Public Data
Exposure Audit
A growing cloud and SaaS estate accumulates forgotten sites, shared links, public storage and credentials in old code. We identify what an outsider can reach and give the security owner a ranked remediation plan.
Find public files
Check the exposure
Assign the fix
You get a ranked list of data to close off.
Mapped
PUBLIC ASSETS WITHIN SCOPE
Evidenced
CONFIRMED EXPOSURES
Prioritised
FIXES WITH NAMED OWNERS
The report states the assets, sources and testing methods covered, including any limits on confirmation.
Exposed data is often found through automated scans
An exposed backup, public document or old credential can be found through search engines and automated scans. A forgotten service may still be reachable after the team stops using it.
We map public assets and check the agreed sources for sensitive material. Ownership and testing authority are confirmed before active checks.
The report distinguishes confirmed exposure, suspected exposure and areas that could not be checked.
ASSETS TO REVIEW
- Internal admin panels
- Staging and dev environments
- API keys, database passwords
- Customer files in cloud storage
- Internal Notion, Trello, Drive
- Old microsites you forgot about
POSSIBLE EXPOSURE
- Services recorded by public search tools
- Reachable subdomains and forgotten sites
- Material copied from public repositories
- Objects with overly broad storage access
- Documents accessible through shared links
- Abandoned service connections
Where exposed data usually turns up
The audit follows the public footprint across domains, cloud services, code, documents and third parties. The scope is based on the assets and data connected to your company.
Secrets in code
Credentials can remain usable after a file is deleted or repository history is rewritten. We look for exposure in public code and images, then help the owner assess rotation and access history.
Open buckets and disks
S3, Azure Blob, GCS containers set to "Public" by a developer in a hurry, then forgotten. Old backups served by Apache. .git/ and .env directories one URL away.
Databases on the open internet
We look for reachable database services and missing access controls. Supabase exposure depends on grants and row-level security policies, so the existence of a public client key alone is not proof of a leak.
SaaS oversharing
Shared documents, public boards, invitations and conversation links can expose information beyond the intended audience. We check what an unauthenticated visitor can actually reach.
Dead estate, live risk
Retired sites and abandoned service connections can remain reachable. We assess dangling DNS and forgotten environments against ownership and the provider's behaviour.
What the review gives you
We assess the public surface without credentials or internal assumptions. Confirmed findings include evidence, severity, ownership and a practical remediation route.
The scope, test boundaries, reporting route and urgent-notification process are agreed before the audit begins.
BOOK AN AUDITMap the attack surface
Domains, subdomains, IPs, certificates, cloud accounts you've forgotten. Shodan, Censys, amass, the Wayback Machine. We tell you what's yours before we tell you what's broken.
Hunt the leaks
We inspect agreed public repositories, images, shared pages and breach-notification sources. Credential validation requires specific authorisation and a safe method, and the report does not reproduce usable secrets.
Triage and fix the urgent things
Confirmed urgent exposure is escalated immediately. We agree containment and remediation with your owners, including credential rotation, access restrictions and evidence preservation.
Leave you something to run
A short closing checklist for your team. Optional monitoring so you get an alert the next time a key hits GitHub or a new subdomain wakes up. Re-audit quarterly if you want it on a calendar.
When this is worth discussing
We work best when there is a real operating problem, enough volume to measure and people from the affected teams who can make decisions.
Usually a good fit
- An established UK business, usually with annual revenue above £10m
- A repeated process with a known cost, delay, error rate or capacity problem
- A senior sponsor and a day-to-day owner who understand the work
- Access to the relevant staff, systems, sample records and security requirements
We may point you elsewhere
- A standard product already covers the process well
- The requirement is a one-off small build with no wider operating case
- There is no owner or access to the people and data needed to test the result
- The plan relies on AI making high-impact decisions with nobody responsible for review
Questions from IT, legal and compliance
Isn't this just a pen test?
They answer different questions. A penetration test attacks a defined target. This audit maps the public assets and data associated with the company, including items the security team may not know about. The right order depends on your current asset inventory and testing programme.
We're a small company. Are we really a target?
Automated scans can discover exposed assets without selecting the company in advance. The useful question is whether sensitive information or services are reachable, rather than the company's size.
What do you need from us?
We need the domains, brands and known assets, plus written scope and a contact for urgent findings. Internal access or active confirmation is agreed separately where needed.
Is this legal? Don't you need permission to scan things?
We agree the scope and testing methods with you in writing. We use public data and sources designed to be queried, such as Shodan, Censys, GitHub search and the Wayback Machine. We don't exploit systems or log in without specific authorisation. If a finding needs active confirmation, we agree that step before doing it.
How long does it take?
The timetable depends on the number of domains, cloud accounts and public products in scope. We agree the coverage before testing and report any live high-risk exposure as soon as it is confirmed rather than waiting for the final report.
What about Cyber Essentials and our ISO?
The findings can support your wider security programme by identifying assets and configuration gaps. They do not replace Cyber Essentials assessment, penetration testing or ISO/IEC 27001 certification.
What if you find something serious?
We report confirmed live exposure immediately and help your owners assess containment. Privacy and legal owners decide notification duties. A reportable personal data breach must be notified without undue delay and, where feasible, within 72 hours of awareness. See ICO breach-response guidance.
How much?
The standard audit is fixed-fee. Remediation is priced against the findings once you have seen the report, and ongoing monitoring is quoted separately with its coverage and response terms.
Book a public data exposure audit
Give us the company domains, public products and known cloud estate. We will define the external surface, reporting route and immediate escalation process before testing begins.