Pivot across every regulator's breach feed

Every breach.
Every angle.

Every formally-filed breach disclosure — SEC 8-K, 17 US state AGs, HHS OCR, EU DPAs, ransomware leak sites — extracted into one schema, one feed. Filter and pivot across severity, industry, threat-actor tactics, and compliance timelines.

Compliance officers, underwriters, breach counsel, and security researchers run on the same canonical record — the patterns individual regulator portals don't show you, surfaced.

DisclosureLens — breach intelligence
LIVE FEEDwhat regulators reported · last 30 daysopen analytics →
Indexed · 30d
230
Daily run-rate
7.7
Top source
State AG 94%
LowAMGEN INC.🇺🇸 SEC 8-K · PHI, Health (basic)LowSM ENERGY COMPANY🍁 VT AGMediumMPS Group⭐ TX AG · 481 affected · Government ID, PII
22 sources reporting in the last 30 days · coverage growing weekly
Why one source isn't enough

An SEC filing told investors a breach happened — but omitted the number affected and the data types exposed. 92% of SEC 8-K cyber filings do. The same week, a state AG filing disclosed 2.5 million Social Security numbers were compromised. A ransomware leak site had posted about it 91 days earlier. DisclosureLens merges all three into one record — the full story, not the slice each regulator got.

☠ Leak postday 0
🇺🇸 SEC 8-Kday 91 · no counts
⭐ State AGday 92 · 2.5M SSNs
→ one merged record · confidence 92%
Six patterns the regulator portals don't show you

Built for the analyst the portals didn't plan for

Information asymmetry
SEC tells investors almost nothing

In our corpus, 92% of SEC 8-K cyber filings omit the number of people affected — and 99% of SEC cyber filings overall do. State notices carry the counts and data types the 8-K leaves out. Both views, merged.

Early warning
Leak sites post 3 months before regulators

In our corpus, leak-site posts precede regulatory filings in roughly 9 of 10 cross-linked incidents, with a typical lead of about three months. DisclosureLens correlates both feeds and computes the gap on every record.

Compliance clocks
Filed late · 13 frameworks, one view

SEC 4-day, HIPAA 60-day, GDPR 72-hour, plus the state-AG clocks. Elapsed days computed against each statute — one overdue-clock summary per record, verbatim citation one click away.

Entity scorecards
Five-year breach record for any entity

Per-entity compliance scorecard — totals, per-jurisdiction flags, severity-weighted score, clocks-missed timeline. Downloadable as a signed PDF for audit packets.

Risk analytics
Frequency × severity, per-vertical

Vertical × severity heatmap, repeat-offender index, FAIR-aligned severity fit per industry. comparable_incidents, underwriting_brief, freq_severity_curve under /v1/analytics.

Audit-grade PDFs
PAdES-B signed, tamper-evident

Every scorecard, compliance report, and broker letter is PAdES-B signed with byte-range tamper detection + cert fingerprint in the footer. EU AI Act Art. 50 disclosure on every page.

Five audiences, one schema

Built for

Journalists — see the per-state pages at /breach-notifications. Free dashboard tier, no credit card.
We track the sources, not just the records

Feed News

When a regulator takes a feed offline, relocates it, or restores it, we report it — and keep a live status on every source we collect.

What cross-source data reveals

Even after cross-source enrichment, the HIPAA 60-day clock is fully computable for under 2% of OCR filings — and where it is, nearly half ran late. And corpus-wide, when an entity is breached again, about 4 in 10 re-breaches land within 90 days of the first. Observed in corpus, not a forecast; figures shift as sources are added.

When extraction confidence dips, we read it again

High-stakes fields carry their own escalation thresholds — threat-actor and malware attribution at 0.85, affected counts and industry tags at 0.66 — and a below-threshold field triggers a harder second extraction pass before publication. Named attributions additionally face an adversarial verify pass. Per-field confidence scores on every record.

Disclosure-aware AI

meta.ai_assisted: true on every API response and PDF footer. EU AI Act Art. 50-compliant ahead of the Aug 2, 2026 enforcement date.

Held to the standard we hold regulators to

If DisclosureLens has a material security incident, the disclosure lands in our own feed with source.type = self_disclosure and a 14-day post-mortem.

Free for the public interest

Free for journalists, researchers, and security teams

Full dashboard · 60 req/min API · full corpus history · no credit card. Attribution requested when republished. Sign-in adds API keys and saved filters. Signed PDF deliverables (scorecards, benchmark letters) sit in the paid tier; bulk exports and webhooks are planned.

Get an API key
© DisclosureLens — Every breach. Every angle.Report an error / Request removalTermsPrivacyv0.1.0 · live coverage at /pulse/coverage