Privacy
BreachLense processes uploaded evidence for authorized incident response. Evidence can include personal information, passwords, session values, device details, and screenshots.
Storage and access
Persistent archives and recovered secrets are encrypted by the application. Case access is controlled by permissions and authenticated report shares. Secret reveals, screenshot views, report access, and administrative changes are audited.
Retention
Administrators control retention and removal. Authorization attestations and audit history are preserved when a case is deleted. Secure deletion of a file cannot guarantee forensic erasure from storage media or backups.
Your browser
A secure session cookie is required. The application serves its scripts locally and does not use third-party analytics or external avatar requests. Revealed passwords are cleared from the page after a short interval.