Skip to content

Oscuro data handling

Exposure monitoring means letting a vendor hold records about your staff that came out of criminal breaches. This page says what Keel holds, what it refuses to hold, and how long it keeps it.

The fact that an identity under a domain you verified appears in a source Keel is licensed to read. In practice that is the identity as the source reported it, the source name, the breach or leak-site name, the date it happened, the source’s own data-class labels, a severity, and a single flag saying whether the source states a password was exposed in plaintext.

No password. No password hash. No session token or cookie. No raw breach record, no stealer-log line, no fetched page body, no image.

The database has no column for any of them, so this is the shape of the product and not a setting somebody can flip.

Keel also never tests a discovered credential against a live system, including yours, and never opens accounts on leak sites or forums, posts or messages there, or buys data.

Two licensed sources. Breach, stealer-log and paste coverage comes from Have I Been Pwned’s domain search, whose licence is one of the reasons DNS verification is mandatory. Ransomware leak-site coverage uses data published by RansomLook, licensed under CC BY 4.0, and that attribution appears wherever a finding from it is shown.

Record Kept
Open finding Until you close it
Closed finding 24 months from the date it closed
Finding under a domain you removed 90 days from the removal
What was in scope, and when 7 years

Deleting a finding does not break the evidence it filed. That evidence never carried the person’s identity: it records that a finding was closed, when, and by what action.

You are. Oscuro monitors domains you chose, for identities belonging to your organisation, and you decide what is watched and when a finding is deleted. Keel processes it for you.

Two consequences follow.

A request from one of your people comes to you. If someone asks what is held about them or asks for it to be deleted, you can answer from the app, and Keel will help if the request reaches us at privacy@keelgrc.com instead.

Telling your staff is your job. Keel has no relationship with the people in a finding, and emailing them would be a disclosure in itself. Monitoring your own domain is a normal thing for a security function to do, and putting it in your privacy notice is what makes it unsurprising to the people it covers.