Find exposed AWS access keys before hackers do

Continuously monitor your domains, APIs, public JavaScript, and exposed services. Every run shows you what changed since the last one.

surfacedrift.com/overview

Overview

acme.com · 5 root domains · 218 assets

DoneUpdated 2m ago
Domains55 / 5 on plan
Checks12812 today
Priority issues32 critical · 1 high
Review queue71 running · 0 stale

Recent findings

SeverityFindingAssetSeen
CriticalExposed .env with live database URLapi.acme.com/.env4m ago
CriticalAuth bypass: API accepts JWT alg:noneapi.acme.com/v1/auth9m ago
MediumUndocumented admin API reachableapi.acme.com/internal/v21h ago
MediumStaging host publicly resolvablestaging.acme.com3h ago
LowSecurity headers missing on CDN hostcdn.acme.com1d ago

Vulnerabilities

9 open across acme.com

2 critical

Open issues

SeverityIssueAssetState
CriticalExposed .env with live database URLapi.acme.com/.envOpen
CriticalAuth bypass: API accepts JWT alg:noneapi.acme.com/v1/authOpen
HighAdmin panel reachable without authadmin.acme.comOpen
HighSubdomain takeover candidateblog.acme.comTriaging
MediumUndocumented admin API reachableapi.acme.com/internal/v2Open
MediumStaging host publicly resolvablestaging.acme.comTriaging

Hack Agent

Ask about exposure changes and what to fix next

Workspace context
What changed since the last check on acme.com?
SD

Ask about exposure changes…

Secrets

5 exposed in public assets on acme.com

1 high

Exposed secrets

SeveritySecretSource
HighAWS access key (long-lived IAM)AKIAQ4F7XKZ2NB6QF3J · wJalrXUtnFEMI…bPxRfiCY/assets/config.4c2.js
MediumSupabase anon keysb_pub_3f9a1c7e…e21/assets/vendor.4c2.js
MediumStripe webhook secretwhsec_9c41…2d/api/checkout.js
LowSentry DSNhttps://a1b2c3…@o42.ingest.sentry.io/assets/app.8f1c.js
LowGoogle Maps API keyAIzaSyB7…Xk/index.html

Built by a hacker who’s discovered & reported vulnerabilities to

Trademarks belong to their respective owners. Listed organizations run vulnerability disclosure programs where issues were responsibly reported. This is not an endorsement or partnership.

01See what changed

New secrets, routes, and services land in their own bucket, apart from the stuff you already knew about.

02Open the evidence

Every finding points at the host it came from, the file, and the exact line that tripped it.

03Hand off the fix

Mark it triaged, export the PDF, and re-check the host the moment the fix ships.

The review loop

A security review that reruns itself

Routes, client config, and JavaScript ship faster than anyone reviews them by hand. Every run re-checks your approved domains and boils it down to the four things that actually decide whether you're exposed.

Change detection

Every run is a diff, not a dump

Each run compares what's live now against the last one and shows you only what moved. Then it drops the changes that don't carry security weight, so you're not rereading a wall of findings you already cleared.

  • Weekly on Monitor, daily on Pro and Scale
  • New and changed surface split from known-good
  • Root-domain scope set by your plan

Secrets

Leaked keys, with the file that leaked them

AWS keys, Supabase and Firebase config, webhook secrets, DSNs, and decoded JWTs. Each one is pinned to the exact bundle, source map, or line it came from, so handoff is a link instead of a hunt.

  • Source file and matched context on every hit
  • Decoded JWT previews with risky-claim flags
  • Weak signing-secret checks on Pro and Scale

Reachable surface

The endpoints that matter, minus the noise

New API routes, GraphQL, admin panels, staging hosts, and open ports. The reachable surface an attacker would find, pulled out of the CDN and image noise a scanner usually buries it under.

  • New surface flagged the first run it appears
  • Reachable services and sensitive ports
  • Broader validation on Scale

Handoff

A queue you can hand to whoever owns the fix

Every finding carries severity, evidence, and owner-ready fix steps. Triage states, PDF export, and a one-click recheck against just that host prove the fix actually landed, with no spreadsheet in the loop.

  • Owner-ready fix packets
  • Exportable PDF evidence on every finding
  • Recheck history proves the fix held

Pricing

Know where your app is exposed and what to fix first.

Every plan watches your live app and tells you what actually needs fixing, not just what changed.

Pro

Daily drift
$199/mo

For teams that ship often and need daily checks.

  • 15 root domains, re-checked daily
  • Everything in Monitor, with deeper endpoint validation on every run
  • JWT claim and weak-signing-secret audits, plus risky client-side token usage
  • CVE and tech-stack exposure hints mapped back to the hosts they affect
  • Alerts to Slack, Telegram, webhooks, or email, with shared triage
Start Pro

Scale

Broader validation
$499/mo

For bigger surfaces that need more domains and deeper checks.

  • 40 root domains with priority daily checks
  • Everything in Pro, run across your full scope
  • Broader service and exposure validation on larger environments
  • Higher-capacity triage queue built for multi-domain teams and launches
  • Monthly exposure summary written for leadership and engineering owners
Choose Scale

Surface Drift

Find out what your app is leaking right now.

Start monitoring my domains