Know the day a company you watch files a breach.

Give GalaxyWarden Signals your vendor list, your portfolio, or your book. The moment one of them files a breach with a US regulator, you get an alert — the filing itself, dated and sourced to the record. Not a leaked dump. Not a rumor.

Start monitoring — $499/mo See a live filing ↓ API key issued on checkout — no sales call.
signals · confirmed filings LIVE
OrganizationFilingDateAffectedStatus

Illustrative — representative structure, fictional organizations. The live feed is on your key.

Point it at a list. Get the filing, not the rumor.

The whole product is a workflow you can't rebuild without running the sources yourself: watch, match, alert. You bring the names; we do the rest, and keep doing it.

01 — WATCH

Add the organizations you watch

Your vendors, a portfolio, a book of insureds — 50 to 500 organizations, by self-serve tier. Upload a list or add them as you go.

watchlist: portfolio-a
+ 342 organizations
02 — MATCH

We match every new filing to your list

Entity-matched across name variants, deduped across sources, and corroborated — so one breach is one event, not three, and "Inc." never hides a match.

"Northwind Logistics Inc."
→ Northwind Logistics ✓ matched
03 — ALERT

You hear the moment one files

An alert with the company, the date, what was disclosed, and a link to the official filing — pushed to email, webhook, or your own tools via the API.

alert → Cedar Ridge Clinics
filing on record · confirmed

Breaches turned into dated, public events.

US regulators now require public companies to disclose a material cyber incident within days of judging it material, and every state runs its own breach-notification regime underneath. The result is thousands of dated regulatory disclosures a year — real, countable, and scattered across brittle portals nobody wants to run.

4 days
The clock a public company is on to disclose a cyber incident once it is judged material.
US federal disclosure rule, since late 2023
3,322
US data compromises tracked in 2025 — a record, and climbing year over year.
Identity Theft Resource Center, 2025
~50
Separate state and federal breach regimes feed the same record — the fragmentation that is the moat.
GalaxyWarden coverage

The one alert that's about your vendor, on the day it matters.

Out of every filing across every US regulator, Signals surfaces the ones on your list — confirmed, dated, and sourced — so nothing you watch files a breach without you hearing it first.

No one is required to tell you.

There is no general legal duty in the US for a company to notify every business partner, customer, or vendor of a breach. The obligations run in narrower directions — and they routinely miss the counterparties who carry the supply-chain risk.

One place for filings that live in fifty.

Every US breach regulator publishes on its own portal, in its own format — and some actively block automated reads. We run the sources that matter and add more, so your team never maintains a scraper.

FED

Federal securities filings

Material cyber-incident disclosures — every US public company, on the federal record.

Live
ST

State breach-notification filings

Official state regulator notifications — a growing set of US states, added continuously.

Live · expanding
VLN

Exploited-vulnerability catalog

The federal known-exploited-in-the-wild record — bundled to corroborate incidents and flag active exploitation.

Live
RW

Ransomware leak-site listings

Carried as labelled, unverified claims — clearly marked, never shown as a confirmed breach.

Labelled

Each portal is a different format, and several change without notice. Maintaining that collection is a permanent job — which is the point: you license the maintained feed instead of owning the upkeep.

Managed end to end. Nothing for you to build.

The data is public. The work is running the sources, deduping, entity-matching, and alerting — forever. We own that so your team doesn't.

pushAlerts where you work

Email, webhook, or a push into the system your team already lives in. The alert carries the filing, dated and sourced.

apiJSON API + bearer key

Query by organization, filing type, date, data class, or affected count. Wire it straight into your own tooling.

bulkWarehouse & backfill

Land the full corpus, then keep it live. Pull on your schedule or take the push feed into your warehouse.

slaFreshness & uptime SLA

On the licensed tier, a contractual freshness and uptime commitment — not a best-effort side project.

Confirmed is confirmed. Claimed is labelled.

Trust is the whole product, so we're deliberately conservative about what we call a fact.

Sourced to the record

Every confirmed record links to the official regulatory filing it reproduces — a fair-report posture, not a rumor mill.

Entity-matched

Name variants — Corp / Inc / LLC and formatting drift — resolve to one organization, so a match is never missed and a breach is never double-counted.

Labelled vs confirmed

Leak-site and extortion claims are carried as labelled, unverified — always distinguished from a confirmed regulatory filing, never blurred together.

Honest about limits

Absence of a record is not evidence of no breach. We reproduce the public record and make no warranty of completeness.

Everyone adjacent answers a different question.

The category is crowded with breach-adjacent tools — and that is the opening. Each watches a different thing, from a different source, at a very different price. The lane for a confirmed regulatory filing on your own watchlist is empty.

CategoryWhat it watchesIndicative cost / yrFiling on your watchlist?
Credential-leak monitorsLeaked passwords tied to an address or domain you ownFree to low thousandsNo
Security-ratings vendorsAn outside-in posture score inferred from internet scans~$16k–150kNo
Threat-intel & dark-web feedsUnderground chatter and unverified actor claims~$25k–500kNo
Vendor-risk suitesQuestionnaires with bundled breach history~$19k–75kNo
Filing watchersAny regulatory filing — not breach-specific~$80–300No
GalaxyWarden SignalsThe confirmed breach filing for the organizations on your listSelf-serve tier / licenseYes

Category costs are indicative estimates drawn from third-party reported ranges, not firm quotes — the point is the shape of the market, not the decimal. Positioning as of 2026. Every price shown on this page is an indicative estimate.

Buy a key. Start in minutes.

Three self-serve tiers, sized by how much of your third-party world you watch — no sales call, no procurement. Move to a license only when you want to embed the feed in a product of your own.

StarterSelf-serve
$4,990 / year
$416/mo billed annually · 2 months free · cancel anytime
Indicative estimate
up to 50 organizations

Monitor up to 50 organizations. Your API key is issued on checkout.

  • API key issued instantly on checkout
  • Watchlist alerts on up to 50 organizations
  • Full record — filing type, date, affected count, data classes, source link
  • Federal + state filings, updated daily
  • JSON API + bearer key — query any field
ProfessionalFor regulated ecosystems
$9,990 / year
$832/mo billed annually · 2 months free · cancel anytime
Indicative estimate
up to 250 organizations

Up to 250 organizations — built for teams whose vendors hold PHI or payment data.

  • Everything in Starter, to 250 organizations
  • Priority support
  • Coverage-degradation notices when a source goes dark
  • Full record + JSON API, updated daily
EcosystemFull breadth
$19,990 / year
$1,666/mo billed annually · 2 months free · cancel anytime
Indicative estimate
up to 500 organizations

Up to 500 organizations — the whole third-party web, watched.

  • Everything in Professional, to 500 organizations
  • The long tail: sub-processors, print/mail houses, adjudication vendors
  • Full record + JSON API, updated daily
EnterpriseLicensed
From ~$24k / year
Per engagement · volume, SLA & delivery scoped to you
Indicative estimate

For platforms, insurers, and data vendors that embed the feed inside their own product.

  • Redistribution & embedding rights — resell inside your product
  • Full-corpus & high-volume access
  • Contractual uptime & freshness SLA
  • Custom delivery — push, webhook, warehouse
  • Named contact, contract & security review
Talk to us

Only need monitoring for your own team? A self-serve tier is everything you need — no contact required; pick the watchlist size that matches your third-party world. Enterprise is for redistribution only. Every price shown is an indicative estimate, not a firm price. All records are reproduced from public regulatory filings and sourced to the record. GalaxyWarden Signals treats only official regulatory filings as confirmed — leak-site claims are carried as labelled, unverified records, never as a confirmed breach and never as an alert. It does not scan you or remove your personal data. Absence of a record is not evidence a company was not breached.