Reviewed public-exposure assessment for phishing and fraud risk

Find the public people, role, and contact exposure attackers can use to make fraud feel believable

HumanSurface reviews your company’s public footprint, maps exposed roles and contact paths, and turns them into executive-ready findings and remediation priorities.

Base Assessment

Understand which public information increases impersonation and social engineering risk.

€190
+ VAT
Public exposure of people, roles, and contacts
AI-assisted impersonation risk
Visible public surface
Operational priorities
Synthetic report + scope confirmation call

Assessment + Dark Web

Includes Base plus a cautious review of leak/dark web signals connected to the company.

€390
+ VAT
Everything included in the Base Assessment
Review of leak/dark web signals linked to company domains/emails
Known credential exposure checks, when available
Company references in available OSINT/dark web sources
Operational priorities for critical exposures
Activation happens after scope confirmation. We do not perform invasive scans and do not require access to internal systems.
No credentials or internal access requiredManual review before deliveryBuilt for SMEs, professional firms, and visible teams
Live assessment snapshot
High exposure
HumanSurface Score
72/100
Imperson.
81
HIGH
Fraud
68
MED
HR/Social
74
HIGH

Top findings

5 critical signals

Public email addresses found on company pages

Executive visibility exposed

Predictable email naming pattern detected

What changed in 7 days
+2 public email addresses detected
+1 HR contact page discovered
Overall score moved from 64 to 72
Org visibility mapped
Role exposure modeled
Fraud scenarios generated
Human-centered risk visibility
Executive-ready reporting
Focused on phishing and fraud exposure
Built for practical security assessments
Clear scope before activation

The intro call confirms company, domain, priorities, and whether the reviewed assessment is the right fit.

Public-source methodology

We focus on externally visible people, roles, contact paths, business context, and fraud-enabling signals.

No internal access needed

The launch assessment does not require credentials, agents, inbox access, or invasive setup.

Decision-ready deliverable

You receive scored findings, exposed roles, likely attack scenarios, and practical remediation priorities.

What we uncover

The public information that can increase operational risk.

HumanSurface organizes what is visible from the outside: contacts, roles, technologies, processes, and signals that can make phishing, fraud, and impersonation more credible.

Exposed public surface

Pages, documents, profiles, forms, and company references reachable without authentication.

Visible emails and roles

Direct contacts, predictable email patterns, and recognizable business functions.

Technologies and external signals

Declared or inferable technologies, plus leak or exposure signals when available.

Key-role information

Public details about responsibilities, suppliers, processes, and communications that may be abused.

Dark Web Review

What the Dark Web review includes

The Dark Web review does not promise to find every exposed data point. It looks for signals and indicators linked to domains, company emails, and public references, using available sources and already exposed data. The goal is to understand whether there are elements that increase the risk of unauthorized access, impersonation, fraud, or social engineering.

What we look for

Company emails appearing in known leaks or available sources
Possible credentials or references to verify
Domains, brand names, or company references mentioned in risky contexts
Operational priorities to reduce exposure and abuse

What we do not do

We do not promise complete dark web coverage
We do not buy stolen data
We do not require internal system access
We do not publish sensitive data in the report
Why it matters

It separates business-useful visibility from risk-increasing exposure.

The goal is not to disappear from the web. The goal is to understand which public information is useful to the business and which combinations can support social engineering or fraudulent requests.

Prioritize exposures that make false requests more believable.
Reduce the context available for targeted phishing and operational fraud.
Give management, security, and operations a clear action list.
How it works

An assessment based on public data, human review, and operational priorities.

1

External analysis

We collect relevant public and OSINT signals around the domain and company footprint.

2

Risk interpretation

We connect people, roles, contacts, and processes to realistic abuse scenarios.

3

Report and remediation

We deliver scores, reviewed findings, and practical actions ordered by priority.

Impersonation risk in the AI era

Generative AI makes it easier to turn public context into credible messages.

With generative AI, seemingly harmless public information can be transformed into credible messages, targeted phishing, or impersonation attempts against key company figures. HumanSurface helps clarify which information is visible from the outside and which signals can increase operational risk.

AI-assisted impersonation
Roles, responsibilities, and company relationships that help build plausible pretexts.
Emails, suppliers, documents, and processes that can make a request feel legitimate.
Public context that can be combined into personalized messages against finance, HR, executives, and operations.
Non-invasive and risk-reduction oriented

Reduce risk before it is exploited, without internal system access.

Analysis from public sources and OSINT signals.

No invasive scanning without authorization.

No credentials or internal system access required.

No sensitive data published in demo materials.

The problem

Fraud and impersonation often start with public context, not technical compromise.

Names, roles, emails, team pages, and business details can make a fake request sound real. HumanSurface shows which visible signals create the most usable attack context.

Public exposure

Public emails, names, roles, and pages can increase your attack surface.

Impersonation risk

Visible business context makes fake internal requests more believable.

Actionable remediation

Clear findings and immediate next steps, not generic security reporting.

How it works

A consultation-first path to a reviewed exposure assessment.

01
Step 01

Submit a focused intake

Share your company domain, work email, role, and the exposure concerns you want reviewed.

02
Step 02

Confirm scope on a short call

We review the intake, respond within 1–2 business days, and align on fit, scope, and priorities.

03
Step 03

Receive your assessment

After activation, you receive reviewed findings, scores, exposed roles, scenarios, and remediation priorities.

What you get

Not just data. Clear priorities.

A HumanSurface assessment gives you an executive-ready view of how publicly exposed your organization is and how that exposure can be used against you.

Overall HumanSurface Score
Impersonation Risk
Finance Fraud Risk
HR / Social Engineering Risk
Top critical findings
Most exposed people and roles
Attack scenarios
Immediate remediation
7-day change tracking
Executive assessment
HumanSurface Report
High Risk
Score
72/100
Imperson.
81
Fraud
68
Top findings
Executive visibility increases impersonation risk
Public email addresses found on company pages
HR contacts publicly exposed
Immediate remediation
Reduce direct public email exposure
Introduce payment verification procedures
Train HR and finance on impersonation scenarios
Example findings

Examples of what HumanSurface can reveal

High

Public email addresses detected

Direct contact exposure can increase phishing opportunities and make impersonation attempts more credible.

Medium

Predictable email naming pattern

Attackers may guess additional valid company addresses from visible naming conventions.

High

Executive visibility exposed

Leadership visibility can support urgent-request fraud and role-based impersonation.

Medium

Public HR contacts exposed

Recruiting-related contacts may attract fake applications, malware delivery, or pretexting.

Medium

Team pages reveal business context

Public org details can support spear phishing with more believable business context.

High

Finance roles are easy to identify

Visible finance contacts can raise the likelihood of payment fraud attempts.

Who it’s for

Built for organizations where people are part of the attack surface

SMEs

Fast exposure visibility without heavy implementation.

Professional firms

Ideal for organizations with highly visible names, roles, and contact details.

Manufacturing companies

Useful where leadership, finance, sales, and operations are exposed online.

Agencies

Perfect for public-facing teams, people pages, and visible business context.

Software firms

Helpful for companies with public employee profiles and technical team pages.

MSPs and consultants

A clear, repeatable assessment offering for client engagements.

Why it’s different

Traditional tools monitor systems. HumanSurface shows how attackers can target your company through people.

Traditional security visibility

Endpoints
Infrastructure
Cloud assets
Network exposure
Technical configurations

HumanSurface

Public people exposure
Role-based vulnerability
Impersonation signals
Fraud-enabling business context
Business-oriented remediation
Internal dashboard

A reviewed report and dashboard built for security and business decisions.

The product experience is designed to make exposure explainable: scored signals, role-level context, likely fraud scenarios, and remediation that a team can actually assign.

Assessment overview

Rossi Industriali S.r.l.

last scan · 17 Mar 2026 · domain: rossi-industriali.it

Overall
72
Risk level
High exposure
score
Imperson.
81
score
Fraud
68
score
HR/Social
74

Critical findings

updated now
Public email addresses found on company pages
HIGH
Predictable naming pattern supports address enumeration
MED
Finance role visibility increases urgent-payment fraud risk
HIGH
Public HR contact page discovered
MED

Immediate remediation

Reduce public exposure of direct finance and HR email addresses
Introduce payment verification controls for urgent requests
Review leadership pages and public role descriptions
Train HR and finance on impersonation scenarios
People at risk

Most exposed roles and people

Laura Bianchi
CFO
Main scenario: Payment fraud
risk score
84
Marco Rossi
CEO
Main scenario: Executive impersonation
risk score
81
Giulia Verdi
HR Manager
Main scenario: Fake candidate phishing
risk score
76
7-day delta

What changed in 7 days

+2 public email addresses detected
+1 executive profile indexed
Finance fraud risk unchanged
Overall score moved from 64 to 72
Pricing

Choose the assessment scope before activation.

Start with Assessment Base at €190 + VAT, or add a cautious review of available leak/dark web signals with Assessment + Dark Web at €390 + VAT.

Base Assessment

Understand which public information increases impersonation and social engineering risk.

€190
+ VAT
Public exposure of people, roles, and contacts
AI-assisted impersonation risk
Visible public surface
Operational priorities
Synthetic report + scope confirmation call

Assessment + Dark Web

Includes Base plus a cautious review of leak/dark web signals connected to the company.

€390
+ VAT
Everything included in the Base Assessment
Review of leak/dark web signals linked to company domains/emails
Known credential exposure checks, when available
Company references in available OSINT/dark web sources
Operational priorities for critical exposures
Activation happens after scope confirmation. We do not perform invasive scans and do not require access to internal systems.
Request flow

Consultation first, assessment after scope is clear

Share company details and the reason for the assessment
We review the intake and reply within 1–2 business days
Intro call confirms fit, scope, and activation path
Assessment plans available for selected early customers.
Request assessment

Start with a HumanSurface assessment call.

Tell us what prompted the request. We will review the context and arrange a short intro call before activating the assessment.

Plans: Base €190 + VAT, Dark Web €390 + VAT
Scope confirmed before activation
Reviewed report with remediation priorities
Intro call first

Book a call

Share company details and the reason for the assessment
We review the intake and reply within 1–2 business days
Intro call confirms fit, scope, and activation path