← Articles

Self-OSINT Audit: Find and Reduce Your Personal Exposure

A self-OSINT audit answers three questions: what can a stranger find, which findings create real risk, and what can be removed, corrected, separated, or monitored. The output is a time-stamped exposure register and a short remediation queue with owners and recheck dates.

Prepare a private evidence register

Use an encrypted local document or database. Give findings opaque IDs rather than filenames containing the exposed phone number or address. Store only what you need to remediate the exposure. A screenshot of an entire people-search profile creates a new copy of the data; a URL, field list, date, and narrowly cropped evidence may be enough.

Minimum exposure record
Minimum exposure record
FieldPurposeExample value
Finding IDReference without repeating personal dataEX-014
Source and URLWhere the exposure existsSearch result or publisher page
Identifier typeWhat matchedName, email, phone, address, username, image
ConfidenceHow certain the match isConfirmed, likely, ambiguous
ImpactWhy it mattersAccount takeover, home safety, impersonation, low consequence
ControlAvailable responseDelete, opt out, deindex, correct, separate, monitor
Evidence dateFreshness2026-08-05
Next checkReappearance or unresolved work30, 90, or 180 days

1. Build your identifier list

Start with identifiers you already know and control: full name variants, prior surnames, usernames, email addresses, phone numbers, domains, public profile URLs, and profile images. Add old cities only when needed to distinguish your record from someone with the same name.

Keep the list tied to your own exposure. If a public record includes another person alongside you, record only the fields needed to identify and remediate your listing.

2. Search from a clean context

EFF recommends searching for your own name, nickname, handle, avatar, address, phone number, and email. Use a private window or separate browser while logged out so personalization does not dominate the results. Test more than one search engine because deindexing and ranking differ.

  • Exact full name and common variants in quotation marks.
  • Username alone and with platform or city terms.
  • Email address and phone number in exact form.
  • Current and former address only when home-location exposure is in scope.
  • Profile-image reverse search using an image you own.
  • Public documents connected to your own domain or organization.

Open results cautiously. People-search and scam sites may use aggressive scripts, notification prompts, or payment traps. Do not install extensions, upload an ID, or pay for a report merely to satisfy curiosity. Record the public snippet and stop if the site demands more data than the removal benefit justifies.

Stop point: confirm the match

Before creating a removal task, confirm at least two matching fields that do not depend on the same copied source. Mark ambiguous records as ambiguous. Do not submit an opt-out for another person with the same name.

3. Check accounts and breach exposure

Review public profiles from the outside, not only while logged in. Record exposed contact details, location history, workplace, family connections, public friend lists, old posts, visible recovery hints, and reused usernames. Then inspect the platform's own privacy and session controls.

Have I Been Pwned provides point-in-time breach searches and verified notifications for an email address. Its documentation says notification enrollment requires control of the address. A breach hit is not proof that an account is currently compromised; it is evidence to rotate reused passwords, strengthen multi-factor authentication, review the affected data classes, and watch for targeted phishing.

Breach response by exposed field
Breach response by exposed field
Exposed fieldImmediate actionLonger control
PasswordChange it anywhere reused and terminate sessionsUse unique generated passwords or passkeys
Email and phoneExpect targeted phishing and recovery attemptsSeparate public contact from account recovery
Security answersReplace answer-based recovery where possibleUse random stored answers or stronger recovery
Address or identity dataMonitor impersonation and financial risk appropriate to jurisdictionReduce broker exposure and protect high-value accounts
Session token or secretRevoke sessions, rotate the credential, and inspect access logsLimit token lifetime and device access

4. Check people-search and broker listings

Record the broker, profile URL, fields shown, claimed source, parent company, opt-out route, and proof requested. EFF notes that broker data can repopulate, so deletion is not permanent. Prefer an official opt-out path. Minimize the information sent back to the broker and do not upload government ID unless the documented process and risk justify it.

For a local-first agent workflow, use the data broker removal guide. The audit remains separate from submission: first confirm the matching record, then approve the narrow removal payload, record confirmation, and recheck later.

5. Review search removal and source removal separately

Google's Results about you can monitor search results containing personal contact information and accept removal requests for eligible results. Google states that removing a result from Search does not delete the source page. Create two tasks when necessary: deindex the result from a search engine and request deletion or correction from the publisher.

Preserve the original URL and request confirmation before a page disappears. After source deletion, check that the page returns the expected status and use the search engine's outdated-content route if an old cached result persists.

6. Audit image and document metadata

Download the public copies connected to your exposure. Check document properties, author names, revision comments, embedded filenames, GPS coordinates, capture time, device model, and thumbnails. Inspect sensitive originals locally rather than uploading them to a metadata-checking website.

Replace exposed files with sanitized derivatives where the platform allows it. Removing a photo from one profile does not remove reposts, search caches, or copies held by other people. Record each distinct source rather than claiming the image was erased globally.

7. Connect findings without building an unnecessary graph

Link only what is needed to explain your own exposure: the same username across two platforms, an old email in a breach, a broker profile that reveals an address, or a public document that links a real name to a pseudonym. Keep confidence labels. A shared avatar or username can be coincidence.

The useful output is a list of confirmed paths, such as “public username leads to old forum profile, which reveals recovery email.” Keep unrelated people and records out of the working set so the audit remains easy to verify.

8. Prioritize by impact and reversibility

Remediation order
Remediation order
PriorityFindingResponse
CriticalCredentials, active session secrets, recovery bypass, or direct physical threatRevoke access, rotate affected credentials, and preserve the evidence needed to track the incident
HighHome address, government identifier, private phone, family link, or high-value account pathRemove or restrict source, deindex, harden related accounts, and monitor
MediumOld profile, reused username, employment detail, or data-broker listingDelete, separate, correct, or opt out in a tracked queue
LowBenign public mention with no useful linkageAccept, document, or monitor without creating more copies

Stop point: choose the response

Not every result should be deleted. Removal can confirm to a broker that a record is active, trigger identity-proof demands, break a professional page, or create a public dispute. Choose one control per finding: remove at source, deindex, correct, lock down, separate identities, replace contact information, monitor, or accept.

9. Verify remediation

  1. Save the request date, route, fields disclosed, and confirmation identifier.
  2. Do not mark the finding removed when a form is merely submitted.
  3. Check the source page after the provider's stated processing time.
  4. Check search results separately and from a logged-out context.
  5. Record whether the information was deleted, corrected, suppressed, or only deindexed.
  6. Schedule a recheck because broker listings and indexed copies can return.

10. Produce a short final report

The useful deliverable has five parts:

  • Scope: identifiers, sources, and audit date.
  • Exposure summary: confirmed high and medium findings without reproducing unnecessary personal data.
  • Attack paths: how separate public records connect to a real consequence.
  • Remediation queue: owner, action, status, evidence, and recheck date.
  • Residual risk: public records, third-party copies, court records, and items accepted or impossible to remove.

Recurring schedule

Recheck high-impact identifiers after major events such as moving, a breach notification, a public-facing role, harassment, a domain registration change, or closing an account. For ordinary maintenance, a small quarterly or twice-yearly review is more useful than constant searching. Notifications from a verified breach service or eligible search-removal tool can cover part of the interval.

Sources

Frequently Asked Questions

What is a self-OSINT audit?

A self-OSINT audit searches public sources for your own names, identifiers, images, accounts, and exposed records, then turns confirmed findings into a prioritized remediation queue.

Does removal from Google delete the source page?

No. Google says removal affects Google Search results. To remove information from the web at its source, the site owner or publisher must remove the underlying page or data.