NIST SP 800-63B
Audit-ready password controls, implemented the right way.
Standards like NIST SP 800-63B recommend screening passwords against known-compromised sets. LeakJar gives you the technical controls and evidence to support that recommendation.
Capabilities
Controls that map to real requirements
Compromised Password Screening
NIST SP 800-63B recommends screening passwords against known-compromised sets. LeakJar provides a production-ready API that implements this control using privacy-preserving k-Anonymity queries.
Least-Privilege Access Controls
Role-based access control, project-scoped API keys, and audit logging ensure that sensitive capabilities are available only to authorized users and systems.
Evidence Dashboards
The LeakJar console provides audit-ready dashboards showing check volumes, match rates, policy enforcement actions, and exposure monitoring activity — the evidence your compliance team needs.
Audit Log & Documentation
Every API call, configuration change, and policy enforcement action is logged. Export audit logs for compliance reviews or integrate with your SIEM.
Evidence
What LeakJar helps you demonstrate
Technical controls and evidence that support compliance programs and security reviews.
- Screen user passwords against known-compromised credential sets (NIST SP 800-63B §5.1.1.2)
- Enforce minimum password length without unnecessary complexity rules
- Provide actionable policy outcomes: block, step-up, force reset, or notify
- Maintain audit trails for all screening activity and configuration changes
- Support role-based access control and project-scoped API key management
- Offer exportable compliance evidence for auditors and reviewers
Important notice
LeakJar does not provide legal advice. The information on this page describes technical capabilities that may support compliance programs. Consult with qualified legal counsel to determine specific requirements for your organization.
Start implementing password controls today
Get started with our quickstart guide or talk to our team about enterprise compliance needs.