Monarx has launched Dark Web Monitoring, a white-label service that hosting providers and registrars resell to their own customers, and says the first partners go live in September. The product’s defining choice is where it starts. A host supplies a customer’s domain, and the company says the service then matches breach data against every email address at that domain.
The company traces the timing to what it keeps finding. In recent launches, Monarx says, compromised credentials have turned up across more than 60 percent of a provider’s customer base. Exposure at that level feeds account takeovers, fraud and phishing. The company argues that the older pattern of discovering an incident and working through it by hand no longer keeps pace, because the rise of AI has made exposed data quicker to collect, analyze, combine and weaponize.
Key facts
- Why now: compromised credentials across more than 60 percent of a provider’s customer base in recent launches, according to Monarx. The figure describes its own deployments and no sample was given.
- Setup: domain-first, described by the product page as requiring only a domain to begin. Monarx says it processes breach data for any email address at the monitored domain, and that external addresses such as Gmail accounts are not associated with it automatically.
- What the customer sees: which categories of their data were breached, for example Social Security numbers, bank accounts, passwords or government-issued IDs, without the underlying values. That gives the customer a signal to act on, and masked values are the next addition.
- Scale: 800 billion-plus compromised credentials, 55 billion-plus breached accounts and 100 terabytes-plus of indexed intelligence back to 2014, scanned for 85 data types across five categories.
- Commercials: suggested retail of $1.99 to $9.99 a month, on a revenue share the company describes as starting at 50/50. Integration by API, with a white-label portal, and the host bills through its own system.
One Domain, Every Address Under It
The setup model is where Monarx aims to remove a step. Rather than starting with a list of addresses to watch, it begins with a domain the host already holds in its own records. In written answers, Luke Langford, chief executive of Monarx, put it plainly: “We process all breach data for any email at that domain.”
The boundary sits at the domain. External addresses such as the Gmail account a small business owner uses for signups can also be monitored, but Langford said Monarx does not automatically associate them with the domain. The domain therefore brings coverage of the addresses using it. That reach is not limited to live mailboxes: the company says the product can identify addresses connected to the monitored domain whether or not those mailboxes are currently active.
What the Report Shows the Customer
The report tells a customer which categories of their data have surfaced in a breach. Asked what that looks like today, Langford was direct: “Customers currently only see the categories of data that have been breached.” He gave Social Security numbers, bank account numbers, passwords and government-issued IDs as examples. A customer learns that payment card data was exposed in a given breach, which is the signal to act on that card, without the report displaying any part of the number.
Staying at category level has a second effect a provider will notice: no client’s national identification number is displayed under the host’s own brand. On data protection, the company points to secure access, data minimization, controlled processing and masking as how the service supports providers operating under the General Data Protection Regulation, and notes that the data in question is already exposed on the dark web.
Masked values are the next addition, marked on the product page as coming soon. Langford described the intended form as showing something like the last four digits of a card, enough for a customer to recognize an alert as their own while the complete value stays hidden.
What the Host Sells
The commercial shape is built for volume. The product page suggests retail pricing of $1.99 to $9.99 a month per domain. The standard starting point for partners is a 50/50 revenue share, Monarx says, with terms varying by partner size, deployment and go-to-market approach. Integration is by API into existing hosting, account management and billing systems, with a white-label portal partners can put in front of customers, and the host continues to bill through whatever it already uses, WHMCS or otherwise.
The page carries a calculator for the revenue this might produce, and its worked example takes a portfolio of 100,000 domains at a 10 percent opt-in attach rate and $5 a month, arriving at $600,000 of annual recurring revenue before revenue share, tax, churn or discounts. The page adds its own caution that the results are directional estimates and should not be presented as guaranteed revenue. Monarx did not provide attach-rate or revenue-per-user figures from live deployments; the first hosting and registrar partners are scheduled to go live in September.
The Numbers Behind the Matching
Monarx puts the dataset at more than 800 billion compromised credentials and 55 billion breached accounts, drawn from over 100 terabytes of indexed intelligence with coverage reaching back to 2014. The service scans for 85 data types across five categories: personal information including names, addresses and national identification numbers; password data including clear, hashed and salted forms; social and account identifiers; financial details including card numbers, bank accounts and cryptocurrency addresses; and technical fields such as IP addresses and customer identifiers. The figures describe different layers of the service: 85 is the number of data types monitored, while 800 billion refers to the compromised credentials in the dataset.
Asked how the service compares with free resources, the company’s answer was breadth. Services like Have I Been Pwned are valuable, Monarx says, but represent a subset of exposed data, while its own ingestion runs across the public web, deep web and dark web rather than any single breach database. That range is what the company puts forward as the main difference.
What the Host Hands the Customer
Alerts are surfaced as new breaches are processed rather than on a scan schedule, which is where the speed argument becomes a product decision. What follows is guidance rather than actions the service performs, and the work it calls for happens elsewhere: changing a compromised password, enabling multi-factor authentication, securing another affected account, arranging credit monitoring.
Monarx describes the point of that guidance as helping a customer understand the risk and act before the exposure becomes a larger incident, rather than simply telling them their data is out there. Because the experience is white-labeled, providers will also need to decide how it fits into their existing customer support workflow.
About the Data
The monitoring boundary, what customers see today, the revenue share and the launch timing come from written answers Monarx provided to us, the most recent of them attributed to chief executive Luke Langford. The company also supplied its account of why it built the product now, including the finding that compromised credentials have appeared across more than 60 percent of a provider’s customer base in recent launches. That figure describes Monarx’s own deployments; it did not name the providers or give a sample size. Prices are those displayed on the product page on September 7, 2026.