Security

Built to reduce the data we can lose.

Public evidence stays bounded. Sensitive text stays local. Production changes stay yours.

01

SSRF controls

Remote URL checks reject credentials, custom ports, local names, IP literals and reserved IPv4 ranges, and revalidate redirects.

02

No secret uploads

The secret and CSP analyzers run entirely in the browser. The UI makes this boundary visible before input.

03

Payment verification

Stripe Checkout Sessions are created server-side and paid access is verified against an allowlisted live Price.

Report a vulnerability

Email security@exposureaudit.net with reproduction steps and impact. Do not access other users' data, disrupt service or use social engineering. Good-faith, bounded reports will be reviewed.