Troy Hunt (Have I Been Pwned)
Australia · haveibeenpwned.com · 14 vendors
Have I Been Pwned (HIBP) is a website that allows internet users to check whether their personal data has been compromised by data breaches. The service aggregates data from hundreds of data breaches, enabling individuals and organizations to identify if their information has been leaked and take precautionary measures. It was created by security expert Troy Hunt.
Resilience scores
- Digital Sovereignty: 0
- Digital Resilience: 9
- Financial Resilience: 7
Technology vendors
- Meta Platforms, Inc. — Technology — United States
- Mozilla Open Source Support — Technology — United States
- Stripe, Inc. — Financial Services — United States
- and 11 more
Services catalogue
2 services in catalogue across 1 category; runs on 14 sub-vendors.
- Domain Verification
- Have I Been Pwned
Insights
Last updated 2026-05-12 · revision 2
14 direct vendors, 202 subvendors
Direct vendors by controlling owner country (sample)
- Canada: 1
- United States: 10
- Sweden: 1
Subvendors by controlling owner country (sample)
- South Korea: 1
- Sweden: 6
- Germany: 6
Migration Readiness: 8/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Troy Hunt (Have I Been Pwned) exhibits high migration readiness primarily due to its highly modern and cloud-native technology stack. The extensive use of Microsoft Azure, including serverless Azure Functions, positions the company with a flexible and scalable architecture. The adoption of edge computing with Cloudflare Workers further demonstrates an agile and distributed approach to infrastructure. This cloud-native and serverless paradigm inherently reduces the complexity of future migrations, whether for platform upgrades, multi-cloud strategies, or refactoring efforts. The company's focus on RESTful API design and modern languages like C#/.NET and TypeScript also supports easier integration and migration pathways. The assessment is limited by the lack of specific data regarding regulatory environment and data residency requirements, which can significantly impact migration strategies and costs. Financial stability data (revenue concentration, growth history) is also absent, making it difficult to assess the company's capacity to fund a major migration effort. While the tech stack is highly cloud-native, the deep integration with Microsoft Azure could present a degree of vendor lock-in if a migration away from Azure were considered, though the "Vendor Lock-in Risk" is stated as "Unknown." The precise number of vendors is unclear ("Total Vendors: 0" is contradictory), but the reliance on major platforms like Azure and Cloudflare implies a dependency that would need careful management during any significant migration.
Compliance
4 in-scope frameworks identified; showing 3.
ISO 27001 (source) — Assessment Required
As a cybersecurity service handling sensitive breach data and personal information, ISO 27001 certification would be highly valuable for demonstrating information security management maturity. The absence of public certification represents moderate risk for enterprise customer confidence and competitive positioning in the cybersecurity market.
Evidence: https://haveibeenpwned.com/Privacy, https://haveibeenpwned.com/DPA
GDPR (source) — Compliant
HIBP processes personal data of EU/EEA residents through their breach notification service and has implemented comprehensive GDPR compliance measures including a detailed DPA with Standard Contractual Clauses, data subject rights procedures, and explicit GDPR references in their privacy policy. However, as a cybersecurity service handling sensitive breach data, there remains inherent regulatory scrutiny risk and potential for data protection authority investigations.
Evidence: https://haveibeenpwned.com/Privacy, https://haveibeenpwned.com/DPA, https://haveibeenpwned.com/OptOut
Australian Privacy Act 1988 — Compliant
As an Australian company (Superlative Enterprises Pty Ltd), HIBP is subject to the Australian Privacy Act and has implemented comprehensive privacy controls. Their detailed privacy policy, data handling procedures, and explicit reference to Australian privacy law compliance indicate strong adherence to local requirements.
Evidence: https://haveibeenpwned.com/Privacy
Financials
Three-year financials
- 2024:
- 2023:
- 2022:
Financial Resilience Score: 7/10
Have I Been Pwned (operated through Superlative Enterprises Pty Ltd) demonstrates strong qualitative financial resilience despite the absence of disclosed financial figures. As a small Australian proprietary company, it is exempt from public financial lodgement with ASIC, but Troy Hunt has publicly stated the business is profitable and self-funded with no external debt or VC overhang. The cost base is extremely low due to in-kind infrastructure sponsorship from Microsoft Azure and Cloudflare, which shields HIBP from major bandwidth and CDN expenses. Recurring revenue from API subscriptions (Pwned 1-5 tiers starting at US$3.50/month) and enterprise domain monitoring subscriptions provides predictable cash flow. The brand has become the de-facto standard for breach notification, integrated into 1Password, Mozilla Monitor, and major IAM tools, with institutional partnerships including the UK NCSC, US FBI, and Australian Signals Directorate. However, resilience is constrained by significant key-person risk centered on Troy Hunt personally—a dependency that contributed to the failed 2019-2020 'Project Svalbard' sale process. The business has no product or geographic diversification, depends heavily on Azure/Cloudflare in-kind support, and faces a monetization ceiling because public lookups remain free by founder philosophy. Regulatory exposure around handling stolen credential data also represents a latent risk.
Key strengths: Profitable and self-funded with no external debt or VC backing, Extremely low cost base due to Microsoft Azure and Cloudflare in-kind sponsorship, Recurring API and enterprise subscription revenue, De-facto industry standard brand integrated into major identity products (1Password, Mozilla Monitor), Institutional credibility via partnerships with UK NCSC, US FBI, and Australian agencies, 13 billion breached accounts indexed across 800+ breaches as of 2024
Risk factors: Key-person risk concentrated on Troy Hunt personally, Legal/regulatory exposure handling stolen credential data, Heavy dependence on Azure and Cloudflare in-kind infrastructure support, Monetization ceiling because public lookups remain free by design, No product or geographic diversification—single product, single founder, single jurisdiction, Failed 2019-2020 sale process highlighted buyer concerns about founder dependency
Revenue by geography
- United States: 45%
- United Kingdom: 25%
- Australia: 10%
- Western Europe: 10%
- Canada: 8%
- Rest of World: 2%
Revenue by product/service
- Enterprise Domain Subscriptions: 55%
- API Key Subscriptions (Pwned 1-5): 35%
- Pwned Passwords Commercial Licensing: 9%
- Donations and Sponsorships: 1%
Workforce by country
- Australia: 3
- Iceland: 1
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.