External Exposure Audit

We map your company the way an attacker does — every domain, forgotten host, and exposed login — then hand you the short list that matters.

Nobody breaks in through the front door. They find the thing you forgot.

The staging environment that was going to be temporary. The campaign microsite from a launch three years ago, still running an unpatched CMS. The admin panel on a subdomain that was never meant to be public. The API key a developer committed to a public repository in 2022. The cloud bucket holding four years of creative assets and one spreadsheet of customer emails.

None of it is in anyone's asset inventory, because there is no asset inventory. That's the first thing this audit produces.

What We Map

Everything you own that's reachable. Domains, subdomains, forgotten hosts, IP ranges, cloud storage, and infrastructure left behind by acquisitions and previous agencies. This is where the surprises live.

Exposed interfaces. Admin panels, login pages, database tools, dev environments and internal applications that ended up publicly routable.

Email security posture. SPF, DKIM and DMARC — configured, or configured in a way that lets anyone send mail as you. Usually the second one.

Certificate and TLS hygiene. Expiring certificates, weak configurations, and certificate transparency logs revealing hosts you never announced.

Software and version exposure. Publicly identifiable technology with known vulnerabilities, especially the CMS instances that stopped being maintained when the person running them left.

Third-party scripts. Everything loading on your site from someone else's server, and what each one can see.

Credential and data leakage. Company credentials in breach data, secrets in public repositories, sensitive files indexed by search engines.

Your public shape. What an attacker can learn about your people, tools and structure before sending the first email.

A Scan Is Not an Assessment

Run a commercial scanner against a mid-sized company and you get four hundred findings. Most are informational. A meaningful share are false. Nobody reads it, nothing gets fixed, and the report becomes a compliance artifact instead of a security one.

We verify by hand. You get the findings a real attacker could realistically use, ranked by exploitability rather than by the number the scanner printed. If that's six items, the report is six items long — each with what it is, why it matters in your specific environment, and how to close it.

What You Get

  • A complete external asset inventory, often the first one you've had
  • Verified findings ranked by real-world exploitability
  • An executive summary a non-technical board will follow
  • Technical detail your engineers can act on directly
  • A remediation walkthrough call, not just a PDF

Why Aragil

Half of what we find is marketing infrastructure. Old landing pages, campaign domains, tracking servers, agency-hosted assets, tools someone signed up for with a company card.

We know how that layer gets built, because we build it. We know what a departing agency leaves behind, because we've inherited enough of it.

Questions We Get Asked

Is this the same as a penetration test?
No. This maps and verifies what's exposed. A penetration test actively attempts exploitation against a defined target. Most companies should do this first — it tells you what's worth testing.

Will this disrupt anything?
No. The work is non-intrusive and runs against publicly available surfaces. Nothing is exploited, nothing goes down.

How often should we repeat it?
Annually as a baseline, or after anything that changes your footprint — a rebrand, an acquisition, a platform migration, an agency change.

Ready to take the first step?