Source and evidence handling
Where our material comes from, how it is stored, and what can and cannot become public.
Effective
Where material comes from
ThreatBharat draws on publicly reachable material — leak-site listings, criminal forum posts, paste sites, official disclosures, regulatory notices, vendor advisories and independent reporting — together with information given to us directly by affected organisations and researchers.
We record where each signal came from and weigh its reliability. A criminal forum post and a regulator’s notice are not treated as equivalent, and reports say which kind of source underpins them.
What we do not do to obtain material
- We do not buy stolen data, and we do not pay threat actors.
- We do not access systems without authorisation, attempt intrusion, or use credentials that appear in a breach.
- We do not download or hold breached datasets in order to “confirm” them.
- We do not solicit stolen data from sellers, or pose as a buyer to obtain samples.
Two classes of evidence
Every screenshot on this platform exists in two forms, and the distinction is enforced by the system rather than by convention.
The original capture is what an analyst recorded. It may contain unredacted personal data, seller handles, or routes to stolen material. It is stored privately, versioned so it cannot be silently overwritten, and is never served publicly. There is no URL, signed or otherwise, that makes an original capture publicly retrievable.
The public derivative is a separate, redacted image prepared for publication. It becomes publicly visible only after a reviewer who is not its author explicitly approves the redaction. Until then it behaves exactly like material that does not exist.
How approval actually works
Public delivery re-derives the full permission chain on every single request: the report must be public and published, the image must belong to that report, and its redaction must be approved. Nothing is inferred from the URL beyond two identifiers.
A consequence worth stating plainly: if approval is withdrawn or a report is retracted, a link that was already shared stops working immediately. It does not continue to serve from a cache of its own.
Every refusal is identical. An original capture, an unapproved derivative, an image belonging to a different report, and an identifier that never existed all return the same “not found” response, so the response cannot be used to probe what exists.
Protecting people who contact us
If you send us information, we do not publish your identity. We do not confirm to a third party — including a named organisation or a law-enforcement body — that a particular person contacted us, unless you have asked us to or we are compelled by a lawful order that we cannot resist.
We hold correspondence for as long as it is needed to substantiate a published report, and we can remove your contact details from our records on request while retaining the substantive intelligence.
If you need to reach us with something sensitive, write to security@threatbharat.com and ask for a secure channel before sending detail.
Retention
- Published reports are retained indefinitely as a public record, subject to correction and retraction.
- Original captures are retained while the report they support is published, because they are the chain-of-custody evidence for it.
- Withdrawn or rejected derivatives stop being publicly reachable immediately and are removed from the public projection.
- Correspondence is retained while it is relevant to a published report or an open enquiry.
Requests to remove material
If a published report contains material that should not be there — personal data, an unredacted detail, or a factual error — tell us and we will assess it promptly. Use corrections and retractions, or write to support@threatbharat.com. A removal request about personal data is treated as urgent.
We will not remove a report simply because its subject would prefer it were not published. We will always correct what is wrong.