We process data stolen from victims. Here is the law and the discipline around that sentence.
Last reviewed: September 2026 · This summary is public by policy. The underlying assessments and the DPA are available to customers, prospects under NDA, and regulators.
1 · What we process, and why it needs a written basis
The platform indexes data that criminals have already stolen and published: credentials, session cookies and personal identifiers appearing in stealer logs, underground forums and leak sites. That data concerns third parties, the victims, who never consented to anything.
Processing it is lawful when it serves a legitimate, proportionate security purpose, and only under documented safeguards. This page summarizes those safeguards; the full legitimate-interest assessment, framed on GDPR Art. 6(1)(f), is available to customers and regulators on request.
2 · Legitimate interest, narrowly construed
The purpose of processing is singular: enabling organizations to detect and remediate the compromise of their own assets and identities. The platform is licensed to vetted organizations, scoped by contract to that purpose, and is not a people-search service.
We do not enrich victim identities, build consumer profiles, or sell records. Access to raw records requires an organizational account bound by contract to the same purpose limitation.
3 · Where credential material can go
Credential and cookie material is reachable only inside an authenticated session or an authenticated API key, held by an organization contracted to the purpose in section 2 and granted the relevant module. There is no anonymous read path to it, and the console does not display secret values until an analyst deliberately reveals them.
Anything that leaves an unauthenticated context carries aggregate counts and dates only. No credential material is exposed outside an authenticated, contracted, audited context.
4 · Access auditing
Queries against the credential, code-exposure and intelligence-search modules are logged: who searched, what, when, through which interface. Coverage is being extended to the remaining modules. Your organization's own query record is available to you through the API, and provided on request. Our own staff access is governed by the same logging and is reviewed internally. The control applies to us first.
5 · Retention
Records are kept only as long as they serve the security purpose. That is not a fixed period. A leaked credential does not reliably lose its value on a schedule: industry guidance has moved away from forced password rotation, and password reuse remains common. Our policy therefore sets criteria rather than an expiry date: whether the data is still circulating, whether the asset still exists, whether anyone remains able to act on it. Records that meet none of them are removed, and nothing stays in the live index beyond ten years. The criteria are in our processing record and available on request.
6 · Data-subject rights
Individuals may direct questions or objections regarding their personal data to our data-protection contact. We respond within the statutory timelines that apply, GDPR primary among them. Note that removing a victim's record from the index can remove their employer's ability to protect them. We explain this trade-off in every response and act on the data subject's decision.
Data protection contact
privacy@generalintels.com handles data-subject requests, regulator inquiries and DPA copies. We answer counsel-to-counsel questions in demos as well; bring yours.
Reading this because you want to know what we do with your data as a visitor or a customer contact? That is a different document: the privacy notice.
Your counsel will have questions.
Bring them. We answer counsel-to-counsel.
NDA-friendly briefings · global coverage · no slideware