What you receive
Relevant exposure findings, supporting source context and recommended investigative actions.
Relevant exposure findings, supporting source context and recommended investigative actions.
Your technical and communications owners confirm relevance and coordinate the response.
Repeat monitoring, account investigation and takedown support are separate scopes.
A clearly defined scope. Public-source coverage is incomplete and changes over time. The review never includes unauthorised access or use of exposed credentials. Takedown services and continuous monitoring are outside this review and would require separate agreement.
For understanding your organisation’s public footprint. Discovery of an asset does not authorise a vulnerability scan or penetration test. Explore penetration testing.
We’ll agree a written proposal and obtain authorisation before the assessment begins.
Public exposure checks use open-source intelligence, also called OSINT, to examine information associated with agreed organisational names, domains and brands. The aim is to identify relevant exposure for investigation, not to access systems without permission.
Look for exposed files and organisational information associated with the agreed domains and assets.
Check for indications of exposed credentials within agreed, lawfully accessible sources. Findings require careful handling and validation.
Look for relevant lookalike domains and other public indicators that may warrant investigation.
Separate the observation from the conclusion. Finding information associated with your organisation does not, by itself, prove an active threat or a compromised account. These distinctions help your team decide what to investigate.
| Evidence field | What to record | Useful next step |
|---|---|---|
| Association confidence | Confirmed, uncertain or unrelated to the organisation, with the reason for that classification. A confirmed association does not establish malicious use. | Confirm ownership before allocating investigation or excluding an unrelated name match. |
| Age and freshness | Source date, observation date and whether the information still describes the current environment. Historical material can have a confirmed association. | Check whether an older asset, account or document remains relevant now. |
| Sensitivity and context | What the information reveals, its intended audience and any uncertainty about its significance. | Ask the appropriate owner to determine whether publication is intentional or protective action is needed. |
| Action and ownership | The person responsible, next action, dependencies and outstanding requests concerning third-party copies. | Track action on the original and remaining copies separately; discovery does not guarantee removal. |
A useful finding record includes the source, observation date, identifier involved, supporting context and reason for concern. Historical material can also have a confirmed association: age and confidence are separate attributes. The review concerns organisational public information such as indexed documents, domain/brand information and credential-exposure indicators in lawfully accessible sources. Source categories and any direct requests to public assets belong in the engagement scope; a public observation is not permission to scan or log in. Confirm ownership, reduce unintended exposure at the source, let authorised account owners protect affected accounts and track any third-party removal requests through the reporting channel.
Understand what is visible, assess what matters and give the right teams a clear next step.
Visibility
Identify information associated with agreed brands and domains that may be overlooked during an internal review. Assess relevance before acting on a finding.
Protection
Use relevant lookalike-domain and credential-exposure findings to inform investigation and protective action. A suspicious domain is not, by itself, proof of malicious activity.
Response
Give IT, security and communications teams a shared view of findings. Keep sensitive details restricted and decide who owns investigation, removal requests or account-protection actions.
Public documents and indexed information can reveal details about an organisation’s systems or operations. Review the relevance and sensitivity of each finding before deciding whether publication is intentional or needs attention.
An exposed address or historical credential reference is a signal for investigation. Record the source, date and uncertainty, then let the authorised account owner assess protective action. A match alone does not show that an account is currently compromised.
Lookalike domains may merit investigation where they could be confused with your organisation. Assess context and ownership before classifying a domain as malicious or requesting action; similarity is not evidence of abuse on its own.
Review how the information associated with your organisation appears to outsiders. Findings can inform publication practices, document handling and coordination between marketing, IT and security teams.
A report with the source, observation date and reason for concern makes investigation easier to assign. It also helps separate an action you control, such as removing your own file, from a request that depends on a third-party provider.
Use a defined review to decide whether further monitoring, takedown support or account investigation is needed. Those services require their own scope; discovery does not guarantee removal or prevent every impersonation attempt.
Confirm the organisation names, domains and brands in scope, permitted sources and the handling of potentially sensitive information.
Examine agreed, lawfully accessible sources for relevant files, exposure indicators and lookalike domains. Source availability affects coverage.
Distinguish potentially relevant findings from unrelated names or historical information. Record uncertainty rather than treating every match as a confirmed threat.
Provide context and recommended next steps. Limit sensitive details to the people who need them and agree secure reporting arrangements.
Your team validates findings and takes appropriate action. Takedowns, incident response and repeat checks are not included unless separately agreed.

Work is authorised in writing before any assessment begins, and stays within the agreed scope.
Related services answer different questions. Confirm which scope you are buying before you compare quotes.
| Approach | What it tells you | Scope to confirm |
|---|---|---|
| Public exposure checks / OSINT | Examines relevant organisational information in agreed public sources. | Coverage depends on available sources and identifiers; findings may be historical or uncertain. |
| Vulnerability scanning | Actively checks authorised technical targets for known weaknesses. | A separate scope; discovering an asset publicly does not authorise testing it. |
| Monitoring and takedown services | Repeat observation or assistance with removal requests, where contracted. | Neither continuous monitoring nor removal is included in a public exposure review by default. |
Illustrative example, not a client case study
This is a teaching example of a finding record, not an extract from a customer report or a promise of a particular report template.
Organisation names, domains, brands, source coverage, review depth and reporting requirements affect the quote. Include subsidiaries or historical brands explicitly. A one-off review, repeat monitoring and takedown support are different scopes.
Provide the legal and trading names, current and legacy domains, brands and relevant subsidiaries. Identify who owns technical and communications responses and agree how sensitive findings will be shared. Do not send passwords or leaked data through the enquiry form.
Allow for access preparation, the assessment, report delivery and your team’s remediation work. Confirm the delivery format, dates and any follow-up checks in your quote so each team knows when its input is needed.

Practical answers about scope, cost and what happens next.
Compare all six security servicesPublic exposure checks use open-source intelligence, also called OSINT, to examine information associated with agreed organisational names, domains and brands. The aim is to identify relevant exposure for investigation, not to access systems without permission.
Link to this answerNo. An exposure finding needs validation and context. It does not by itself prove that an account is currently accessible or has been misused. Your team should assess the finding and take proportionate protective action.
Link to this answerNo. Identifying a possible exposure does not authorise logging in or trying credentials. The public exposure review does not include using exposed credentials to access accounts.
Link to this answerRemoval and takedown work is not included by default. Findings can support your investigation and any requests to the responsible provider, but removal cannot be guaranteed.
Link to this answerNo. This is a scoped public exposure review using agreed sources. It does not imply complete coverage of private sources, criminal forums or ongoing monitoring.
Link to this answerOSINT means open-source intelligence: collecting and assessing information from publicly available sources. Fig’s public exposure checks apply this to agreed organisational names, domains and brands to identify relevant exposure for investigation.
Link to this answerNo. Search indexes, public sources and historical records are incomplete and change over time. The report should identify the sources, identifiers and review period so you can understand what the findings cover and where uncertainty remains.
Link to this answerOrganisation names, domains, brands, source coverage, review depth and reporting requirements affect the quote. Include subsidiaries or historical brands explicitly. A one-off review, repeat monitoring and takedown support are different scopes.
Link to this answerNo. Security testing and reviews can help identify gaps, but certification requires a separate assessment under the relevant scheme. Buying this service does not guarantee certification.
Link to this answerExplore a different assessment, manage remediation or prepare for certification.
Related service
Automated checks of agreed websites and systems for known weaknesses, helping you prioritise what needs attention.
ExploreRelated service
A qualified tester attempts to exploit weaknesses in agreed applications, APIs or networks, with written authorisation. Includes a report, fix guidance and a retest of the findings.
ExploreSoftware
Manage compliance gaps, remediation and supporting evidence.
ExploreCertification
Explore certification options for your organisation.
Explore
Explains how publicly indexed material can expose organisational and technical information.
Read the OWASP guide Independent technical guidance. Stock photograph for illustration.Work with Fig directly or through your MSP. Your proposal identifies the contracting entity, assessment scope and delivery responsibilities.
The companies
See the entities, licences and people behind the platform and our assessments.
ExploreMSP partners
Offer these services under your own brand and retain the client relationship.
ExplorePublished evidence
Verify our company details, licences and the claims we make in public.
ExploreContent updated .
Tell us what you need from public exposure checks (osint), the systems involved and any deadline. We’ll discuss the options and provide a quote.