How it works

How KMayer Exposure Lens AI delivers a safe Phase 1 external exposure review.

The tool is designed to give business and technical teams a fast, credible view of public exposure posture without crossing into exploitation, brute-force behavior, or intrusive scanning.

Normalize the public target

Every request starts with careful domain validation and normalization. Public mode accepts only valid public domains and rejects localhost, private-address paths, malformed targets, and suspicious input before any fetch begins.

Collect a capped set of passive signals

The scan checks public DNS, HTTPS reachability, TLS certificate basics, mail-authentication posture, visible headers, robots, sitemap, security.txt, and a tightly capped set of same-host public pages.

Turn facts into business-ready guidance

The output focuses on what appears externally visible, why it matters, and what the first corrective steps should be. If AI summarization is unavailable, the factual findings still render cleanly.

Included

What public mode is designed to surface

  • Public DNS records including A, AAAA, MX, NS, TXT, SPF, DMARC, and CAA where available.
  • HTTPS and TLS checks against the apex host and www only, with tightly limited redirects and strict same-host controls.
  • Visible public metadata, headers, indexing clues, and a small set of internal public pages linked from the homepage.

Excluded

What the tool deliberately does not do

  • No brute-force subdomain enumeration, hidden-path discovery, port scanning, exploitation, or authenticated testing.
  • No login interaction, no third-party domain scanning, and no crawling beyond the assessed public host boundaries.
  • No promise of complete asset visibility: Phase 1 is an external visibility review, not a full security assessment.

Results and privacy

Private delivery is part of the product design, not an afterthought.

Each review runs asynchronously, then the completed results stay behind a private results route that requires both an opaque URL token and a one-time email verification step. The public informational pages remain indexable, but private results remain non-indexed and excluded from sitemap discovery.

KMayer - IT Service Provider
Privacy Policy

Our website is committed to protecting your privacy. We collect and process data to enhance your experience, such as recognizing you when you return and understanding how you interact with our content. Your information is used responsibly to ensure that our services remain valuable, secure, and tailored to your needs. For a detailed explanation of how we handle and protect your data, please refer to our Privacy Policy