Enya Security
Request an audit
SERVICE

Online
exposure analysis

Discover what information about your business is publicly accessible, and what an attacker can find without even targeting you.

100% passive
zero impact
Attacker's view
OSINT method
Clear report
ranked by priority
Methodical
and actionable
Response within 24-48 business hours
Domains & subdomains
Cloud & storage
GitHub & code
TLS/SSL certificates
Services & open ports
Breaches & databases
Email & messaging
Social networks

WHAT WE LOOK FOR

Internet footprint

  • Domains & subdomains
  • DNS, IP addresses & hosting
  • Detected technologies
  • Certificates & expiry dates
  • Public pages & services

Email security

  • SPF, DKIM and DMARC records
  • Look-alike domains
  • Spoofing risk
  • Exposed configurations
  • Leaked email addresses

Public data

  • GitHub repositories & source code
  • Cloud buckets & storage
  • Forgotten files & backups
  • Web archives & documents
  • Exposed sensitive information

Visible weaknesses

  • Exposed versions & technologies
  • Known CVEs
  • Open ports & services
  • HTTP security headers
  • Risky configurations

OUR APPROACH IN 6 STEPS

1

Scoping

Defining the perimeter and objectives.

2

Collection

Gathering public information from OSINT sources.

3

Analysis

Reviewing your footprint and the risks it creates.

4

Scoring

Overall exposure score and prioritisation.

5

Report

A clear report with findings and recommendations.

6

Action plan

A remediation plan to reduce your exposure.

DELIVERABLES

  • Password-protected PDF report

    5-7 pages (Express) to 12-18 pages (Premium)

  • Overall exposure level

    Scale from 🟢 Low to 🔴 Critical

  • Summary table by domain
  • Prioritised action plan

    P1 (48h), P2 (2 weeks), P3 (30 days)

  • Executive summary

    Included in Premium — written in plain language

  • Debrief call

    30 min (Standard) · 45 min (Premium)

WHY ENYA SECURITY?

  • Entirely passive analysis

    No access to your systems, no risk of disruption.

  • A real attacker's perspective

    The same sources an attacker uses: OSINT, Shodan, breach databases, public repositories.

  • Strict confidentiality

    Password-protected report, data deleted within 30 days.

  • Optional Dark Web module

    Strictly passive research, only on written confirmation.

  • Transparency

    Fixed fees, no surprises.

FREQUENTLY ASKED QUESTIONS

Can this analysis affect my website or systems?

No. The analysis is entirely passive and non-intrusive: public DNS queries, WHOIS lookups, and consultation of tools such as Shodan or Censys in passive mode. No exploitation of vulnerabilities, no active testing, no access to your internal systems.

Do you need access to my systems?

No internal access is required: no client VPN, no direct connection. The analysis covers only what is visible and publicly accessible from the internet.

What is the Dark Web module?

A read-only, passive search across publicly accessible sources (Ahmia, ransomware.live, Hudson Rock), carried out from an isolated environment. No registration, no purchase, no contact with malicious actors. Available as an option (+€150) on all tiers, with mandatory written confirmation before it runs.

How long does the analysis take?

Working time varies by tier: around 4 hours for Express (delivery within 5 days), 7 hours for Standard (7 days), 10 hours for Premium (10 business days from receipt of the signed Rules of Engagement).

Is the report confidential?

Yes. The report is password-protected, with the password sent separately, and intended solely for your organisation. Technical data collected is deleted 30 days after delivery, and the confidentiality obligation remains in force for 5 years after the engagement ends. More detail in our privacy policy.

Curious what an attacker can already see about your business?

Tell us about your situation and get a tailored quote in under 48 hours.

Request an analysis Response within 24-48 business hours