Exposure Remediation

Exposed .env File Discovered & Removed

August 24, 2026 · Legal · Texas

Engagement Snapshot

Client: Texas Law Firm (name anonymized)
Industry: Legal
Exposure: .env File — DB Credentials & API Keys
Outcome: Zero exposures · Credentials rotated in 24h · Score 35 → 85

The Incident

During a routine security audit, we discovered a publicly accessible .env file containing database credentials, API keys, and secret tokens. The file was indexed by search engines and accessible to anyone who knew the URL. Three sensitive files were exposed.

What We Did

Before vs After

Security Score3585
Exposed Sensitive Files30
Credential RotationNeededDone in 24h
Search Engine IndexedYesNo

Key Takeaways

.env files should never be web-accessible. One misconfigured nginx rule exposes every secret. Audit your document root.

FAQ

How was the .env file found?

Automated perimeter scanning that checks common sensitive paths — .env, .git, backup files — on every scan.

Don't wait for the breach

The best time to harden was before the incident. The second best time is now.

Deploy Protection

Other Case Studies