Discovery
Find the AI nobody told you about
Shadow AI gets discussed as an employee-behaviour problem, which is the easy half. The expensive half is technical: a provider key shipped in a client bundle, a browser calling a model API directly, an agent a contractor left running. None of it shows up in a policy review, and all of it is yours.
Where it actually hides
- API keys and endpoints left in client-side bundles or exposed source maps.
- Direct browser-to-provider calls that never touch your backend and never appear in your logs.
- Prototypes that quietly became production, owned by whoever built them and documented nowhere.
- Contractor work still holding live credentials after the engagement ended.
What the check does
Every capability on this page carries its real status: shipped code, work we do inside a pilot, or a design we have not built yet.
Reads your product from the outside
Live todayGive it a URL. It fetches what a visitor's browser gets β scripts, headers, source maps β and reports what that already reveals about your AI setup. No account, no email wall, the full report is shown.
Findings with severity, evidence and confidence
Live todayEach finding carries a status, a severity, the evidence behind it and how confident the check is. What it could not determine is marked unknown, not quietly passed.
A permanent link to the report
Live todayEvery scan is stored and reopenable at its own URL, so you can send it to the team that owns the fix instead of screenshotting it.
Inventory that keeps itself current
Design intentDeriving a live inventory from governed traffic is the design. It needs a gateway we have not built, so today discovery is external plus whatever a pilot instruments.
A realistic first week
1. Scan your own product
Live todayTwo minutes, free, and it usually tells you something you did not know β most often about a bundle or a header.
2. Fix what is exposed externally
Live todayKeys in client code and direct provider calls are the findings worth acting on the same day, because anyone reading your bundle can act on them too.
3. Decide what governance you actually need
Pilot scopeSometimes the answer is a policy and two fixes, not a platform. We would rather scope that honestly than sell a pilot into a problem you just solved.
What exists today
- The External AI Exposure Check is live, free and requires no account; reports keep a permanent link.
- The report states its own limits: from a URL it cannot see server-side routing, budgets or internal systems.
- Scans are stored with the host, findings and a hashed IP β so aggregate stats exist without keeping raw addresses.
What we do not claim
- The scan is not a penetration test and not a full security audit.
- A URL cannot reveal internal systems. Anything we cannot see is marked "not checked", never "passed".
- We do not offer scanning of third-party domains as a service β point it at a product you are responsible for.
- Finding shadow AI is not governing it. The first is a report; the second is work we would scope with you.
Questions people actually ask
Is the external check really free?
Yes, and the whole report is shown without an email. The contact form appears only if you want a control review afterwards.
What exactly does it look at?
The public surface of the page: scripts and bundles, source maps when they are exposed, response headers, and signals of direct calls to model providers from the browser. It reports evidence, with secrets redacted in what it shows back.
Do you store our scan?
Yes β the host, the findings, the score and a hashed IP, so the report keeps a permanent link and we can count usage. We do not store raw IP addresses.
It found nothing. Are we fine?
It means nothing was visible from outside, which is a narrower statement. Server-side keys, internal agents and vendor integrations are invisible to a URL scan by definition.
Do we have to route everything through you afterwards?
No, and you could not today even if you wanted β that gateway is not built. External discovery needs nothing from you at all.
Run the check first, talk to us after
The scan costs nothing and you keep the report either way. If what it finds is worth a conversation, the form below reaches a person.
Prefer to check us first? The record structure is written out field by field on the evidence page, and the external check shows its full report without an email.
Also useful
Free, no signup β what your product reveals about its AI from the outside.
Security & data handlingRetention, keys, access, deployment options β with the gaps named.
Evidence pack structureField by field: what a record can hold, what exists today, what is design.
AI governance knowledge baseLonger write-ups on agent risk, monitorability and oversight.