Breach-watch is StretchVault's quick exposure scan. Where a full Watchtower review is the thorough, saved audit you run periodically, Breach-watch is the at-a-glance check you can look at any time to spot the credentials that need attention now.
What Breach-watch flags
Breach-watch scans a vault and labels each item with any risk flags that apply:
- Exposed — the item is marked as exposed, or its secret matched a common-breach list. StretchVault sets this automatically when a saved secret is found in a breach corpus.
- Reused — the same secret value appears on more than one item in the vault (detected by fingerprint, never by comparing plaintext).
- Weak — the strength score is below 60.
- Old — the secret hasn't been rotated in more than 180 days.
- No 2FA — the item's two-factor flag is off.
Only items with at least one flag appear in the findings, so the list is a focused to-do rather than a full inventory.
The security score
Breach-watch also returns a security score and a breakdown: the total number of items, how many are flagged, and a count of each flag type. The score reflects the overall risk in the vault — the more flags across your items, the lower it goes. It's a fast pulse-check; for the fully weighted, saved score and detailed recommendations, run Watchtower.
How to run Breach-watch
- Open the Breach-watch tab.
- Select the vault you want to scan.
- Read the summary: total items, flagged items, and the security score.
- Review the findings — each flagged item shows its flags, its strength score, and how many days old it is.
- Act on the flags: rotate exposed items, make reused items unique, strengthen weak ones, refresh old ones, and enable 2FA where it's missing.
A realistic example
Before a client hands over a new set of accounts, Meridian Studio drops them into the Client Credentials vault and runs Breach-watch. Instantly they see three items flagged: one exposed (a password that turned up in a breach list), one reused (the client used the same password on two systems), and two no 2FA. The account manager rotates the exposed and reused passwords with the generator and asks the client to enable 2FA. The whole triage takes a couple of minutes — no spreadsheet, no manual comparison.
Breach-watch vs. Watchtower at a glance
- Breach-watch — fast, always-on scan; flags at glance-friendly thresholds (weak below 60, old beyond 180 days); great for quick triage and onboarding new credentials.
- Watchtower — thorough, weighted security score; classifies with stricter thresholds; saves each run to Audit history; produces prioritized recommendations. Use it for periodic reviews and reporting.
Using both is the intended workflow: Breach-watch to catch problems the moment credentials arrive or change, Watchtower for the scheduled, on-the-record review.
Tips
- Run Breach-watch whenever you add a batch of credentials — it's the fastest way to catch a bad password before it's in production use.
- Treat any exposed flag as urgent; that password should be considered compromised and rotated immediately.
- Clear the no 2FA flags you can by enabling two-factor on the account and flipping the item's flag — it's the cheapest security win available.
- If the same value keeps showing as reused, generate unique replacements rather than tweaking one character; near-duplicates still fingerprint differently but remain guessable.
Troubleshooting
No items are flagged but I expected some. Breach-watch only flags items that have been analyzed. If items were saved before analysis was available, edit and re-save them (or run Watchtower) so their strength and exposure are recomputed.
An item shows "old" that I rotated recently. Age is measured from the last rotation (or creation) date. Make sure your rotation actually saved a new secret value on the item, which updates the date.
The scan won't run. Exposure analysis depends on the security engine. Check the Health tab and contact your administrator if the engine is offline.
FAQ
Is my password sent to a breach service? No. Reuse is detected locally by fingerprint, and breach matching is done against a bundled list — your plaintext secret never leaves StretchVault's secure boundary for these checks.
Was this helpful?
Help us improve this article
Use these controls to share whether this answer solved the issue. Feedback helps prioritize updates to StretchSuite Support.

