How Umbrify protects your data

Security is not a feature - it is the foundation of everything we build.

We never store your password

When you check a password, the password itself never goes to us or to Have I Been Pwned. Your device hashes it locally (SHA-1) and only the first 5 characters of that hash are sent to HIBP - that is k-anonymity. HIBP returns matching suffixes; your device finishes the check. We never store any part of the password.

Breach data from Have I Been Pwned

Breach data is sourced from Have I Been Pwned (HIBP), the world's largest publicly available breach database maintained by Troy Hunt. HIBP aggregates data from publicly disclosed breaches. Umbrify uses the HIBP API under their terms of service and provides proper attribution on all breach results.

Your data is encrypted

All user data stored in our backend (Supabase on AWS) is encrypted at rest with AES-256. Data in transit uses TLS 1.2 or higher. Encryption keys are managed by AWS KMS and rotated automatically.

No data selling

Our business model is subscriptions, not advertising. We do not sell, license, or share your personal information with data brokers, advertisers, or any third party for commercial purposes. Your data is used only to provide the service to you.

Found a vulnerability?

We take security reports seriously. If you discover a vulnerability in Umbrify, please disclose it responsibly. We will acknowledge reports within 48 hours and work to resolve valid issues promptly.

security@umbrify.app