Trust, verified.

No cherry-picked testimonials. No "Featured in" banners we bought. Instead: what DoxxScan actually does, what it sees, and what it keeps — in full, inspectable detail. Last updated 2026-04-24.

How DoxxScan actually works

When you enter an email, username, phone, or name, DoxxScan queries four independent breach-intelligence datasets — Have I Been Pwned, DeHashed (V2 API), and two internal indexes aggregated from public paste dumps and disclosed breach corpora. Every match is hashed client-side before the lookup key is sent. The result is progressive: an email match can reveal usernames, a username match can reveal passwords, a password can reveal linked accounts. We call this the DoxxScan Chain; our /compare page walks through how it differs from yes/no breach checkers.

By the numbers

These are the numbers we publish on marketing pages, here in one audit-ready place:

15B+
Breach records indexed across HIBP + DeHashed + internal corpora
700+
Distinct breach sources monitored
95+
Platforms our chain discovery covers
100+
Data-broker sites tracked for opt-out
<5s
Median scan time for email + username entry
7
Average exposed accounts our users do not know about before scanning

What we store, what we do not

We store, for your account:

Your email (verified), scan history (which credentials you chose to scan — not the credentials themselves), risk scores, and remediation progress. That is enough to keep your dashboard working across sessions.

We do not store — ever:

Plaintext passwords from any breach. Social Security numbers, IDs, or financial account numbers. Your scan queries after the report is rendered. We show you passwords that appeared in public breach corpora so you can remediate them, then drop them from our result cache.

Security disclosure

If you find a vulnerability, we want to hear from you. Full disclosure policy, scope, out-of-scope list, and hall of fame: /security. Machine-readable contact: /security.txt (RFC 9116). Reach us directly at support@galaxywarden.com. Researchers acting in good faith will not be pursued under the CFAA for actions covered by our disclosure scope. Our official-domain verification page is at /doxxscan/trust.

Responsible-disclosure friendly No-CFAA-against-researchers pledge security.txt published

Names you will see

Anti-doxxing products have a naming problem because security is full of jargon. Our conventions:

Who is behind this

BATech LLC, operating since 2018 — first as a penetration-testing consultancy, now building DoxxScan and GalaxyWarden. Registered domain galaxywarden.com. Contact: support@galaxywarden.com. Mailing address on request; we do not publish it here because, as an anti-doxxing company, we practice what we preach.

Read more about the team at /about.

This page is updated whenever something on it changes. See our deploy rhythm for release cadence.

Start Free Trial
Built by the same team that secures Fortune 500 and Inc. 500 companies. · 15B+ breach records · 95+ platforms monitored · 8 years in cybersecurity · Zero data sales, ever.
Chat
W
AI Assistant DoxxScan
Checking...
Hey! I'm the DoxxScan AI Assistant. Got questions about your scan or cybersecurity? I'm here to help right away. A human teammate reviews every chat and may follow up by email — usually within 24 hours.