SHIELD validates content signatures so SPA soft-200 responses do not become fake .env or .git findings.
What did your site
leave outside?
SHIELD reviews the public surface for things production often exposes by accident: source maps with source content, repository/config artifacts, directory indexes, verbose debug output, internal URLs and unnecessary runtime disclosure. Evidence first. No exploit theater.
Check a public site →What did the site
leave outside?
SHIELD looks for a small set of high-signal public exposures—source maps, repository/config artifacts, directory indexes, debug output, internal references and unnecessary runtime disclosure. It does not exploit the site or dump sensitive contents.
Secret files, source maps and debug pages are classified from bounded responses, but sensitive body contents are intentionally excluded from reports.
No auth bypass, payload execution, port scan or private-network access. Requests remain within the same public-web safety model as MAP.
Findings explain what was verified, why it matters and the practical production change that removes the exposure.