Free AI-stack exposure check
Is your AI stack exposed?
One click. We check your server for the AI tools attackers find first — Ollama, n8n, vLLM, Langfuse, Open WebUI, ComfyUI — and tell you exactly how to lock them down.
Only scan assets you own or are authorized to test.
- Safe by design — read-only metadata checks. No logins, no POSTs, no exploits.
- Graded findings — not “port open”, but “anyone can burn your GPU”, with severity.
- Fix cards — 3-step fixes in plain English, with a command to verify you’re done.
How it works
From target to fix in three steps
No agent, no signup, nothing to install.
-
Point us at a target
Enter the domain or IP of a server you own. We resolve it and probe only well-known metadata endpoints.
-
We check what answers
Six checkers look for exposed AI services — unauthenticated APIs, open setup pages, version leaks.
-
You get a grade and fixes
An A–F report with severity-ranked findings and a plain-English fix card for each one.
What we check
The AI tools attackers find first
Self-hosted AI infrastructure ships with open defaults. These are the seven most commonly exposed.
Ollama :11434
Open model API — anyone can list, run, or delete your models and burn your GPU.
n8n :5678
Unclaimed setup or open settings — a stranger can take ownership and read your credentials.
vLLM :8000
Unauthenticated inference endpoint — free compute for whoever finds it first.
Langfuse :3000
Tracing dashboard reachable — your LLM prompts, outputs, and user data on display.
Open WebUI :8080
Chat UI exposed — conversation history visible, open signup lets strangers use your models.
ComfyUI :8188
Open workflow API — arbitrary image jobs on your GPU, plus known RCE history.
Ray :8265
Open dashboard — unauthenticated job submission is remote code execution on your cluster.
Bots scan for these within hours of going online.
Find out what they’d see on your server — before they do.