Every formally-filed breach disclosure — SEC 8-K, 17 US state AGs, HHS OCR, EU DPAs, ransomware leak sites — extracted into one schema, one feed. Filter and pivot across severity, industry, threat-actor tactics, and compliance timelines.
Compliance officers, underwriters, breach counsel, and security researchers run on the same canonical record — the patterns individual regulator portals don't show you, surfaced.

An SEC filing told investors a breach happened — but omitted the number affected and the data types exposed. 92% of SEC 8-K cyber filings do. The same week, a state AG filing disclosed 2.5 million Social Security numbers were compromised. A ransomware leak site had posted about it 91 days earlier. DisclosureLens merges all three into one record — the full story, not the slice each regulator got.
In our corpus, 92% of SEC 8-K cyber filings omit the number of people affected — and 99% of SEC cyber filings overall do. State notices carry the counts and data types the 8-K leaves out. Both views, merged.
In our corpus, leak-site posts precede regulatory filings in roughly 9 of 10 cross-linked incidents, with a typical lead of about three months. DisclosureLens correlates both feeds and computes the gap on every record.
SEC 4-day, HIPAA 60-day, GDPR 72-hour, plus the state-AG clocks. Elapsed days computed against each statute — one overdue-clock summary per record, verbatim citation one click away.
Per-entity compliance scorecard — totals, per-jurisdiction flags, severity-weighted score, clocks-missed timeline. Downloadable as a signed PDF for audit packets.
Vertical × severity heatmap, repeat-offender index, FAIR-aligned severity fit per industry. comparable_incidents, underwriting_brief, freq_severity_curve under /v1/analytics.
Every scorecard, compliance report, and broker letter is PAdES-B signed with byte-range tamper detection + cert fingerprint in the footer. EU AI Act Art. 50 disclosure on every page.
Per-framework clock tracking, late-disclosure leaderboards, signed compliance reports.
Open →Frequency × severity heatmap, repeat-offender index, benchmark letters. Pre-fills underwriting submissions.
Open →Entity-keyed five-year scorecard, named-entity treatment per Fair Report Privilege, signed PDF.
Open →Near-real-time feed, 20+ facets, OpenAPI schema, free tier — 60 req/min, full corpus history.
Open →When a regulator takes a feed offline, relocates it, or restores it, we report it — and keep a live status on every source we collect.
Ransomware gangs published more victims in the first half of 2026 than in any half-year on record — 4,993 organizations. For the first time, America contributed none of the growth.
Read the report →
Maine's attorney general pulled the nation's most-cited breach registry offline after two hoax filings. Six weeks on, it's still dark — and our complete 5,913-record copy is preserved.
Read the report →A zone-wide Cloudflare challenge locked every automated reader out of Montana's breach portal in June. Six weeks later we cleared it with a stealth browser — and never lost a filing.
Read the report →Hawaii's public breach registry quietly shrank from 138 rows to 55, dropping years of older notices while the live feed kept reading healthy. We recovered the 84 filings it erased — several now survive in the open only in our copy.
Read the report →Even after cross-source enrichment, the HIPAA 60-day clock is fully computable for under 2% of OCR filings — and where it is, nearly half ran late. And corpus-wide, when an entity is breached again, about 4 in 10 re-breaches land within 90 days of the first. Observed in corpus, not a forecast; figures shift as sources are added.
High-stakes fields carry their own escalation thresholds — threat-actor and malware attribution at 0.85, affected counts and industry tags at 0.66 — and a below-threshold field triggers a harder second extraction pass before publication. Named attributions additionally face an adversarial verify pass. Per-field confidence scores on every record.
meta.ai_assisted: true on every API response and PDF footer. EU AI Act Art. 50-compliant ahead of the Aug 2, 2026 enforcement date.
If DisclosureLens has a material security incident, the disclosure lands in our own feed with source.type = self_disclosure and a 14-day post-mortem.
Full dashboard · 60 req/min API · full corpus history · no credit card. Attribution requested when republished. Sign-in adds API keys and saved filters. Signed PDF deliverables (scorecards, benchmark letters) sit in the paid tier; bulk exports and webhooks are planned.