
About AIExpose
AI Infrastructure Security Observatory
What is AIExpose?
AIExpose is an open OSINT observatory that continuously monitors publicly exposed AI infrastructure across the internet. It detects exposed API keys, unprotected AI models, known vulnerabilities in AI tools, and misconfigured certificates belonging to AI companies worldwide.
All data collected by AIExpose comes exclusively from public sources β no private systems are accessed or exploited.
Why Does It Exist?
The rapid adoption of AI tools has outpaced security awareness. Developers frequently expose API keys in public repositories, deploy AI models without authentication, and use AI frameworks with known vulnerabilities. AIExpose makes this problem visible β and actionable.
How It Works
π Data Collection
Automated scrapers run daily collecting data from GitHub, NVD, HuggingFace and certificate transparency logs. Internet-wide scanning data from Shodan is collected on a weekly cycle.
π Risk Scoring
Each finding is scored 0-100 based on five weighted factors: exposure level, data sensitivity, exploitability, business impact and patch availability.
πΊοΈ Visualization
Findings are displayed on an interactive world map, allowing users to explore AI security exposures by geography and severity.
π§ Responsible Disclosure
AIExpose follows a responsible disclosure policy for all original findings. For exposed infrastructure found via Shodan, we notify the cloud provider abuse contact (AWS, Google Cloud, Linode, etc.) who notifies the owner directly. For GitHub findings, we notify the repository owner. IPs and repository names are anonymised during the 90-day disclosure period. If no response is received after 90 days, full details are published. For publicly known CVEs, we aggregate and visualize existing public data β the disclosure process has already occurred through NVD and other databases.
Finding IDs
Each finding is assigned an internal tracking ID in the format AIE-YYYY-NNNNN (e.g. AIE-2026-00001), used to reference a specific finding consistently across the platform. This is not an official vulnerability numbering authority like CVE β it's simply a way to consistently identify and cite specific findings within AIExpose. CVE findings keep their official NVD identifier instead, since one already exists.
Data Sources
- βGitHub API β public repositories with exposed AI credentials
- βNVD (NIST) β known CVEs affecting AI tools and frameworks
- βcrt.sh β certificate transparency logs for AI company domains
- βHuggingFace β public Spaces are scanned for hardcoded credentials in source code
- βShodan β internet-wide scanning data to identify exposed AI infrastructure. Discovery powered by Shodan's continuous scanning.
Risk Severity Levels
Note: certificate findings are capped at Medium severity regardless of score β they represent a reconnaissance / attack-surface signal (e.g. an internal-looking subdomain with a wildcard or expired certificate), not a confirmed exploitable vulnerability.
About the Author
AIExpose was created and is maintained by Carlos Dominguez, a Security Analyst based in Dublin, Ireland.
Contact: [email protected]