External Exposure Security

Find what your website exposes unintentionally.

Public secrets, API keys, open paths, and misconfigurations. The engine finds them and ranks the findings.

AI assists with classifying and prioritizing findings.

  • Clearly defined scan scope
  • No intentional service interruption
  • Secrets and PII are redacted

ReconSec Security Assessment

demo-company.de

Demo
  • Critical1
  • High3
  • Medium6
  • Low8

Attack surface

Secrets API / OpenAPI TLS / DNS JS / source maps

Recent findings

  • Critical Source map with keys and PII
  • High JS bundle with API paths
  • High OpenAPI without access control
  • Medium DMARC policy missing

How the security check works

  1. 01

    Name the domain

    Tell us the website whose publicly reachable surface you want reviewed.

  2. 02

    Confirm authorization

    Confirm that you own or operate the site, or that you have the authority to request the security check.

  3. 03

    Receive results

    Our analysis engine works through the agreed scope layer by layer. You then receive the first findings and their context by email.

What can anyone reach that was never meant to be public?

Not just the visible page. Keys, source maps, admin paths, weak headers, and mail records can sit in public too.

Depending on scope, the engine looks for:

  • API keys, secrets, and PII Keys, tokens, and personal details in public JS bundles and source maps. Redacted in findings.
  • Source maps and code Original sources, internal paths, and API routes, if the map is reachable without a login.
  • Open paths and API docs Health, admin, OpenAPI, or config files, if they answer without a login.
  • Security headers and CORS Missing or weak headers, as far as the origin advertises them.
  • TLS, DNS, and mail Certificate, name resolution, MX, SPF, and DMARC.

Not just find it. Understand it.

The engine fetches public source maps, bundles, and paths, then looks for keys, secrets, and other exposures. AI classifies: what it is, why it matters, what to do next.

Found by ReconSec

Public source map on demo-company.de

/static/js/main.8f2a.js.map

Secrets and PII redacted

STRIPE_SECRET_KEY = sk_live_••••••••••••••••OPENAI_API_KEY = sk-••••••••••••••••••••AWS_ACCESS_KEY_ID = AKIA••••••••••••Name = M•••••• S••••••Email = m••••••@example.de

Context

Priority High
Why it matters

A public source map can expose build secrets and personal data with no login. That is the same path stolen credentials and keys take onto the open web.

Next step

Stop serving the map. Rotate the exposed keys. Ship bundles without sourcesContent.

From a signal to a finding you can use.

Each finding should say what, where, why it matters, what priority, and what to do next.

Executive summary

Security Health

61 / 100

Demo with no real customer data. Findings ordered by severity, surface, and next step.

Findings by severity

Critical 1
High 4
Medium 8
Low 12

Categories

ExposureConfigurationWebAPIDNSData
Critical

Publicly reachable source map with API keys and original sources

Web · demo-company.de

Why it matters
Source maps can expose internal paths, comments, and secret-shaped strings from the build, with no login required.

Next step
Stop serving the map publicly and ship bundles without sourcesContent.

High

OpenAPI specification without access control

API · demo-company.de

Why it matters
A publicly reachable specification shows endpoints and data models that were often not meant for anonymous users.

Next step
Put the docs behind authentication, or limit them to what is intentionally public.

A security check needs clear limits.

You set the scope

The requested website or domain is recorded as part of the assessment request.

You confirm authorization

You must confirm that you own or operate the system, or that you are expressly authorized to request the security check.

We stay inside the agreed frame

ReconSec examines the external surface covered by the agreed assessment. The standard assessment is not designed to modify systems, interrupt services, or manipulate data.

What is reachable from outside is already visible.

12,195

Confirmed data breaches in Verizon’s 2025 DBIR, from 22,052 incidents.

Source: Verizon DBIR 2025

Frequently asked questions

(01) What does ReconSec check?

The public part you authorize: secrets and API keys, source maps, open paths and API docs, security headers, TLS, DNS, and mail. The frame is in the Scan Scope.

No. The standard check stays on the public surface. No DDoS, no intentional interruption, no destructive change. A deeper assessment can be agreed separately.

No. You must own or operate it, or be expressly authorized to request the check.

So we can attribute the request. The address must belong to the website’s domain, for example max@example.de for shop.example.de. Results go to that address.

We document the exposure, not the people. Personal details in findings are masked where possible.

Not as a permanent archive. Results only as long as delivery requires. Request and authorization records stay separate.

By email after we review the request. The public request is without charge.

Yes. Scope, window, and deliverables are then agreed separately.

What on your website is publicly reachable without you knowing?

Let the engine check which secrets, open paths, and misconfigurations are publicly reachable. You get a prioritized overview.