Skip to main content
DEX-01 · Exposure · 1 of 9 Modules

Your secrets, your code, your customer data — all the places you didn't mean to put them.

Public GitHub repos accidentally pushed by contractors. S3 buckets misconfigured during a migration. PDFs indexed by Google with PII inside. ShadowMap continuously monitors public sources for data and secrets attributable to your organisation, and tells you whose laptop or whose cloud account it came from.

5–15
Active secrets surfaced in first 30 days

In the first 30 days, average customer surfaces 5–15 active secret leaks they didn't know about — usually in repos owned by ex-employees or contractors.

What it discovers

Discovers, prioritises, and routes — automatically.

Code repositories, cloud buckets, paste sites, and document leaks — surfaced with secret scanning and ownership attribution.

01

Public-repo secret scanning

Continuous scanning of GitHub, GitLab, and Bitbucket public repos for AWS keys, API tokens, database creds, and internal-domain leaks attributable to your org.

02

Cloud-storage exposures

Open S3, GCS, Azure Blob, DigitalOcean Spaces, and exposed Elasticsearch / MongoDB indexed by your domain or staff email.

03

Paste-site monitoring

Pastebin, ghostbin, deepai, and 30+ other paste sites scanned for content matching your brand, customer names, or staff emails.

04

Indexed documents

Google + Bing dorking for filetype-specific exposures (PDF, XLS, DOC) hosted on your subdomains or referencing your customer data.

05

Internal-tool exposures

Misconfigured Jenkins, Jira, Confluence, GitLab CE, and similar internal tools indexed by Shodan or Censys.

06

Ownership attribution

Each finding traced back to the contributor, repo owner, cloud account, or asset that produced it — so remediation has a name attached.

07

Severity by impact

A leaked AWS root key in a public repo = page-the-CISO. A misconfigured staging Jenkins on a sandbox account = file a ticket. ShadowMap separates them automatically.

08

Auto-ticket for revocation

High-severity findings auto-create rotation/revocation tickets routed to the owning team, with the exact file:line reference and rotation steps.

How it works

From seed to remediation, in four steps.

1

Seed

Use your asset graph from Attack Surface + employee email patterns + brand keywords as the search seed.

2

Crawl

Continuous crawling of public-repo APIs, paste sites, search indexes, and cloud-bucket directories.

3

Match

Pattern + entropy detection for secrets; content matching for branded data; ownership attribution from commit metadata.

4

Triage

High-severity → page; medium → ticket; low → digest. Auto-revocation playbooks for known cloud-creds providers.

See Data Exposure on your own assets.

A 30-minute live walk-through with a ShadowMap engineer on your own domains. We map you live; you keep the report whether or not you choose to engage.