Free · No signup · Real breach data

Your data is already exposed.
See exactly where.

We check your email against the same breach and dark-web data security teams use. It takes about ten seconds, and it is free.

Your address goes to Have I Been Pwned over HTTPS — that check cannot be made anonymous. A free scan leaves no record of it with us.

or
Known breach databases Dark web monitoring VPN protection Instant alerts

Your privacy command center

Exposure Alerts

Know when your data leaks

Broker Removal

We submit recurring opt-outs for you

Family Coverage

Protect the people in your household

Crisis Assist

Get a guided response when risk spikes

Simple Pricing

Start protecting yourself

Less than $0.15/day for full coverage.

$9/month

Or $79/year — save 27%

  • Free exposure report
  • Dark web credential monitoring
  • Recurring broker opt-outs every 60 days
  • Removal dashboard with evidence archive
  • Plain-English alerts and next steps
  • Emergency Lock and guided recovery
  • 5% revenue donated to ITRC

Cancel anytime. No contracts.

How It Works

A simple flow from detection to action.

Scan first, monitor what matters, get help taking the next step.

01

Run a free scan

Check if your email shows up in any known breach — no account needed, no credit card.

02

Remove continuously

Klaw submits broker opt-outs on a recurring cadence so removed data is less likely to reappear unnoticed.

03

Monitor and respond

Get alerts, recovery guidance, and escalation paths when new exposure or fraud risk appears.

Platform

Monitoring, guidance, and response — in one place.

Monitoring

See exposure before it turns into a problem.

  • Free exposure report
  • Dark web checks on paid plans
  • Smart alerts
  • Monitoring history

Guidance

Understand what happened and what to do.

  • Incident playbooks
  • Recovery checklists
  • Broker opt-out workflows
  • AI recommendations

Response

Act quickly when something feels wrong.

  • Emergency Lock
  • Escalation paths
  • Secure Notes
  • Higher-tier support

Emergency Lock

Lock the dashboard and start recovery when something feels off.

Emergency Lock is built for speed — act first, then work through a structured recovery path instead of losing time figuring out what to do. It locks the Klaw dashboard, not your sign-in, so change your password and turn on two-factor authentication too.

One-tap dashboard lock

Guided recovery workflow

Human review on paid tiers

Lockdown phone on eligible plans

VPN Access

Privacy beyond dashboards and alerts.

Longer-term paid plans include VPN access — a more complete privacy layer while KLAW handles breach monitoring and recovery guidance.

Encrypted browsing on public Wi-Fi
Private connection for daily use
Included on paid longer billing plans
High-speed access on select tiers

Plans

Clear pricing. Start free.

Begin with free breach scanning, then upgrade for automated monitoring, dark web coverage, and stronger support.

Free

$0

Free exposure report

Breach ScansUnlimited
Dark Web ScansLocked
Auto-Scan—
Incident SupportSelf-service
Lockdown Phone—
ITRC Donation—

Basic

$9/mo

Core monitoring

Breach ScansUnlimited
Dark Web ScansUnlimited
Auto-ScanEvery few days
Incident SupportGuided self-service
Lockdown Phone—
ITRC Donation5% to ITRC

Plus

$19/mo

Most popular choice

Popular
Breach ScansUnlimited
Dark Web ScansUnlimited
Auto-ScanFrequent automated
Incident SupportHuman-reviewed
Lockdown Phone—
ITRC Donation7% to ITRC

Ultra

$39/mo

Priority coverage

Breach ScansUnlimited
Dark Web ScansUnlimited
Auto-ScanDaily automated
Incident SupportPriority human review
Lockdown PhoneIncluded
ITRC Donation10% to ITRC
VPN is included on paid 6-month and yearly plans. All plans include unlimited breach scans.

For developers

Klaw as an API.Screen an applicant. Keep none of it.

Send us an applicant, get back a 0–100 score, a Pass / Review / Fail decision and a signed token. We destroy the data before the response is written, so the liability never lands on your side.

POST /v1/verifications
 
{ "applicant": { "email": "…", "full_name": "…" } }
 
→ 201
{
  "decision": "pass",
  "trust_score": 87,
  "exposure": { "surface": 3, "dark_web": 1 },
  "token": "eyJhbGciOiJFZERTQSIs…",
  "retained": null
}

Your plan helps support real victims too.

A portion of every paid subscription goes to the Identity Theft Resource Center — funding free support for people dealing with fraud and identity theft.

Learn More About ITRC

Privacy & Transparency

Clear limits around what KLAW stores.

What We Store

  • • Account email
  • • Hashed monitored items
  • • Breach summaries
  • • Alert settings

What We Don't Store

  • • Passwords
  • • Plaintext card details
  • • Browsing history
  • • Data sold to advertisers

Threat Intelligence

Security context without the noise.

Track the broader threat landscape, then connect it back to your own exposure.

Live Threat Intelligence

Active & Recent Cyber Threats

Real-time threat data pulled from CISA's Known Exploited Vulnerabilities feed and live security intelligence. Updated regularly.

Criticalsocial engineeringOct 6, 2026

ClickFix Browser-Based Social Engineering

Attackers are increasingly using 'ClickFix' tactics, where users are prompted to copy and paste malicious commands into their own terminals under the guise of security verification or software installation. These attacks exploit user trust and bypass traditional file-based malware defenses.

Web BrowsersTerminal/Command Line InterfacesmacOSWindows

Action: Restrict the ability for non-administrative users to execute terminal commands and implement strict endpoint monitoring for suspicious script execution.

HighmalwareOct 6, 2026

WaterPlum Cryptocurrency-Focused Malware

The WaterPlum group is actively targeting individuals with fake job recruitment lures to deliver malware. This malware steals cryptocurrency wallet credentials and provides remote access, which is then used to pivot into the victim's corporate network.

Cryptocurrency WalletsWindows

Action: Warn employees about unexpected recruitment-themed emails and block unauthorized software installations on corporate endpoints.

Criticalsocial engineeringOct 6, 2026

AI-Enhanced Voice Phishing (Vishing)

Voice phishing has overtaken email as a primary social engineering vector in 2026. Attackers are using generative AI to clone voices of colleagues or executives to manipulate help desk staff into resetting MFA devices or authorizing fraudulent wire transfers.

Corporate Help DesksFinancial/Accounts Payable Departments

Action: Implement verification protocols that do not rely on voice recognition, such as multi-person authentication for sensitive requests.

HighphishingOct 6, 2026

CSuite Multi-Stage Phishing and Session Theft

This active campaign impersonates common business tools like Microsoft 365, Adobe, and Zoom to deceive users. It utilizes counterfeit document pages to steal active session tokens, allowing attackers to bypass traditional password-based authentication and MFA.

Microsoft 365AdobeDropboxZoomGoogle Meet

Action: Implement phishing-resistant MFA (such as FIDO2 security keys) and monitor for suspicious unauthorized session token usage.

HighphishingOct 6, 2026

N0va Device Code Phishing

N0va is an active phishing campaign targeting users across North America and Europe by leveraging the legitimate Microsoft device code authentication flow. By tricking users into entering a device code on a malicious site, attackers obtain persistent access tokens.

Microsoft 365Microsoft TeamsSharePointOneDrive

Action: Educate users on the risks of entering device codes from unsolicited prompts and restrict OAuth device code flow access where possible.

MediumphishingOct 5, 2026

Amazon-themed Phishing Campaigns

Fraudsters are actively distributing phishing emails impersonating Amazon to deceive consumers into revealing sensitive financial information. These scams leverage the trusted brand name to trick users into clicking malicious links or providing account credentials.

Amazon

Action: Verify all order-related emails directly through the official Amazon website or app rather than clicking links in emails.

Showing 6 of 50 threats · Sources: CISA KEV + live security intelligence

Track Your Progress

Enterprise Application Status

Check where your enterprise application is in the review process.

Enterprise Application Status

Track your application in real-time

KLAW Removal Engine

We send opt-out emails to data brokers. Automatically.

Data brokers are selling your name, address, relatives, and phone number right now. KLAW sends legally-recognized removal requests every 60 days so they can't just re-list you.

  • Real opt-out emails sent directly to brokers
  • Recurring re-submission every 60 days
  • CCPA, TDPSA & GDPR legal basis included
  • Track every request in your dashboard
Start Removal — $9/mo
200+
Data brokers targeted
60d
Re-submission cycle
100%
Legal compliance
24h
First emails sent

FAQ

Real questions, straightforward answers.

Yes. You can cancel from your account settings without contracts, cancellation fees, or extra steps. Access continues through the end of your billing period.

Your data may already be exposed

Don't wait months to find out your info is out there.

Start with a free scan, then decide if you want deeper monitoring, privacy tools, and real support.

Questions? help@klawusa.org