AI Exposure Scan

What can an AI agent do with your domain?

Enter a domain. AxioRank reads its public AI-facing surfaces and grades what an autonomous agent could discover or abuse, from leaked secrets in llms.txt to unauthenticated MCP tools. Free, no signup.

try

Enter a domain to map its AI attack surface.

We read only public, well-known files, the same requests a search crawler makes. No signup, no login, nothing intrusive.

What we check

A read-only sweep of your AI-facing surfaces

The scan probes a fixed set of well-known files and scores what it finds with the same engine that guards live agent traffic. Presence of a file is neutral; only risky content moves the grade.

Discovery files

robots.txt AI directives, llms.txt, llms-full.txt, and ai.txt. What models are told they may read, and where a secret sometimes gets pasted by mistake.

Agent surfaces

MCP server cards, A2A agent cards, NANDA AgentFacts, and plugin manifests. Scored for dangerous or unauthenticated tools an assistant could call.

Identity & auth

OAuth authorization-server and protected-resource metadata, did:web documents. Whether agent access is gated, and whether identity keys are domain-bound.

Content inspection

Every fetched surface runs through the same engine that guards live agent traffic, flagging leaked secrets, PII, and indirect prompt injection.

Passive and crawler-equivalent

Every request is a read-only GET for a standard public path, the same thing a search engine already does. AxioRank never authenticates, calls a tool, or probes beyond the fixed list of well-known files.

AI Exposure Index

How well-known domains score

A point-in-time index of common domains, scored on their public AI-facing surfaces only. Grades reflect what is publicly readable and are not an affiliation, endorsement, or judgment of any listed company.

DomainGradeRisk
zapier.comBlimited35/100
resend.comBlimited35/100
weaviate.ioAminimal18/100
sentry.ioAminimal18/100
notion.soAminimal0/100
linear.appAminimal0/100
supabase.comAminimal0/100
perplexity.aiAminimal0/100
shopify.comAminimal0/100
langchain.comAminimal0/100
llamaindex.aiAminimal0/100
modal.comAminimal0/100
fly.ioAminimal0/100
hubspot.comAminimal0/100
n8n.ioAminimal0/100
cloudflare.comAminimal0/100
pinecone.ioAminimal0/100
cursor.comAminimal0/100
clerk.comAminimal0/100
browserbase.comAminimal0/100
firecrawl.devAminimal0/100
mintlify.comAminimal0/100
cohere.comAminimal0/100
stripe.comAminimal0/100
mistral.aiAminimal0/100
together.aiAminimal0/100
huggingface.coAminimal0/100
replicate.comAminimal0/100
elevenlabs.ioAminimal0/100
render.comAminimal0/100
railway.appAminimal0/100
vercel.comAminimal0/100
workos.comAminimal0/100
openai.comAminimal0/100
anthropic.comAminimal0/100
github.comAminimal0/100

FAQ

AI exposure, explained

What is an AI attack surface?

It is everything about your domain that an autonomous AI agent can discover and act on without logging in: your robots AI directives, llms.txt and ai.txt files, published agent or MCP cards, plugin manifests, and OAuth metadata. The more you expose, and the less it is authenticated, the more an agent (or an attacker steering one) can do.

Does the scan touch my servers or require access?

No. The scan only issues read-only GET requests for standard public files at well-known paths, the same requests a search engine crawler makes. It never authenticates, never calls a tool, and never enumerates beyond that fixed list. It is fully passive.

What is llms.txt?

llms.txt is an emerging convention: a plain-text file at your site root that maps your canonical content for large language models. It is useful, but because it is often generated or hand-edited, it is also a place API keys and internal notes occasionally leak. The scan reads it and flags anything sensitive.

How is the grade calculated?

Each surface we find is scored by AxioRank's detection engine for leaked secrets, PII, prompt injection, and dangerous or unauthenticated capabilities. Those signals combine into a 0 to 100 risk score, which maps to a letter grade from A (minimal exposure) to F (critical exposure). Merely publishing an AI-facing file never lowers your grade; only risky content does.

Do I need to sign up?

No. The scan and the full report are free and public. Signup is only for continuous monitoring and enforcement through the AxioRank gateway.

A scan is a snapshot. Close the surface for good.

AxioRank continuously verifies the agents that reach your surfaces, scores every tool call, and enforces policy at the gateway. Start free, no card.