How many open doors before someone reaches your data.
We map what’s already visible, then show how it can lead to your customer data. Free.
The full report stays free. Need to go further? Deep scan actively tests one HTTPS URL you control (domain proof, paid report).
Sites tested
0
How it works
From a domain to a clear dump-risk story.
Enter a domain or work email
No posture questionnaire. We scan what is already public and show how surface flaws enable compromise.
Public surface check
The free full report covers DMARC, HTTPS headers, subdomains, and public leak signals, then the path to a data leak.
Cleartext vs encryption vs tokens
See the proof chain, an illustrative dump (clear → encrypted in flows → tokens), and a direct path to Veilio tokenization.
Deep scan
When the free report is not enough.
The full report reads what is already public. A Deep scan actively tests one HTTPS URL you control, to see what is actually reachable, and what to fix.
Purpose: move from public signals (DMARC, headers, subdomains) to an authorized test, with a report and fix recommendations. It is not a certified pentest.
Prove you own the domain
A DNS TXT record is required. We only test what you authorize.
Choose the HTTPS URL
The verified domain or a subdomain, port 443. Non-destructive active test, a few minutes.
Report and remediations
The report can surface XSS, injections, weak auth, exposed secrets, sensitive data leaks, and misconfigurations, each with a concrete fix. About 5 to 20 minutes.
99 € · DNS record required · not a legal assessment.
Start a Deep scanComing soonWhat we look at
Surface proof, then the data gap.
Public surface signals
DMARC / SPF, security headers, subdomains, public code and breach mentions, when Full mode is selected.
Attack path to a leak
When DMARC is missing or p=none, we show how spoofing leads to internal access and data siphoning.
Cleartext vs encryption vs tokens
Side-by-side dump demo: clear storage, encryption-only (still clear in app flows), then opaque tokens.
Close the gap with Veilio
Tokenize sensitive fields before storage so a stolen dump no longer yields usable PII.
Sample report
What a board-ready verdict looks like.
Illustrative only. A live report leads with the proof chain (surface → usable dump → tokenize), then the dump comparison.
- High
Weak DMARC (p=none) enables domain spoofing
DNS / email auth
- High
No DMARC policy on the company domain
DNS / email auth
- Medium
Stolen dump would still expose usable customer fields
Dump comparison
Surface flaws make compromise and data leak easier
Why founders and CTOs use it
Open the conversation on data risk in minutes: one public signal (when available), a clear cleartext-vs-tokens story, and an attack path you can put in front of a board or a security review, before a full audit.
Board-shareable PDF export included
- ·No account required
- ·Surface checks are passive
- ·Not a pentest
- ·Illustrative dump demo
Veilio Exposure uses public signals and an illustrative dump narrative. The full report and the Deep scan are not a security audit, a pentest, or a legal assessment.
