Concepts

What HRS Exposure looks for

The checks Exposure runs against your domains and people from the outside, how findings are graded, and what it never stores.

PublicUpdated October 6, 2026

HRS Exposure looks at your organization the way an attacker would before writing a phishing email: from the outside, using what is already public or already leaked. It shows you what someone could learn about your people and your domains, and which of those things matter most.

The checks

Every scan of a domain runs these checks:

Check What it looks for
Credential Exposure Work accounts that appear in known breaches or in infostealer logs (credentials stolen from an infected device).
Executive & VIP Exposure Your leaders as your own public pages present them, and whether their likely work accounts appear in breach or infostealer data. These are the people a fake invoice or fake CEO message would impersonate.
Email Spoofability Whether your domain's email authentication would stop someone sending mail that claims to be from you.
Look-alike Domains Registered domains close enough to yours to fool a reader.
Web & TLS Hygiene Weak or outdated encryption and known-vulnerable web server versions on your sites.
External Surface Every host an outsider can find under your domain, and what each one is for.
Third-Party Exposure Who else holds part of your domain, read from public DNS: services allowed to send mail as you, whoever controls your DNS, and anyone who can see your mail flow.

Two more are not part of every scan. Identity Posture runs only when you have connected your directory, because it answers a question the outside can't: whether a person whose password leaked could actually be signed in as, for example because multi-factor sign-in is off. Leaked Credentials looks for credentials your people have published by accident in public source code.

How findings are graded

Each finding gets a severity, set by one rule for every source so that two providers can't disagree about the same exposure. A fresh infostealer hit, from the last 90 days, is always critical: it means a password may be in use by someone else right now.

Each domain also gets a posture grade from A to F:

Grade Score Band
A 90 to 100 strong
B 80 to 89 fair
C 70 to 79 fair
D 55 to 69 weak
F below 55 critical

What it never stores

Exposure never stores a leaked password. A finding records that a password was exposed, not the password itself, and an automated self-test checks that no part of the system can hold one. Findings about executives carry their name and title as evidence, never their email address or a credential.

What happens with the results

  • Findings tied to a person feed the data handling part of that person's ShieldScore in HRS Learn.
  • Findings expire. Once an exposure is resolved, it stops counting against the person.
  • Fixes are verified by a re-scan rather than taken on trust.
  • Any action against a person's account, such as resetting a password or ending sessions, is started by an admin, never by the system on its own.

An exposure is not a breach. It means the information exists somewhere reachable. The useful response is targeted: reset what needs resetting, and give the person coaching that matches what was found.

Still stuck?Contact support

Related