Confirmed breach intelligence, the moment it’s filed.
Every US data-breach notification filed with a state Attorney General — structured, dated, and queryable. Not a credential dump, not an extortion crew’s claim: the regulatory record itself.
Confirmed filings from CA · OR · VT · WA · MA — current to within days.
Illustrative — representative structure, fictional organisations.
A regulatory record, not a credential dump.
Most “breach data” is either a pile of leaked credentials or an extortion crew’s leak-site post. Signals is neither: it is the notification a company was legally required to file, reproduced from the public record and sourced to the filing.
Signals Confirmed filings
Official state-AG and SEC 8-K disclosures. Structured fields, a filing date, an affected count, and a link to the source record. Every row attributable.
Elsewhere Dumps & rumour
Leaked credential collections and unverified extortion listings — noisy, unattributable, and legally fraught to resell. A different question from “who filed.”
Built to sit inside your stack.
JSON API
Bearer-key REST endpoint. Query by organisation, state, date, data class, or affected count.
Watchlist alerts
Register the entities you care about — a portfolio, a vendor list — and hear the moment one files.
Current to days
Ingested daily from the source portals, not a quarterly CSV. New filings land within days of posting.
Sourced & dated
Every record attributes the exact AG filing and date. Accurate reproduction of the public record — corrections honoured.
Structured fields
Organisation, state, filing & breach dates, affected count, data classes — normalised, not raw HTML.
Bulk & query
Backfill the corpus, then keep it live. Pull on your schedule; filter to only what you watch.
# confirmed filings for organisations on your watchlist curl "https://www.galaxywarden.com/api/signals/v1/breaches?organization=northwind" \ -H "Authorization: Bearer sk_live_…" # -> every record sourced to its official filing { "organization": "Northwind Logistics, Inc.", "disclosed_date": "2026-08-21", "data_exposed": ["name", "ssn"], "regulatory": { "as_reported": "California AG filing" }, "corroborated": true }
For the teams that price and monitor risk.
Cyber underwriters & claims
Confirmed incident data with affected counts, for pricing renewals and validating claims against the public record.
Third-party & vendor risk
Watch a portfolio of suppliers and hear the moment one files a breach — before it reaches you through the news.
Threat & security intelligence
A confirmed, structured signal to corroborate against leak-site noise and enrich your own incident feeds.
Buy a key. Query in minutes.
Subscribe and your API token is issued on checkout — no sales call for self-serve. Scale to a licence when you need volume or redistribution.
Full API access for one team’s internal use, live in minutes.
- API token issued on checkout
- Every confirmed filing — CA · OR · VT · WA · MA, plus SEC 8-K
- Full record: filing & breach dates, affected count, data classes, source link
- JSON API + bearer key — query any field
- Watchlist alerts on the names you track
For teams that build the feed into their own product — insurers, platforms and data vendors.
- Redistribution & embedding rights — resell it inside your product
- High-volume & full-corpus bulk access
- Uptime & freshness SLA, in writing
- Custom delivery — push feed, warehouse, webhook
- Named contact, contract & security review
Self-serve is licensed for your team’s internal use. Redistribution or embedding is the Enterprise licence, quoted per engagement. All data is reproduced from public regulatory filings and attributed to source.
Included: SEC EDGAR Form 8-K Item 1.05 filings, tracked daily; state Attorney-General breach-notification filings; CC BY-licensed breach-catalogue records; and our own work joining a filing back to any earlier record we already held for that organisation.
Included, as claims: ransomware leak-site listings. We carry them from CC BY-licensed sources we may actually sell from, with credit, and they are in the paid feed. They are unverified criminal claims, so they are labelled corroborated: false, they are excluded from /breaches unless you pass corroborated_only=0, and they never trigger an alert. An alert still means a filing or an official disclosure.
Absence of a record is not evidence that no breach occurred. This is the filed public record, not a claim by us that any company was breached.