Sharing is a feature and people use it, which is the point. What accumulates is the share nobody closed: a document set to anyone with the link, an app granted access years ago by someone who has since left, a shared drive still open to people outside the company. None of it looks like an incident until it is one.
Most leaks are a link somebody meant to send, and the default decides how far it travels. We read the default sharing setting for new files and whether it opens them to everyone with the link, and the domain-level rules for sharing outside the company and what they currently permit.
Code is the part people forget is data. We find repositories visible to anyone on the internet, and repositories that can be copied to a personal account and walk out that way.
An app granted access years ago by somebody who has since left is still reading today. We list the third-party apps holding a grant to read or export company data, and what each grant actually covers.
Those questions are the shape of it, not the inventory. Underneath them is a larger set of individual settings we read on each platform, and it moves every time a platform ships something new.
Where a CIS safeguard fits the evidence, the finding carries it, so the answer you give an auditor is the answer we already gave you. Where none fits, we leave it unmapped rather than claim a control we cannot stand behind.
A finding names the setting, the repository or the app grant, so you can see what is exposed before you decide.
Every change is prepared for you, made only once you approve it, logged, and reversible where the platform allows. How that works
Today we read sharing and data settings from Google Workspace, GitHub and AWS. More platforms are in development.