Self-OSINT Audit: Find and Reduce Your Personal Exposure
A self-OSINT audit answers three questions: what can a stranger find, which findings create real risk, and what can be removed, corrected, separated, or monitored. The output is a time-stamped exposure register and a short remediation queue with owners and recheck dates.
Prepare a private evidence register
Use an encrypted local document or database. Give findings opaque IDs rather than filenames containing the exposed phone number or address. Store only what you need to remediate the exposure. A screenshot of an entire people-search profile creates a new copy of the data; a URL, field list, date, and narrowly cropped evidence may be enough.
| Field | Purpose | Example value |
|---|---|---|
| Finding ID | Reference without repeating personal data | EX-014 |
| Source and URL | Where the exposure exists | Search result or publisher page |
| Identifier type | What matched | Name, email, phone, address, username, image |
| Confidence | How certain the match is | Confirmed, likely, ambiguous |
| Impact | Why it matters | Account takeover, home safety, impersonation, low consequence |
| Control | Available response | Delete, opt out, deindex, correct, separate, monitor |
| Evidence date | Freshness | 2026-08-05 |
| Next check | Reappearance or unresolved work | 30, 90, or 180 days |
1. Build your identifier list
Start with identifiers you already know and control: full name variants, prior surnames, usernames, email addresses, phone numbers, domains, public profile URLs, and profile images. Add old cities only when needed to distinguish your record from someone with the same name.
Keep the list tied to your own exposure. If a public record includes another person alongside you, record only the fields needed to identify and remediate your listing.
2. Search from a clean context
EFF recommends searching for your own name, nickname, handle, avatar, address, phone number, and email. Use a private window or separate browser while logged out so personalization does not dominate the results. Test more than one search engine because deindexing and ranking differ.
- Exact full name and common variants in quotation marks.
- Username alone and with platform or city terms.
- Email address and phone number in exact form.
- Current and former address only when home-location exposure is in scope.
- Profile-image reverse search using an image you own.
- Public documents connected to your own domain or organization.
Open results cautiously. People-search and scam sites may use aggressive scripts, notification prompts, or payment traps. Do not install extensions, upload an ID, or pay for a report merely to satisfy curiosity. Record the public snippet and stop if the site demands more data than the removal benefit justifies.
Stop point: confirm the match
3. Check accounts and breach exposure
Review public profiles from the outside, not only while logged in. Record exposed contact details, location history, workplace, family connections, public friend lists, old posts, visible recovery hints, and reused usernames. Then inspect the platform's own privacy and session controls.
Have I Been Pwned provides point-in-time breach searches and verified notifications for an email address. Its documentation says notification enrollment requires control of the address. A breach hit is not proof that an account is currently compromised; it is evidence to rotate reused passwords, strengthen multi-factor authentication, review the affected data classes, and watch for targeted phishing.
| Exposed field | Immediate action | Longer control |
|---|---|---|
| Password | Change it anywhere reused and terminate sessions | Use unique generated passwords or passkeys |
| Email and phone | Expect targeted phishing and recovery attempts | Separate public contact from account recovery |
| Security answers | Replace answer-based recovery where possible | Use random stored answers or stronger recovery |
| Address or identity data | Monitor impersonation and financial risk appropriate to jurisdiction | Reduce broker exposure and protect high-value accounts |
| Session token or secret | Revoke sessions, rotate the credential, and inspect access logs | Limit token lifetime and device access |
4. Check people-search and broker listings
Record the broker, profile URL, fields shown, claimed source, parent company, opt-out route, and proof requested. EFF notes that broker data can repopulate, so deletion is not permanent. Prefer an official opt-out path. Minimize the information sent back to the broker and do not upload government ID unless the documented process and risk justify it.
For a local-first agent workflow, use the data broker removal guide. The audit remains separate from submission: first confirm the matching record, then approve the narrow removal payload, record confirmation, and recheck later.
5. Review search removal and source removal separately
Google's Results about you can monitor search results containing personal contact information and accept removal requests for eligible results. Google states that removing a result from Search does not delete the source page. Create two tasks when necessary: deindex the result from a search engine and request deletion or correction from the publisher.
Preserve the original URL and request confirmation before a page disappears. After source deletion, check that the page returns the expected status and use the search engine's outdated-content route if an old cached result persists.
6. Audit image and document metadata
Download the public copies connected to your exposure. Check document properties, author names, revision comments, embedded filenames, GPS coordinates, capture time, device model, and thumbnails. Inspect sensitive originals locally rather than uploading them to a metadata-checking website.
Replace exposed files with sanitized derivatives where the platform allows it. Removing a photo from one profile does not remove reposts, search caches, or copies held by other people. Record each distinct source rather than claiming the image was erased globally.
7. Connect findings without building an unnecessary graph
Link only what is needed to explain your own exposure: the same username across two platforms, an old email in a breach, a broker profile that reveals an address, or a public document that links a real name to a pseudonym. Keep confidence labels. A shared avatar or username can be coincidence.
The useful output is a list of confirmed paths, such as “public username leads to old forum profile, which reveals recovery email.” Keep unrelated people and records out of the working set so the audit remains easy to verify.
8. Prioritize by impact and reversibility
| Priority | Finding | Response |
|---|---|---|
| Critical | Credentials, active session secrets, recovery bypass, or direct physical threat | Revoke access, rotate affected credentials, and preserve the evidence needed to track the incident |
| High | Home address, government identifier, private phone, family link, or high-value account path | Remove or restrict source, deindex, harden related accounts, and monitor |
| Medium | Old profile, reused username, employment detail, or data-broker listing | Delete, separate, correct, or opt out in a tracked queue |
| Low | Benign public mention with no useful linkage | Accept, document, or monitor without creating more copies |
Stop point: choose the response
Not every result should be deleted. Removal can confirm to a broker that a record is active, trigger identity-proof demands, break a professional page, or create a public dispute. Choose one control per finding: remove at source, deindex, correct, lock down, separate identities, replace contact information, monitor, or accept.
9. Verify remediation
- Save the request date, route, fields disclosed, and confirmation identifier.
- Do not mark the finding removed when a form is merely submitted.
- Check the source page after the provider's stated processing time.
- Check search results separately and from a logged-out context.
- Record whether the information was deleted, corrected, suppressed, or only deindexed.
- Schedule a recheck because broker listings and indexed copies can return.
10. Produce a short final report
The useful deliverable has five parts:
- Scope: identifiers, sources, and audit date.
- Exposure summary: confirmed high and medium findings without reproducing unnecessary personal data.
- Attack paths: how separate public records connect to a real consequence.
- Remediation queue: owner, action, status, evidence, and recheck date.
- Residual risk: public records, third-party copies, court records, and items accepted or impossible to remove.
Recurring schedule
Recheck high-impact identifiers after major events such as moving, a breach notification, a public-facing role, harassment, a domain registration change, or closing an account. For ordinary maintenance, a small quarterly or twice-yearly review is more useful than constant searching. Notifications from a verified breach service or eligible search-removal tool can cover part of the interval.
Sources
Frequently Asked Questions
What is a self-OSINT audit?
A self-OSINT audit searches public sources for your own names, identifiers, images, accounts, and exposed records, then turns confirmed findings into a prioritized remediation queue.
Does removal from Google delete the source page?
No. Google says removal affects Google Search results. To remove information from the web at its source, the site owner or publisher must remove the underlying page or data.