Last reviewed August 11, 2026
Sources and methodology
HackProof uses primary platform documentation and public-agency guidance. We avoid invented statistics and distinguish a useful signal from a guarantee.
Exposure checking
- Have I Been Pwned API — Pwned PasswordsOfficial k-anonymity range-search and response-padding documentation.
- Have I Been Pwned privacy policyOfficial description of browser-side hashing and service data practices.
- Have I Been Pwned subscriptionsOfficial distinction between free browser/password tools and paid email-search APIs.
Account protection
- CISA Secure Our WorldPrimary public guidance on strong passwords, MFA, updates, and phishing.
- Google Account security guidanceOfficial Google Security Checkup and account-protection steps.
- Microsoft compromised-account recoveryOfficial recovery and post-compromise guidance.
Why this release does not connect mailboxes
- Google Gmail API scopesOfficial classification of sensitive and restricted Gmail scopes.
- Google restricted-scope verificationOfficial verification and annual security-assessment implications.
- Microsoft Graph permissions referenceOfficial Mail.Read and Mail.ReadBasic permission descriptions.
- Microsoft publisher verificationOfficial trust and consent context for multitenant applications.
Method limits
A breach corpus cannot include unknown incidents. A questionnaire is not a device scan. Password absence from a corpus is not proof of strength. HackProof prioritizes actions and explains uncertainty instead of labeling a person “safe” or “unsafe.”