Discovery

Find the AI nobody told you about

Shadow AI gets discussed as an employee-behaviour problem, which is the easy half. The expensive half is technical: a provider key shipped in a client bundle, a browser calling a model API directly, an agent a contractor left running. None of it shows up in a policy review, and all of it is yours.

Where it actually hides

  • API keys and endpoints left in client-side bundles or exposed source maps.
  • Direct browser-to-provider calls that never touch your backend and never appear in your logs.
  • Prototypes that quietly became production, owned by whoever built them and documented nowhere.
  • Contractor work still holding live credentials after the engagement ended.

What the check does

Every capability on this page carries its real status: shipped code, work we do inside a pilot, or a design we have not built yet.

Reads your product from the outside

Live today

Give it a URL. It fetches what a visitor's browser gets — scripts, headers, source maps — and reports what that already reveals about your AI setup. No account, no email wall, the full report is shown.

Findings with severity, evidence and confidence

Live today

Each finding carries a status, a severity, the evidence behind it and how confident the check is. What it could not determine is marked unknown, not quietly passed.

A permanent link to the report

Live today

Every scan is stored and reopenable at its own URL, so you can send it to the team that owns the fix instead of screenshotting it.

Inventory that keeps itself current

Design intent

Deriving a live inventory from governed traffic is the design. It needs a gateway we have not built, so today discovery is external plus whatever a pilot instruments.

A realistic first week

1. Scan your own product

Live today

Two minutes, free, and it usually tells you something you did not know — most often about a bundle or a header.

2. Fix what is exposed externally

Live today

Keys in client code and direct provider calls are the findings worth acting on the same day, because anyone reading your bundle can act on them too.

3. Decide what governance you actually need

Pilot scope

Sometimes the answer is a policy and two fixes, not a platform. We would rather scope that honestly than sell a pilot into a problem you just solved.

What exists today

  • The External AI Exposure Check is live, free and requires no account; reports keep a permanent link.
  • The report states its own limits: from a URL it cannot see server-side routing, budgets or internal systems.
  • Scans are stored with the host, findings and a hashed IP — so aggregate stats exist without keeping raw addresses.

What we do not claim

  • The scan is not a penetration test and not a full security audit.
  • A URL cannot reveal internal systems. Anything we cannot see is marked "not checked", never "passed".
  • We do not offer scanning of third-party domains as a service — point it at a product you are responsible for.
  • Finding shadow AI is not governing it. The first is a report; the second is work we would scope with you.

Questions people actually ask

Is the external check really free?

Yes, and the whole report is shown without an email. The contact form appears only if you want a control review afterwards.

What exactly does it look at?

The public surface of the page: scripts and bundles, source maps when they are exposed, response headers, and signals of direct calls to model providers from the browser. It reports evidence, with secrets redacted in what it shows back.

Do you store our scan?

Yes — the host, the findings, the score and a hashed IP, so the report keeps a permanent link and we can count usage. We do not store raw IP addresses.

It found nothing. Are we fine?

It means nothing was visible from outside, which is a narrower statement. Server-side keys, internal agents and vendor integrations are invisible to a URL scan by definition.

Do we have to route everything through you afterwards?

No, and you could not today even if you wanted — that gateway is not built. External discovery needs nothing from you at all.

Run the check first, talk to us after

The scan costs nothing and you keep the report either way. If what it finds is worth a conversation, the form below reaches a person.

Prefer to check us first? The record structure is written out field by field on the evidence page, and the external check shows its full report without an email.

Request a control review

Email or Telegram is enough. A person replies; there is no automated sales sequence.

Also useful

Other problems we cover