FAQ

Exposure questions

Common questions about HRS Exposure, from what it scans and stores to how it affects scores and what it costs to try.

PublicUpdated October 6, 2026

Is Exposure part of HRS Learn?

It's an add-on with its own console at exposure.humanriskshield.com. If your plan includes it, you open it from Exposure in the HRS Learn admin sidebar and are signed in automatically.

Can I try it before buying?

Yes. A one-time scan of any domain is available at exposure.humanriskshield.com without an account. Continuous monitoring, findings tied to people, and the feed into ShieldScore need the add-on and a verified domain.

Why do I have to verify my domain?

So nobody can monitor a domain they don't control. You add a TXT record at your DNS provider and select Verify ownership. Unverified domains are never scanned. See Monitor your domains.

Does Exposure scan our network or log in to anything?

No. Every standard check uses what anyone outside can already see: public DNS, public web pages, certificate logs and breach and infostealer data from licensed providers. The one exception is Identity Posture, which reads your directory through a connection you choose to make.

Does Exposure store leaked passwords?

No. A finding records that a password was exposed, never the password itself, and a self-test checks that no part of the system can hold one.

How often are domains re-scanned?

On the cadence you choose per domain: daily, every 3 days, weekly, every 2 weeks or monthly. Weekly is the default.

How does Exposure affect ShieldScore?

Findings tied to a person feed the data handling part of their ShieldScore in HRS Learn. When the exposure is resolved, it stops counting against them. Exposure's own A to F grade for a domain runs the other way to ShieldScore: higher is better.

Will Exposure reset someone's password for us?

Not on its own. Any action against a person's account is started by an admin. Exposure helps you decide what to do and checks with a re-scan that the fix worked.

What does a critical finding mean?

Something an attacker could use now. A fresh infostealer hit is always critical: a work account's credentials showing up in logs stolen from an infected device within the last 90 days. That password may be in someone else's hands now. Reset it, end the person's active sessions, and check the device.

Can we pull findings into our own tools?

Yes. Exposure admins can create API keys under settings, and the API reference is published at exposure.humanriskshield.com/docs/api. See API and integrations overview.

Who can do what in Exposure?

Viewers read findings and reports. Analysts also triage findings, run scans and manage domains. Admins also manage users, organization settings and API keys.

Still stuck?Contact support

Related