Privacy Policy

Last updated: June 23, 2026

1. Who We Are

AIExpose (aiexpose.net) is an AI Infrastructure Security Observatory operated by Carlos Dominguez, based in Dublin, Ireland. Contact: [email protected]

2. What Data We Collect

AIExpose does not operate visitor accounts and does not run its own analytics or tracking on visitors. We work with the following categories of data:

  • Publicly available security data from sources such as GitHub, NVD, crt.sh, HuggingFace and Shodan, used to populate the observatory
  • We do not log or store visitor IP addresses on our own servers. Our infrastructure provider, Cloudflare, processes visitor IP addresses as part of its standard security and content delivery service — see Section 4 below
  • If you contact us directly (for example, to report an issue or ask a question), we process the personal data you provide in that communication (such as your name and email address) solely to respond to you

3. Cookies

AIExpose uses only essential technical cookies necessary for the website to function. We do not use tracking or advertising cookies.

4. Third Party Services

  • Cloudflare — provides DNS, security, tunnel and CDN services. Processes visitor IP addresses as part of its standard service, subject to Cloudflare's own privacy policy.
  • CartoDB — provides map tiles for the interactive world map.
  • Shodan — internet-wide scanning data used to identify exposed AI infrastructure. See our About page for details on how this data is used.

5. Your Rights (GDPR)

AIExpose does not collect personal data from visitors browsing the website. If you contact us directly, in relation to the personal data you provide through that communication, as an EU resident you have the right to:

  • Access the data you have provided
  • Request correction or deletion of that data
  • Object to its processing

You also have the right to lodge a complaint with the Irish Data Protection Commission (dataprotection.ie) at any time.

Contact us at [email protected] to exercise these rights.

6. Disputing or Updating a Finding

Findings published on AIExpose relate to organisations and publicly accessible infrastructure, not to private individuals, and therefore generally fall outside the scope of GDPR. However, if an organisation has resolved an issue referenced in a finding, or believes a finding is inaccurate, you may contact us at [email protected]. We will review the request and, where appropriate, update the finding's status to reflect remediation rather than remove the historical record, in line with our responsible disclosure approach described on the About page.

If a finding inadvertently identifies a private individual (rather than an organisation), that individual may request review or removal under Section 5 above.

7. Data Retention

Security findings (CVEs, exposed infrastructure, certificate data) are retained indefinitely as they form the core dataset of the observatory. We do not generate or retain our own server access logs. Any logs generated by Cloudflare as part of its service are subject to Cloudflare's own retention policy, not ours.

8. Contact

For any privacy related questions contact us at: [email protected]