Give GalaxyWarden Signals your vendor list, your portfolio, or your book. The moment one of them files a breach with a US regulator, you get an alert — the filing itself, dated and sourced to the record. Not a leaked dump. Not a rumor.
Illustrative — representative structure, fictional organizations. The live feed is on your key.
The whole product is a workflow you can't rebuild without running the sources yourself: watch, match, alert. You bring the names; we do the rest, and keep doing it.
Your vendors, a portfolio, a book of insureds — 50 to 500 organizations, by self-serve tier. Upload a list or add them as you go.
Entity-matched across name variants, deduped across sources, and corroborated — so one breach is one event, not three, and "Inc." never hides a match.
An alert with the company, the date, what was disclosed, and a link to the official filing — pushed to email, webhook, or your own tools via the API.
US regulators now require public companies to disclose a material cyber incident within days of judging it material, and every state runs its own breach-notification regime underneath. The result is thousands of dated regulatory disclosures a year — real, countable, and scattered across brittle portals nobody wants to run.
Out of every filing across every US regulator, Signals surfaces the ones on your list — confirmed, dated, and sourced — so nothing you watch files a breach without you hearing it first.
There is no general legal duty in the US for a company to notify every business partner, customer, or vendor of a breach. The obligations run in narrower directions — and they routinely miss the counterparties who carry the supply-chain risk.
A public regulatory filing is the independent signal that doesn't wait on the breached company choosing to email you — dated, sourced, and on the public record the day it posts. That patchwork of duties is exactly what makes one monitored feed worth having.
This is general framing to explain the product, not legal advice — specific duties vary by state, sector, and contract.
Every US breach regulator publishes on its own portal, in its own format — and some actively block automated reads. We run the sources that matter and add more, so your team never maintains a scraper.
Material cyber-incident disclosures — every US public company, on the federal record.
Official state regulator notifications — a growing set of US states, added continuously.
The federal known-exploited-in-the-wild record — bundled to corroborate incidents and flag active exploitation.
Carried as labelled, unverified claims — clearly marked, never shown as a confirmed breach.
Each portal is a different format, and several change without notice. Maintaining that collection is a permanent job — which is the point: you license the maintained feed instead of owning the upkeep.
The data is public. The work is running the sources, deduping, entity-matching, and alerting — forever. We own that so your team doesn't.
Email, webhook, or a push into the system your team already lives in. The alert carries the filing, dated and sourced.
Query by organization, filing type, date, data class, or affected count. Wire it straight into your own tooling.
Land the full corpus, then keep it live. Pull on your schedule or take the push feed into your warehouse.
On the licensed tier, a contractual freshness and uptime commitment — not a best-effort side project.
Trust is the whole product, so we're deliberately conservative about what we call a fact.
Every confirmed record links to the official regulatory filing it reproduces — a fair-report posture, not a rumor mill.
Name variants — Corp / Inc / LLC and formatting drift — resolve to one organization, so a match is never missed and a breach is never double-counted.
Leak-site and extortion claims are carried as labelled, unverified — always distinguished from a confirmed regulatory filing, never blurred together.
Absence of a record is not evidence of no breach. We reproduce the public record and make no warranty of completeness.
The category is crowded with breach-adjacent tools — and that is the opening. Each watches a different thing, from a different source, at a very different price. The lane for a confirmed regulatory filing on your own watchlist is empty.
Category costs are indicative estimates drawn from third-party reported ranges, not firm quotes — the point is the shape of the market, not the decimal. Positioning as of 2026. Every price shown on this page is an indicative estimate.
Three self-serve tiers, sized by how much of your third-party world you watch — no sales call, no procurement. Move to a license only when you want to embed the feed in a product of your own.
Monitor up to 50 organizations. Your API key is issued on checkout.
Up to 250 organizations — built for teams whose vendors hold PHI or payment data.
Up to 500 organizations — the whole third-party web, watched.
For platforms, insurers, and data vendors that embed the feed inside their own product.
Only need monitoring for your own team? A self-serve tier is everything you need — no contact required; pick the watchlist size that matches your third-party world. Enterprise is for redistribution only. Every price shown is an indicative estimate, not a firm price. All records are reproduced from public regulatory filings and sourced to the record. GalaxyWarden Signals treats only official regulatory filings as confirmed — leak-site claims are carried as labelled, unverified records, never as a confirmed breach and never as an alert. It does not scan you or remove your personal data. Absence of a record is not evidence a company was not breached.