Command Palette

Search for a command to run...

Identity Linking

Understand rarity-weighted identity evidence, graph traversal, safeguards, and API usage.

Evidence, not proof
Identity Linking assigns explainable evidence scores. A result can support an investigation, but it does not prove that two identifiers belong to the same person.

What the tool does

Start with an email, international phone number, or a username. LeakZero examines existing breach records for rare shared credential evidence, discovers service context internally, scores each connection, and follows only strong email or phone links. No extra profile fields are created and the breach database schema is not changed.

Email
Primary identifier; strong links can expand.
Phone
Primary identifier; normalized before matching.
Username
Service context is discovered internally, remains domain-scoped, and never expands.

How a connection is discovered

Known emailRare shared passwordCandidate phoneNext evidence round

Passwords are bridges, but their value depends on rarity. Multiple independent shared passwords are substantially stronger evidence than one. A matching service domain and a similar identifier name can support a link, but a domain never creates a link by itself.

Score and expansion rules

EvidenceEffectCan bridge alone?
Very rare shared passwordStrongSometimes
Several distinct shared passwordsVery strongYes
Shared service domainSupportingNo
Similar identifier nameSupportingNo
Common passwordIgnoredNo
Two thresholds
The display threshold controls what you can inspect. The higher expansion threshold controls what the engine may follow. Lowering the display threshold cannot make weak links expand.

Safety limits and edge cases

Finite traversal
Loops cannot run forever.
Every normalized identifier and password is processed once. Depth, time, identifier, password, evidence-row, and output budgets stop oversized neighborhoods deterministically.
Sensitive evidence
Correlation output masks password values.
Paths and evidence show a masked secret. Search logs contain only aggregate counts and stop reasons. Full breach searches keep their existing permissions and behavior.

Dashboard, Telegram, and API

The feature requires the breach_advanced_identity_linking subscription entitlement in every interface. Dashboard and Telegram searches consume one normal search row per returned candidate. Public API searches bill one API unit per returned candidate. Internal evidence rows are visible in metadata but are not billed.

curl -X POST https://api.leakzero.io/api/v1/public/search/identity-linking \
  -H "x-api-key: lz_..." \
  -H "x-timestamp: 2026-09-05T12:00:00Z" \
  -H "content-type: application/json" \
  -d '{
    "field": "email",
    "value": "[email protected]",
    "maxDepth": 2,
    "minConfidence": 0.35,
    "maxResults": 50,
    "includePossible": true
  }'
Documentation - LeakZero | LeakZero