Every business has an attack surface it cannot see: the subdomains it forgot, the staging server still on the public internet, the .env file one deploy left readable, the API key that shipped inside a frontend bundle. Attackers map this surface constantly and cheaply. Most companies have never looked at it once.
The external exposure report is that look, done properly. It is the same reconnaissance an outside attacker performs — from the public internet, with no source code, no credentials, and no server access — turned into a written, prioritized report you can act on before it becomes an incident.
From $1,999 · fixed-price external exposure report
Outside-in, exactly as a stranger sees you
This is the counterpart to the AI-built codebase audit. That one reads your source from the inside; this one assumes nothing and starts where a real adversary starts — with your domain name and a search box. What can be discovered, enumerated, and probed about your systems without ever touching a file you gave us?
The answer is almost always more than the business expected. That gap is the point of the exercise: you cannot defend an exposure you do not know you have.
What we map
Forgotten and stale assets: subdomains, staging and development environments, and old deployments still reachable from the internet. Outdated software with known CVEs, missing or weak security headers, and weak TLS configuration. Accidentally exposed files — readable .env or .git directories — and secrets shipped in your public frontend bundle.
We also check whether the guarantees you think you have actually hold: is your row-level security really enforced when the public API is hit directly, or only when the UI politely asks? And we surface injection and OSINT exposure discoverable without touching a single file.
Non-intrusive by default, authorized before anything active
Reconnaissance is non-intrusive: it observes what is already public. Any active testing — anything that sends traffic designed to probe rather than merely to browse — happens only inside a signed, countersigned scope of work, and only once we have confirmed the target is yours to test. We begin no scanning of any kind until that authorization is in place.
That discipline is not bureaucracy. Testing systems you are not authorized to test is a crime, and a firm that is casual about authorization is a firm that will eventually be casual with your systems too.
From one-time report to continuous monitoring
The report is a point-in-time snapshot: here is what you expose today, ranked by severity, with a remediation step for each finding. But your attack surface changes every time you ship. Continuous exposure monitoring attaches after the initial report and re-runs the assessment on a recurring cadence, flagging newly exposed assets and misconfigurations as they appear — from $499/month, under the same signed authorization.
The goal is simple: be the one who finds the forgotten staging server, not the one who reads about it in a breach notification.