Skip to main content
Success
[PRO SERVICES / SECURITY & GOVERNANCE]

Public Data
Exposure Audit

A growing cloud and SaaS estate accumulates forgotten sites, shared links, public storage and credentials in old code. We identify what an outsider can reach and give the security owner a ranked remediation plan.

HOW IT WORKS
1

Find public files

2

Check the exposure

3

Assign the fix

You get a ranked list of data to close off.

Mapped

PUBLIC ASSETS WITHIN SCOPE

Evidenced

CONFIRMED EXPOSURES

Prioritised

FIXES WITH NAMED OWNERS

The report states the assets, sources and testing methods covered, including any limits on confirmation.

[THE OPERATING PROBLEM]

Exposed data is often found through automated scans

An exposed backup, public document or old credential can be found through search engines and automated scans. A forgotten service may still be reachable after the team stops using it.

We map public assets and check the agreed sources for sensitive material. Ownership and testing authority are confirmed before active checks.

The report distinguishes confirmed exposure, suspected exposure and areas that could not be checked.

ASSETS TO REVIEW

  • Internal admin panels
  • Staging and dev environments
  • API keys, database passwords
  • Customer files in cloud storage
  • Internal Notion, Trello, Drive
  • Old microsites you forgot about

POSSIBLE EXPOSURE

  • Services recorded by public search tools
  • Reachable subdomains and forgotten sites
  • Material copied from public repositories
  • Objects with overly broad storage access
  • Documents accessible through shared links
  • Abandoned service connections
[WHAT WE LOOK FOR]

Where exposed data usually turns up

The audit follows the public footprint across domains, cloud services, code, documents and third parties. The scope is based on the assets and data connected to your company.

01

Secrets in code

Credentials can remain usable after a file is deleted or repository history is rewritten. We look for exposure in public code and images, then help the owner assess rotation and access history.

02

Open buckets and disks

S3, Azure Blob, GCS containers set to "Public" by a developer in a hurry, then forgotten. Old backups served by Apache. .git/ and .env directories one URL away.

03

Databases on the open internet

We look for reachable database services and missing access controls. Supabase exposure depends on grants and row-level security policies, so the existence of a public client key alone is not proof of a leak.

04

SaaS oversharing

Shared documents, public boards, invitations and conversation links can expose information beyond the intended audience. We check what an unauthenticated visitor can actually reach.

05

Dead estate, live risk

Retired sites and abandoned service connections can remain reachable. We assess dangling DNS and forgotten environments against ownership and the provider's behaviour.

[HOW WE WORK]

What the review gives you

We assess the public surface without credentials or internal assumptions. Confirmed findings include evidence, severity, ownership and a practical remediation route.

The scope, test boundaries, reporting route and urgent-notification process are agreed before the audit begins.

BOOK AN AUDIT
01

Map the attack surface

Domains, subdomains, IPs, certificates, cloud accounts you've forgotten. Shodan, Censys, amass, the Wayback Machine. We tell you what's yours before we tell you what's broken.

02

Hunt the leaks

We inspect agreed public repositories, images, shared pages and breach-notification sources. Credential validation requires specific authorisation and a safe method, and the report does not reproduce usable secrets.

03

Triage and fix the urgent things

Confirmed urgent exposure is escalated immediately. We agree containment and remediation with your owners, including credential rotation, access restrictions and evidence preservation.

04

Leave you something to run

A short closing checklist for your team. Optional monitoring so you get an alert the next time a key hits GitHub or a new subdomain wakes up. Re-audit quarterly if you want it on a calendar.

[A USEFUL FIRST CONVERSATION]

When this is worth discussing

We work best when there is a real operating problem, enough volume to measure and people from the affected teams who can make decisions.

Usually a good fit

  • An established UK business, usually with annual revenue above £10m
  • A repeated process with a known cost, delay, error rate or capacity problem
  • A senior sponsor and a day-to-day owner who understand the work
  • Access to the relevant staff, systems, sample records and security requirements

We may point you elsewhere

  • A standard product already covers the process well
  • The requirement is a one-off small build with no wider operating case
  • There is no owner or access to the people and data needed to test the result
  • The plan relies on AI making high-impact decisions with nobody responsible for review
[QUESTIONS]

Questions from IT, legal and compliance

Q.01

Isn't this just a pen test?

They answer different questions. A penetration test attacks a defined target. This audit maps the public assets and data associated with the company, including items the security team may not know about. The right order depends on your current asset inventory and testing programme.

Q.02

We're a small company. Are we really a target?

Automated scans can discover exposed assets without selecting the company in advance. The useful question is whether sensitive information or services are reachable, rather than the company's size.

Q.03

What do you need from us?

We need the domains, brands and known assets, plus written scope and a contact for urgent findings. Internal access or active confirmation is agreed separately where needed.

Q.04

Is this legal? Don't you need permission to scan things?

We agree the scope and testing methods with you in writing. We use public data and sources designed to be queried, such as Shodan, Censys, GitHub search and the Wayback Machine. We don't exploit systems or log in without specific authorisation. If a finding needs active confirmation, we agree that step before doing it.

Q.05

How long does it take?

The timetable depends on the number of domains, cloud accounts and public products in scope. We agree the coverage before testing and report any live high-risk exposure as soon as it is confirmed rather than waiting for the final report.

Q.06

What about Cyber Essentials and our ISO?

The findings can support your wider security programme by identifying assets and configuration gaps. They do not replace Cyber Essentials assessment, penetration testing or ISO/IEC 27001 certification.

Q.07

What if you find something serious?

We report confirmed live exposure immediately and help your owners assess containment. Privacy and legal owners decide notification duties. A reportable personal data breach must be notified without undue delay and, where feasible, within 72 hours of awareness. See ICO breach-response guidance.

Q.08

How much?

The standard audit is fixed-fee. Remediation is priced against the findings once you have seen the report, and ongoing monitoring is quoted separately with its coverage and response terms.

Vu Agency security audit session

Book a public data exposure audit

Give us the company domains, public products and known cloud estate. We will define the external surface, reporting route and immediate escalation process before testing begins.

[MORE PRO SERVICES]

More from Security & Governance

Every Pro Service page covers what it is, who it fits and how to start. The full list is in the footer below.

Message us on WhatsApp