Create a read-only credential
Create the credential in Have I Been Pwned with the minimum read scope, paste it into devguard, and the connection is live. The integration page in the product spells out the exact permissions.
devguard queries the Have I Been Pwned domain search for your domain and turns breach exposure into evidence: the API connects, your domain is monitored, and new breaches surface as findings.
3 read-only checks, run on a schedule. Each failure becomes a finding linked to a control — every check is listed, none are “coming soon”.
Confirms the API key authenticates and has domain-search access by listing subscribed domains. A 401 or 403 is reported as an invalid key or a missing domain-search subscription rather than a silent error.
api-connectivity
Coverage guard: fails if the configured domain is not among the account's subscribed, verified domains, which would let the breach check pass vacuously. Guards against asserting on a domain HIBP is not actually monitoring.
domain-under-monitoring
Fails if any account on the domain appears in a known breach. HIBP returns HTTP 404 when no accounts on the domain are breached (the clean, passing state) and HTTP 200 with an alias-to-breaches object when there are — that 200 is the failing state. A 401/403 is a hard error (not swallowed), so an auth or verification problem never reads as clean.
no-breached-accounts
Bring your current platform's test list — we'll map it against these checks, gap by gap
Setup is minutes, not a migration project — and every step stays on your side
Create the credential in Have I Been Pwned with the minimum read scope, paste it into devguard, and the connection is live. The integration page in the product spells out the exact permissions.
The first run starts right after connecting, then repeats on a schedule. Results are timestamped, so your evidence has a history, not a snapshot.
Passing results attach as evidence to the controls they support; failures become findings you triage. When the audit comes, the proof is already connected.
Open any page for its full check register.
You create and scope every credential yourself, and you can revoke it at any time. Checks only read; results and evidence are stored in Switzerland and stay exportable.
Yes. The checks authenticate with a credential you create and scope yourself, and only ever read configuration. devguard holds no write access to Have I Been Pwned and remediates nothing silently.
A failed check becomes a finding linked to the control it supports, with the evidence attached. You decide the treatment — nothing pages your engineers and nothing is auto-remediated.
Checks run from Swiss infrastructure, and results and evidence are stored in Switzerland. Everything is exportable — your evidence stays yours.
20 minutes on how you run certification today. Bring your current test or control list and we'll map it against these checks — honestly, gap by gap.