GNSAC
Metrics & methodology
Publication register

Quantitative claims, with scope and limitations.

This page is the public reference for platform figures used across the GNSAC website and product collateral. It explains what each number means and what it does not establish.

Snapshot date
2026-08-21
Evidence reference
PMR-2026-08-21
Verification status
Internal production snapshot; not independently audited.
Published metric definitions
8.7B+

Corporate credential records

De-duplicated records classified as corporate credential exposure within the production repository.

Repository coverage changes as sources are added, removed or reprocessed; a record is not proof of a currently valid credential.

~11M/day

New records per day

Approximate production ingestion volume across credential, underground-source, threat-intelligence and hash processing pipelines.

A rolling operational estimate, not a guaranteed minimum; source availability and reprocessing can materially change daily volume.

~7M/day

Credential records processed daily

Approximate daily records entering credential-exposure processing before all review and de-duplication stages complete.

Processing volume is not the number of unique affected people or organisations.

1.7B+

Password hashes analysed

Hash observations processed for exposure context within the intelligence repository.

The count includes observations, not necessarily unique or currently usable passwords.

1.53B+

Underground leak records

Records indexed from selected underground and leak-data collections.

A record may represent a claim or observation requiring validation; it is not itself confirmation of an incident.

600+

Monitored intelligence sources

Selected source endpoints or collections configured for recurring production monitoring.

Availability and lawful access vary; source count does not measure relevance or completeness.

806

Threat-actor profiles tracked

Actor profiles present in the production knowledge base at the snapshot date.

Profiles may merge aliases and vary in confidence or activity status.

150+

Messaging channels monitored

Selected lawfully accessible messaging communities included in recurring monitoring.

Channels may become unavailable or change scope without notice.

132+

OSINT and CTI analysis modules

Distinct enabled checks or processing modules in the production assessment workflow.

Applicable modules vary by scope, domain structure, licence and source availability.

3.1M

Phishing URLs indexed

URL observations classified for phishing-infrastructure analysis.

Classification status can change after review or source updates.

7.5M

Indicators indexed

Indicator observations retained for correlation and investigation context.

An indexed indicator is not necessarily malicious, current or relevant to every customer.

101K+

Vulnerability records available for matching

Vulnerability records available to enrich externally observed technology findings.

Availability does not mean every record is applicable to, or exploitable in, a customer environment.

500+

Ransomware leak-site sources tracked

Active and historical leak-site source records available to the monitoring workflow.

Sites and mirrors change frequently; a source count is not a guarantee of continuous access.

How to read these figures

How to read these figures

Repository and processing figures describe the production dataset at a point in time. They do not represent unique people, guaranteed coverage, detection of every exposure or proof that every record is current or valid. Source availability, reprocessing and de-duplication can change the figures.

Platform Metrics & Measurement Notes | GNSAC