Pulse
Slice by source, severity, sector, threat actor, compliance window — every panel pivots back to the underlying records.
Slice by source, severity, sector, threat actor, compliance window — every panel pivots back to the underlying records.
Derived from affected count, data sensitivity, and sector criticality.
1,899 rows · 90-day window
Top 2-digit sectors hit, ranked by indexed filings.
Multi-tag industry mapping — security-context verticals. 'Other' = filings with no NAICS signal, NOT zero.
Days from discovery → filing.
NIST SP 800-122 + HIPAA-aligned categories. Multi-tag — one filing can affect several types.
The grain below data types: SSN and driver's licence are separate here, and every US credit-monitoring mandate turns on which one it was.
On-time vs late notice across SEC 4-day, HIPAA 60-day, GDPR 72-hour, 8 state-AG clocks, and pre-disclosure leak gaps.
812 rows · 90-day window·1,087 filings carry no discovered_at — shown apart, on their own scale, because at 16.5× the tallest dated bucket they would otherwise flatten the distribution
Banded distribution of affected_individual_count.
1,899 rows · 90-day window·571 filings disclose no count — shown apart, because an explicit NULL is not a band and must not rank against measured ones
high-sensitivity types (government ID, genetic, biometric, minors) tinted danger
Stated not involved — the regulator asked and the filing answered no. A separate fact from the bars above, never summed with them, and absent from both means the filing was silent.
stated exposed — a separate count of filings stating an element was NOT involved appears below, and the two are never added
on time· review· late·bars share one scale