Check whether your company domain appears in the public FortiBleed domain dataset. Results are shown only after verifying a company email from the same domain.
This lookup does not confirm that a system is compromised. Assess any result in your organization's context.
FortiBleed Check FAQ
What does the FortiBleed Check look up?
It compares an exact normalized company domain with the sanitized public FortiBleed domain dataset provided to Vigilbase. The result includes the dataset source and retrieval date.This is a dataset snapshot, not a live scan of your Fortinet devices or a search of every credential exposure. Read the retrieval date when deciding how current the evidence is.Compare the public security checksPrivacy and data handling
Does a FortiBleed match prove that our systems are compromised?
No. A match means the domain appears in the dataset. Vigilbase has not independently confirmed the underlying credentials or a current compromise of your systems.A result that is not listed is also limited to that dataset. Treat either outcome as one piece of evidence alongside your authentication logs, account history and endpoint telemetry.Managed detection and response explainedEndpoint detection and response explained
Why must I verify a company email for FortiBleed results?
The result can imply credential exposure, so access requires a verified email from the checked company domain or an allowed parent company domain. Results are bound to the verified email and domain.This access check is not authorization to test devices or other organizations. FortiBleed remains a browser-gated sensitive lookup and is not available through the public agent execute API.Tool access and verification requirementsPrivacy and data handling
What should we do if our domain is listed?
Ask your security owner to review the relevant Fortinet access and authentication evidence. Investigate affected accounts, possible credential reuse and signs of unauthorized access before deciding the response.Where exposure is confirmed, coordinate credential rotation, session review and further investigation through your incident process, then verify the outcome. The lookup itself does not reset credentials or contain an incident.Managed detection and response explainedSupport channels and escalation