About BreachBook
BreachBook is a public record of disclosed U.S. data breaches. It is compiled and published by Oak and Main Developers LLC, a California limited liability company.
Who publishes this
| Publisher | Oak and Main Developers LLC |
| Jurisdiction | California, United States |
| Mailing address | 2108 N St., Sacramento, CA 95816 |
| Corrections | [email protected] |
| General enquiries | [email protected] |
| Security reports | [email protected] |
What this record is
Every entry on this site is a breach an organization disclosed to a government agency, republished with the exposed data classes, the dates on the record, a computed severity score, and a citation to the filing it came from. Nothing here is reported by us; it is assembled from records the government already publishes, and every published fact traces to one of them. Coverage, method, retrieval conduct and the gaps in the record are set out in full on the sources and methodology page.
The severity score is computed, never assigned. The rubric is versioned and published in full, including the rules for what happens when a source does not disclose a field, so any score on the site can be recalculated by hand from the record it describes.
What this record is not
- Not a "have I been breached" lookup. That function exists at Have I Been Pwned. We link to it and never proxy or replicate it — their terms prohibit it, and such a tool would collect exactly the personal information this site exists to document the exposure of.
- Not a law firm, and not legal advice. Oak and Main Developers LLC does not practise law. The statutory summaries under rights by state report what a statute provides; they do not advise on how it applies to any person or any incident.
- Not a settlement administrator. Settlement pages link only to the official administrator for that case. This site never accepts claim information.
- Not an accusation. A breach appearing here means an organization filed a required disclosure. It is not a finding that the organization broke any law.
Editorial standards
The editorial rules this site is built to are not aspirational: several are enforced by the build, which fails rather than publishing a page that violates them. A record with no cited source never renders. A settlement page whose claim link points at our own domain fails the build. The site ships no executable JavaScript, so it cannot track a reader even by accident.
We report rather than alarm. We do not publish "you may be owed" headlines, countdown urgency on anything but an actual legal deadline, or language implying a reader was affected by a breach they may have no connection to.
Corrections
Errors are corrected openly and logged with the date and what changed. Records are never silently edited and never deleted. To report an error, write to [email protected] with the page URL and, where you have one, a citation to the government or court document showing the correct fact. The full policy and the correction log are on the corrections page.
Privacy
This site collects no data about its readers: no cookies, no analytics, no tracking, no third-party scripts. See the privacy policy for the detail, including what Cloudflare necessarily sees in serving the request.