No data leaves this browser. Every file you drop is parsed in memory by JavaScript on this page. There are no network requests, no analytics, no CDN links and no server. You can verify this by opening the page from file:// with the network disconnected, or by watching the browser's Network tab. Username, email, user-principal, IP and device-name columns are deleted at parse time before anything is matched, counted, drawn or exported, and the page tells you which columns it dropped. Counts below 5 are shown and exported as <5. Nothing is written to disk except the exports you explicitly download. Reloading the page discards everything.

1 · Load your exports

Drop the files

CSV or TSV. Three input formats are recognised, and the format is detected from the column headers — a domain / DNS / proxy / web-filter report, an OAuth app list (Google Workspace App access control, or Microsoft Entra enterprise applications), or a software-spend export. Drop several at once, in any order. Drop a previous baseline.json alongside them to run drift detection. See README-ai-exposure-scan.md for where each export lives in your admin console.

Drop your exports here
or click to choose — domain report, OAuth app list, spend export, previous baseline.json
No exports loaded yet. Drop your files above, or press Load sample data to see the scan working on a synthetic school.