BREACH
The full password never leaves your browser. We hash it locally and only send the first 5 SHA-1 characters to the HIBP Pwned Passwords API using the k-anonymity range model.