Oscuro data handling
Exposure monitoring means letting a vendor hold records about your staff that came out of criminal breaches. This page says what Keel holds, what it refuses to hold, and how long it keeps it.
What Oscuro stores
Section titled “What Oscuro stores”The fact that an identity under a domain you verified appears in a source Keel is licensed to read. In practice that is the identity as the source reported it, the source name, the breach or leak-site name, the date it happened, the source’s own data-class labels, a severity, and a single flag saying whether the source states a password was exposed in plaintext.
What Oscuro refuses to store
Section titled “What Oscuro refuses to store”No password. No password hash. No session token or cookie. No raw breach record, no stealer-log line, no fetched page body, no image.
The database has no column for any of them, so this is the shape of the product and not a setting somebody can flip.
Keel also never tests a discovered credential against a live system, including yours, and never opens accounts on leak sites or forums, posts or messages there, or buys data.
Where the data comes from
Section titled “Where the data comes from”Two licensed sources. Breach, stealer-log and paste coverage comes from Have I Been Pwned’s domain search, whose licence is one of the reasons DNS verification is mandatory. Ransomware leak-site coverage uses data published by RansomLook, licensed under CC BY 4.0, and that attribution appears wherever a finding from it is shown.
How long it is kept
Section titled “How long it is kept”| Record | Kept |
|---|---|
| Open finding | Until you close it |
| Closed finding | 24 months from the date it closed |
| Finding under a domain you removed | 90 days from the removal |
| What was in scope, and when | 7 years |
Deleting a finding does not break the evidence it filed. That evidence never carried the person’s identity: it records that a finding was closed, when, and by what action.
Who is the controller
Section titled “Who is the controller”You are. Oscuro monitors domains you chose, for identities belonging to your organisation, and you decide what is watched and when a finding is deleted. Keel processes it for you.
Two consequences follow.
A request from one of your people comes to you. If someone asks what is held about them or
asks for it to be deleted, you can answer from the app, and Keel will help if the request
reaches us at privacy@keelgrc.com instead.
Telling your staff is your job. Keel has no relationship with the people in a finding, and emailing them would be a disclosure in itself. Monitoring your own domain is a normal thing for a security function to do, and putting it in your privacy notice is what makes it unsurprising to the people it covers.