passwords' is a budget line, a training mandate and a policy change rolled into one finding. Re-run quarterly and the trend becomes the KPI, a falling exposure rate is one of the few security metrics that's simultaneously honest, measurable and board-legible.