← All research

If the basics were missed, what is hiding behind the login?

2026-09-21 · OrangeStealth Security

Some security fixes fit on a single line. The consequences of missing them do not.

Our recent research found businesses missing basic email protections in records anyone could look up. That raises a bigger question: if the visible basics were overlooked, who has checked what is happening behind the login?

We only looked at the outside

Our posts on missing SPF records and DMARC with no enforcement request came from public records. We did not need a password or access to anyone's database to find those gaps.

Sometimes the repair is a short DNS edit. Once legitimate senders are checked, a DMARC policy can ask receiving mail servers to reject messages that fail your domain's authentication checks. That can strengthen protection against someone using your name on a fake invoice. It is not a guarantee against every kind of phishing.

A missing setting is not evidence of a breach, or proof of a hidden backend flaw. But finding an overlooked public setting is a good reason to ask what else has never been reviewed. Our public-record research could not answer that question.

What can go wrong behind a working website?

The site loads. Payments work. Customers can log in. None of that tells you whether these problems are hiding underneath:

  • A gateway lets the wrong request through. The system recognizes a customer but fails to check which files that customer may open. A working login can still lead to someone else's private documents.
  • A leaked secret becomes someone else's key. A credential left in a public file can give its finder access to data or a paid service. The result could be stolen information, unauthorized activity or a bill you did not create.
  • An integration shares more than it needs. A tool that only needs a name and appointment time receives a full customer record instead. Now more information is exposed if that connection or provider is compromised.
  • An abandoned endpoint is still open. The old version disappeared from the menu, not from the internet. It may still reach live data without the protections added to its replacement.
  • A forgotten DNS record points somewhere it should not. An old subdomain can lead to an abandoned service. In some cases, another party can reclaim that service and put content under a name your customers trust.
  • The API routes have become a maze. One action passes through more systems than it needs to. Complexity alone is not a vulnerability, but it makes unnecessary access, extra copies of data and inconsistent checks easier to overlook.

Picture a hypothetical real-estate brokerage with a polished client portal. The new portal works perfectly. An older document-download route still runs in the background with weaker access checks. If it exposes a closing packet to the wrong person, the client does not care that the new login page passed its tests.

These are possible failure modes, not findings about the businesses in our public scans. OWASP's guidance on forgotten APIs and unnecessary data sharing describes why they deserve attention.

The part our earlier research could not see

That is why we put together The Invisible Backend. It looks beyond the polished screen at leaked secrets, overlooked access, forgotten routes and information sent to the wrong place. AI can make software faster to build; it does not make these questions disappear.

“For organizations without an internal security team, this report shows what a polished application or vendor can conceal behind the interface.”
— OrangeStealth, The Invisible Backend

What to actually do about it

  • Start with what is public. Run the free domain check. If it flags one or two items, helping you fix them is on us.
  • Ask what is still running. Have your developer or provider identify old endpoints, unused integrations and forgotten domain records.
  • Ask what could leave the business. Who can retrieve client files? Where are service keys exposed? Which outside tools receive customer information?
  • Ask for a checked answer. Have an authorized reviewer verify the important protections and confirm repairs, rather than relying on “it works.”

Get the full report as a free PDF by email. The detail is there when you need it. Future updates are optional through a separate, unchecked box.

For a fuller look at what is visible from outside your business, start with our passive, external-only External Security Posture Assessment or book a 20-minute conversation. Reviewing private backend behavior requires a separate, authorized scope. Start outside, then decide what deserves a closer look.