Define the security question
A guide to discovering and reviewing internet-facing assets in a way that leads to fixes, ownership, and current evidence.
Discover public assets, stale DNS, preview deployments, APIs, and ownership gaps with evidence-driven remediation.
Page intent
resourceA guide to discovering and reviewing internet-facing assets in a way that leads to fixes, ownership, and current evidence.
This resource is structured as an operating guide: use it to scope the work, make decisions explicit, and turn the result into something engineering, leadership, or buyers can review.
A guide to discovering and reviewing internet-facing assets in a way that leads to fixes, ownership, and current evidence.
Discover public domains, subdomains, preview URLs, APIs, and exposed admin surfaces.
Tie each asset to owner, environment, data sensitivity, and expected exposure.
external asset inventory
Build the public asset inventory from DNS, hosting providers, repos, and app routes.
Classify production, preview, staging, deprecated, and unknown surfaces.
Prioritize assets by exposure, authentication, data class, and takeover risk.
Create a recurring review cadence with owner and retest notes.
external asset inventory
stale DNS review record
preview exposure decision log
surface reduction report
Unknown subdomains staying live after migrations or experiments.
Preview deployments exposing unfinished features or seeded data.
SaaS integrations creating public callbacks no one owns.
Asset lists becoming stale before engineering acts on them.
Unknown subdomains staying live after migrations or experiments.
Preview deployments exposing unfinished features or seeded data.
external asset inventory
SaaS integrations creating public callbacks no one owns.
Include domains, subdomains, deploy previews, APIs, callbacks, admin panels, storage endpoints, and third-party hosted surfaces.
Review after migrations, launch events, major integrations, and on a recurring cadence for active teams.
Unowned assets stay exposed because no team is accountable for removal, hardening, or monitoring.
SafeVibe connects discovered surfaces to application checks, remediation owners, and evidence that the exposure was handled.
Use External attack surface management guide as the starting point, then turn the checklist into SafeVibe scan scope and remediation evidence.