NEWJoin 2M+ software buyers|Get Weekly Insights, Trends & Expert PicksSubscribe free →

SaaS Insights

Credential Breach Monitoring for Business 2026: Verified Pricing and Cost Per Domain

S

Written by

Spotsaas Editorial Team

Published October 3, 2026

Credential breach monitoring answers one question: have any of our people had their credentials exposed in a third-party breach?

It matters because credential reuse remains the most reliable way into an organisation. An employee who used their work email on a breached forum in 2019, with a password they also use on your VPN, is a live route in that no amount of perimeter spending closes.

This is also a category where pricing is unusually transparent, and where the free tier is genuinely sufficient for a lot of organisations. Both of those are rare enough to be worth setting out properly.

We verified pricing at the vendor in October 2026.

Start with the free tier, because it may be enough

Have I Been Pwned’s free tier includes:

  • Browser email search
  • Email notifications
  • Pwned Passwords
  • Breach monitoring API
  • Domain monitoring for domains with up to 10 breached addresses

That last item is the one that matters and the one most often missed. You can monitor your own domain at no cost, provided fewer than ten addresses on it appear in breaches.

For a company of twenty or thirty people with reasonable password hygiene, that threshold may never be crossed. The correct first action is therefore not to buy anything. It is to verify your domain on the free tier and find out how exposed you actually are.

If you exceed ten breached addresses, you have learned something important and you now have a number to budget against. If you do not, you have a monitoring capability at no cost.

Pwned Passwords, which checks whether a password has appeared in a breach corpus, also requires no paid subscription. Wiring it into your password reset flow is one of the cheapest meaningful controls available, because it blocks the specific failure mode this whole category exists to detect.

Core plans: monitoring your own domains

Core plans add direct email search and larger domain monitoring:

Plan Monthly Rate limit Domains Address limit
Core 1 $4.39 10 RPM 1 25
Core 2 $21.59 50 RPM 3 100
Core 3 $36.99 100 RPM 5 500
Core 4 $159 500 RPM 10 Unlimited
Core 5 $319 1,000 RPM 20 Unlimited

Two things drive the price: how many domains you monitor, and how fast you can query the API.

The jump from Core 3 to Core 4 is the significant one. It is a 4.3x price increase, and what it buys is removal of the breached-address cap. If your exposure is under 500 addresses, Core 3 at $36.99 a month covers five domains and is likely the right landing spot for a mid-sized organisation.

Most organisations with a single domain and moderate exposure never need to go past Core 1 or Core 2. At $4.39 a month, Core 1 costs less annually than a single hour of consultant time.

The address cap is the thing to model

Breached-address limits are easy to misread as a soft guideline. They are the binding constraint on the lower tiers.

Core 1 covers 25 breached addresses, Core 2 covers 100, Core 3 covers 500. A thousand-person company with a decade of history and a few acquisitions will commonly exceed 500 breached addresses, because the figure counts historical exposures rather than current employees. People who left years ago still appear.

That is why the unlimited tiers start at Core 4. The question is not how many staff you have; it is how many addresses on your domain have ever appeared in a breach corpus. Those are very different numbers, and the second is usually larger.

Check it on the free tier before choosing a tier on headcount.

Pro plans: monitoring other people’s domains

Pro plans are a different product aimed at a different buyer:

Plan Monthly Rate limit Domains
Pro 1 $379 1,000 RPM 50
Pro 2 $699 2,000 RPM 100
Pro 3 $1,299 4,000 RPM 200
Pro 4 $2,499 8,000 RPM 400
Pro 5 $4,599 16,000 RPM 800

The distinguishing feature is that Pro supports monitoring your customers’ domains as well as your own, plus k-anonymity search and Pwned Passwords support.

That makes Pro a managed service provider and security vendor product rather than an in-house one. If you are an MSP offering breach monitoring to a client base, or a security platform embedding the capability, this is your tier. If you are an internal security team, it almost certainly is not, regardless of headcount.

K-anonymity search is the technically interesting part. It allows querying without transmitting the full address or password, which matters when you are checking data belonging to clients rather than to yourself. If you are building a feature on top of this, that is the capability you are paying for.

Cost per domain falls sharply with scale

Dividing monthly price by domains monitored shows how steeply the economics change:

Plan Monthly Domains Per domain
Core 4 $159 10 $15.90
Core 5 $319 20 $15.95
Pro 1 $379 50 $7.58
Pro 2 $699 100 $6.99
Pro 5 $4,599 800 $5.75

Per domain, Pro 5 is about 64% cheaper than Core 4. The curve flattens after Pro 2, so most of the volume benefit is captured by the time you reach 100 domains.

There is also a quiet threshold worth noticing. Core 5 monitors 20 domains at $319 a month. Pro 1 monitors 50 at $379. For $60 more you get 2.5 times the domains, provided the Pro feature set suits you.

Any organisation sitting at the top of Core with more domains to add should compare the two directly rather than assuming the next step up stays within the same family. This is the sort of boundary that costs money precisely because it looks like an upgrade path when it is actually a product switch.

Rate limits are a design constraint, not a detail

Every tier is bounded by requests per minute, and this is easy to under-plan.

Rate limit 5,000 addresses 25,000 addresses
10 RPM ~8 hours ~42 hours
100 RPM ~50 minutes ~4 hours
500 RPM ~10 minutes ~50 minutes
4,000 RPM ~1 minute ~6 minutes

If you intend a one-off sweep of a large address list, or a scheduled recurring sweep, the rate limit rather than the domain count may determine your tier.

The High RPM plans exist precisely for this, with throughput rather than domain coverage as the product: $1,150 a month at 4,000 RPM, $2,299 at 8,000, $3,449 at 12,000, $4,333 at 16,000 and $5,833 at 24,000.

Work out your intended query volume and frequency before choosing, because moving up a tier for throughput is a materially different cost decision from moving up for domains. A team that only needs continuous domain monitoring needs very little throughput; a team building a signup-time check against a large user base needs a great deal.

A note on published figures

Third-party roundups of this vendor’s pricing circulate widely and were wrong on every tier we checked. Commonly reported figures of $3.95, $19, $32 and $137 do not match the published $4.39, $21.59, $36.99 and $159.

The differences are not large in absolute terms, but a plan reported at $137 that actually costs $159 is 16% out, and at the Pro tiers the same proportional error runs to hundreds of dollars a month.

We found the same pattern in employment background check software, where every aggregator figure for three vendors was wrong, and in identity verification pricing. Verify at the vendor before you budget.

Where the rest of the market sits

Breach and credential monitoring shades into broader threat intelligence, and pricing transparency drops away quickly once it does.

BreachSense operates in the same space with a focus on breach and dark web data for organisations, and quotes rather than publishing rates.

Beyond that, the category merges into enterprise threat intelligence platforms sold on annual contracts, where monitoring is one module among many. If you only need credential exposure monitoring, buying a full threat intelligence platform is substantial overspend.

The practical sequence is to establish exposure cheaply first, then decide whether you need more than monitoring. Teams frequently do the reverse, buying a platform and then discovering that the capability they actually wanted was available free.

What to do with a positive result

Monitoring is only useful if a hit triggers something. A credible process has four steps.

Force a password reset for the affected account, and specifically check whether that password was reused on internal systems. The breach itself is usually old news; the reuse is the live risk.

Check for multi-factor authentication on the account. An exposed credential on an account with strong MFA is a much smaller problem than one without, and this is the step that converts an alert into a risk rating.

Look for the same person elsewhere. A personal address exposed in a breach often shares a password with the work account. This is where employee privacy meets security, which we cover in employee data broker removal.

Record it. Repeat exposures for the same person indicate a habit worth addressing through training rather than another reset. If the same five people account for most of your alerts, the intervention is behavioural, not technical.

Without that workflow, breach monitoring produces alerts nobody acts on, which is worse than not monitoring because it creates documented awareness without response.

Count your domains properly

Domain count drives tier selection, and most organisations undercount it.

Include every domain that still receives mail or has ever issued staff addresses:

  • Acquired companies’ domains, which often keep receiving mail for years after an acquisition
  • Country-specific domains used by regional teams
  • Legacy domains from a rebrand, which are frequently still live and rarely governed
  • Product domains where support or sales addresses were issued

Legacy and acquired domains are disproportionately likely to carry stale credentials, because nobody owns their password policy. They are the domains most worth monitoring and the ones most often left off the list.

An organisation that counts one domain and buys Core 1 may discover it actually has seven.

Seven questions before you buy

  1. Have we checked the free tier first? Domain monitoring is free below ten breached addresses. Establish actual exposure before budgeting.
  2. How many breached addresses do we have, not how many staff? The cap counts historical exposures, including former employees.
  3. How many domains do we genuinely need to monitor? Count acquired brands, regional domains and legacy domains that still receive mail.
  4. What query volume and frequency do we need? Rate limits, not domain counts, often determine the tier.
  5. Are we monitoring our own domains or customers’ domains? Customer monitoring moves you to Pro, which starts at $379 a month.
  6. Who receives alerts, and what happens next? Define the reset and reuse-check workflow before switching monitoring on.
  7. Is this standalone or part of a wider programme? If you also need phishing simulation and training, look at security awareness training software rather than buying monitoring in isolation.

Frequently asked questions

How much does credential breach monitoring cost?

Have I Been Pwned publishes Core plans from $4.39 a month for one domain up to $319 for twenty, and Pro plans from $379 to $4,599 a month for monitoring customer domains. Domain monitoring is free where fewer than ten breached addresses are involved. Other vendors in the space, including BreachSense, quote on request.

Is breach monitoring free for small businesses?

Often, yes. The free tier covers domain monitoring where fewer than ten addresses on your domain appear in breaches, and also includes Pwned Passwords and the breach monitoring API. Verify your domain on the free tier before paying for anything.

What is the difference between Core and Pro plans?

Core covers direct email search and monitoring of your own domains. Pro adds k-anonymity search and the ability to monitor customers’ domains, which makes it a managed service provider and security vendor product rather than an internal security team one.

How many domains should we monitor?

More than most organisations initially count. Include acquired brands, country-specific domains, legacy domains from rebrands, and product domains that issued support addresses. These are frequently the least well governed and the most likely to carry stale credentials.

What do rate limits mean in practice?

They cap API requests per minute. At 10 requests per minute, sweeping 5,000 addresses takes around eight hours. At 500 per minute it takes about ten minutes, and at 4,000 per minute roughly one minute. If you plan large or frequent sweeps, throughput may determine your tier rather than domain count.

Does the breached-address limit count current employees?

No. It counts addresses on your domain that appear in breach data, which includes people who left years ago. A company with 200 current staff can easily exceed a 500-address cap once historical exposures are included, which is why the unlimited tiers begin at Core 4.

Does breach monitoring stop attacks?

Not by itself. It tells you which credentials are exposed. The protective value comes from what follows: forcing resets, checking whether the password was reused internally, and confirming multi-factor authentication is in place. Monitoring without that workflow generates alerts rather than security.

Pricing verified against haveibeenpwned.com/Subscription on 2 October 2026. Cost-per-domain and sweep-duration figures are our own calculations from those published rates and limits. Rates change, so confirm current figures with the vendor before you commit.

Related Articles