Report an error or request removal
Anyone can use this page — you do not need an account, and you do not need to be a customer. If a record on DisclosureLens is wrong, names you unfairly, contains your personal data, or reproduces material you hold rights in, tell us and we will look at it.
Before you write: what a record does and does not assert
DisclosureLens indexes several different kinds of source, and they carry very different weight. Knowing which one you are looking at usually explains the record:
- Regulatory filings (SEC, HHS OCR, US state attorneys general, EU data protection authorities) — we report what the regulator published. If the filing itself is wrong, the regulator’s record is the thing to correct; tell us anyway and we will annotate ours.
- Threat-actor leak-site claims — these are allegations published by a criminal group, republished here labelled as unverified. They are not confirmation that a breach occurred. If you are named in one and dispute it, use the second route below; a denial from the named organization is exactly the kind of thing we want on file.
- Press reports — third-party journalism, linked to its source.
How to reach us
A record is factually wrong
A date, an affected-individual count, a jurisdiction, a linked filing, or the organization a record is attributed to is incorrect.
Please include:
- The page URL and the record id (the mono id shown on every detail page, e.g. inc_… or bd_…)
- Which field is wrong, and what the correct value is
- The source that supports the correction — ideally the regulator filing itself
You are named in a record and dispute it
Your organization is named — most often in an unverified threat-actor (leak-site) claim — and you believe the record is inaccurate, misattributed, or should not be published.
Please include:
- The page URL and the record id
- Your relationship to the named organization
- What is disputed — that the event occurred, that it involved you, or the characterization
- Anything you can share that supports it (a public statement, a regulator response, an incident-response finding)
Email corrections@disclosurelens.com — “Disputed record / removal request”
A record contains your personal data
You are an individual (not an organization) and personal data about you appears in a published record — for example inside the text of a breach-notification letter — and you want access, correction, or erasure.
Please include:
- The page URL and, if you can, the exact text at issue
- Enough detail to locate the data (we may need to confirm identity before acting on an erasure request)
- What you are asking for: access, correction, erasure, or objection to processing
Email corrections@disclosurelens.com — “Personal data request”
Copyright / DMCA
You hold rights in material reproduced on this site and believe it is used without authorization.
Please include:
- Identification of the copyrighted work and the URL of the material at issue
- Your contact information
- A statement of good-faith belief that the use is not authorized, and that the information in your notice is accurate
What happens next
- Acknowledgement. We aim to acknowledge within 48 hours of receipt.
- Review. We check the claim against the underlying source document and our extraction audit trail (every record stores the model, prompt version, and per-field confidence scores).
- Outcome. A record can be corrected, annotated, unlinked from an incident, retracted from the public feed, or left as-is with our reasoning. We will tell you which, and why.
- Priority. Requests from the named organization itself, and requests concerning an individual’s personal data, are handled ahead of the routine queue.
Other contacts
- Security vulnerabilities: security@disclosurelens.com (see also security.txt and our security page)
- Crawler behaviour and rate limits: abuse@disclosurelens.com (see about the crawler)
- Anything else: contact@disclosurelens.com
How records are produced, and the confidence and review process behind them, is documented on the methodology page.