How the review works

Wie KMayer Exposure Lens AI von der passive_public-Prüfung zu privat verifizierten Ergebnissen und einer gesteuerten vertiefenden Prüfung übergeht.

Each request begins in passive_public. Verification protects private access, the verified-running state keeps the journey clear while processing continues und the results-ready email is sent only after both verification and completion. authorized_deep, read-only connector evidence und trusted export intelligence apply only when ownership, engagement und approvals are in place.

Three-lane model

passive_public, private_verified und authorized_deep keep the review governed.

The public review lane is passive-first and non-intrusive by design.

KMayer Exposure Lens AI reviews public DNS, mail authentication, HTTPS, TLS, headers, trust files, indexing signals, same-host public evidence, vendor ecosystem indicators und passive asset inventory clues. It does not perform exploit attempts, brute force, credential attacks, or intrusive testing in the public lane.

Prüfung lane

passive_public

Public, non-intrusive review of external domain and trust signals.

  • DNS
  • mail authentication
  • HTTPS
  • TLS
  • headers
  • trust files
  • indexing signals
  • same-host public evidence
  • vendor ecosystem signals
  • passive asset inventory clues

Excludes: login attempts, brute force, exploit attempts, intrusive scanning, credential attacks, bypass attempts, private data access.

Prüfung lane

private_verified

Protected results after business email verification.

  • executive summary
  • technical highlights
  • risk themes
  • evidence context
  • prioritized next steps
  • readiness for KMayer-assisted validation

Prüfung lane

authorized_deep

Gesteuerte tiefere Prüfung available only under verified ownership, active engagement, approved scope und explicit consent.

  • deeper technical validation
  • remediation planning
  • infrastructure review
  • Cybersicherheit follow-up
  • documentation for decision makers

Executive journey view

From public signal to governed deeper validation, the process stays clear for non-technical buyers.

01 Bounded start

Absenden domain

The review starts from a bounded passive request and business context, not an unrestricted scan brief.

02 Trust gate

E-Mail verifizieren

Die erste kundenbezogene E-Mail schützt die private Route, bevor ein fertiges Ergebnis bereitgestellt wird.

03 Öffentliche Nachweise

Passive review runs

Öffentliche Nachweise is collected first so the opening lane stays safe, non-invasive und explainable.

04 Private Zustellung

Freischaltung privater Ergebnisse

The verified recipient sees either the verified-running state or the completed private results page.

05 Berechtigung erforderlich

Gesteuerte tiefere Prüfung

If ownership and engagement qualify, authorized_deep can unlock a more decision-ready evidence set.

06 Approved context

Connector and export context

Read-only-Connector-Nachweise and approved trusted exports can deepen confidence only when explicitly eligible.

07 Next-step lane

KMayer remediation lane

The output moves into validation, prioritization und deeper remediation planning rather than stopping at findings.

Prüfung journey

Die Customer Journey ist bewusst, privat und verifizierungsorientiert vom ersten Antrag bis zu den fertigen Ergebnissen.

Step 1 Anfrageaufnahme

Absenden the domain and business details

Every request starts with domain validation, normalization und guarded input handling before any public fetch begins. Invalid, private-address, localhost und suspicious targets are rejected up front.

Bounded request capture before any review starts.

Step 2 Passive entry lane

Passive_public-Prüfung einreihen

The default entry lane reviews public DNS, mail-trust posture, HTTPS reachability, TLS basics, visible headers, trust files, indexing signals und a tightly capped set of same-host public pages.

Zuerst öffentliche Nachweise, keine intrusive Ausweitung.

Step 3 Trust checkpoint

Senden Sie zuerst die Verifizierungs-E-Mail

The first customer-facing message is the verification email. It protects the private results route before any completed-results delivery is allowed.

Verification comes before private delivery.

Step 4 Empfängernachweis

Verify the request email

The one-time verification link confirms that the intended recipient is the person unlocking the private route, even if the opaque URL is forwarded or discovered out of context.

Privater Zugriff bleibt an den vorgesehenen Empfänger gebunden.

Step 5 Verarbeitungsklarheit

Sehen Sie den Verified-Running-Status, wenn die Prüfung noch läuft

After verification, the private route can show a verified-running state instead of exposing incomplete results. This makes it clear that access is valid while preparation is still underway.

No partial result exposure while the review is still being prepared.

Step 6 Private Freischaltung

Private Ergebnisse freischalten, wenn die Prüfung abgeschlossen ist

When the passive review has finished, the private page opens the completed results immediately for the verified recipient.

Completed results appear only on the verified route.

Step 7 Sequenzierte Lieferung

Senden Sie die Results-Ready-E-Mail erst nach Verifizierung und Abschluss

If the scan finishes before verification, the ready state is preserved but the results-ready email waits until verification occurs. No verified click means no results-ready email to that recipient.

Die Results-Ready-Zustellung bleibt hinter Verifizierung und Abschluss gesperrt.

Step 8 Entscheidungsunterstützung

Use the private results to understand risks, evidence, priorities und next steps

The unlocked page explains the executive summary, technical highlights, risk themes, evidence-source context, priorities, business or trust cues und practical next-step leitlinien.

Business framing and technical context stay together.

Step 9 Gesteuerte deeper lane

Activate authorized_deep only when ownership and engagement are verified

The deeper lane is governed. It applies only when verified ownership, active engagement und the right approvals exist for the reviewed domain or account.

authorized_deep is explicit, not anonymous or automatic.

Step 10 Approved evidence

Add read-only connectors and trusted exports only when eligible

read-only connector evidence, trusted export intelligence, monitoring, history und deeper explainability can extend the review only inside that governed lane and only when the workflow allows them.

Connector and export context deepen the result only when the engagement qualifies.

Decision matrix

Use the first private result to decide what can happen now, what gets deeper with authorization und where KMayer helps next.

What you get now

  • Passive externe Posture-Prüfung, zuerst aus öffentlicher Evidenz aufgebaut.
  • Private verified delivery with executive summary, technical highlights und first priorities.
  • Sichere nicht-invasive Signalerfassung ohne Login-Versuche, Brute Force oder Exploit-Verhalten.

What gets deeper with authorization

  • Read-only-Connector-Nachweise, wenn Tenant oder Domain genehmigt ist.
  • Trusted export intelligence after quarantine, review und approved-for-parse controls.
  • Stronger provenance, vendor and asset context, monitoring continuity und remediation sequencing.

What KMayer can validate next

  • Whether the highest-risk signals map cleanly to real control owners and operational impact.
  • Whether authorized_deep is commercially justified for the reviewed environment.
  • How to turn the result into a practical remediation conversation without widening scope unsafely.

Why verification is required

Private results are intended for the verified recipient. Verification closes the trust gap between the public submission flow and the non-indexed private results route und it keeps completed-results email delivery aligned to the right recipient.

What public mode never does

Der öffentliche Modus bleibt ausschließlich passiv. Er führt keine Login-Versuche, Brute Force, Credential Spraying, Exploit-Verhalten, intrusive Tests, Hidden-Path-Probing oder aktive internetweite Scans aus.

What KMayer can help with after the review

KMayer can validate the findings, prioritize the highest-impact fixes, determine whether authorized deeper review is justified, interpret connector-backed or trusted-export evidence und move the work into assisted remediation planning.

Who provides the review

KMayer provides KMayer Exposure Lens AI. KMayer is the company and provider, while KMayer Exposure Lens AI is the tool and service family used for this review workflow.

Where deeper evidence comes from

Deeper evidence is governed, verified und added only when it improves decision confidence.

The first review stays passive. When ownership and engagement are verified, KMayer can extend the review with approved read-only connector context, trusted export intelligence, monitoring, history und remediation sequencing.

Passive evidence first

Öffentliche Signale definieren die sichere Basisschicht.

The first review is passive and bounded: DNS, mail posture, HTTPS, TLS, trust files, indexing signals und capped same-host public evidence are evaluated before any deeper lane is considered.

  • DNS, mail trust, HTTPS, TLS, headers, trust files und indexing posture.
  • No login attempts, brute force, exploit behavior, or intrusive widening.

Gesteuerte deeper context

authorized_deep activates only with proof and scope.

The deeper lane is not anonymous. It requires verified ownership, active engagement, approved scope und explicit approval for read-only connector evidence or trusted export intelligence.

  • Connector and export evidence remain read-only, attributable und bounded.
  • Privates noindex-Behandlung und Verifizierungskontrollen steuern weiterhin den Zugriff.

Decision-ready follow-through

Deeper evidence improves confidence, history und remediation sequencing.

When eligible, connector and trusted-export context can strengthen provenance, vendor ecosystem interpretation, passive asset inventory, monitoring, history und the sequence of practical remediation work.

  • Use deeper context to validate priority and ownership before change work.
  • Move from findings into KMayer-assisted remediation planning when justified.
Passive first Verified ownership Approved read-only evidence Privates noindex result KMayer-assisted remediation
DE
KMayer - IT Service Provider
Datenschutzerklärung

Our website is committed to protecting your privacy. We collect and process data to enhance your experience, such as recognizing you when you return and understanding how you interact with our content. Your information is used responsibly to ensure that our Dienste remain valuable, secure und tailored to your needs. For a detailed explanation of how we handle and protect your data, please refer to our Datenschutzerklärung