The Domain Exposure API summarizes credential exposure associated with a domain over the previous 12 months.
The report combines two types of compromised credential data:
It also distinguishes between two types of exposure:
For example, a compromised @example.com employee account would contribute to employee exposure. A compromised Gmail user whose infostealer log contains credentials for example.com would contribute to client exposure.
The API returns aggregated statistics rather than individual credentials or personally identifiable information.