“We restored password protection, blocked search engines from indexing the draft pages and changed all the system access keys,” Mia Morin said.
Mia Morin, Intimeros and a test site that went public
Mia Morin, identified in reporting as Editor & AI Quality Analyst at Intimeros, spotted the problem after a test version of the company's AI-companion review site was indexed by Google. Intimeros evaluates and rates AI companions — what the site calls boyfriends, girlfriends and other types of pals — and the test site was part of a redesign effort.
How an intentional temporary change stayed in place for three weeks
According to the report, a colleague working on a test instance had deliberately turned off password protection to show a client what they were working on. That protection remained disabled for three weeks without being noticed. During that period the staging domain was publicly accessible and, crucially, was not excluded from search engines by a robots.txt file.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleWhat was exposed: editorial drafts, pricing and internal notes
While the staging site did not contain user personal data, it was connected to a live production database and served real editorial content. The publicly accessible pages included unpublished reviews, prices and private product notes about various AI companion services. The reporting notes this was editorial content only, but it also states the exposure “could have allowed competitors to see everything that Intimeros was working on and to deduce their entire editorial strategy.”
Immediate remediation and follow-up changes at Intimeros
After discovering the indexing, Morin took a sequence of steps to reduce exposure. She restored password protection, blocked search engines from indexing draft pages, and changed system access keys. Morin said the company now secures every test site the same way it secures the official website and runs weekly automated scans to catch exposed pages.
What this means for technologists, competitors, and editorial teams
- Technologists and security teams: The incident underscores the risk of leaving staging environments publicly reachable and connected to live databases. The source recommends that test or staging sites require logins, use tools to block search and AI crawling, and, where possible, be placed on private servers accessible only via VPN.
- Competitors and commercial observers: Because the exposed pages included unpublished reviews, prices and private notes, the incident illustrates how staging leaks can reveal a publisher’s near-term editorial pipeline and pricing signals even when no user data is involved.
- Editorial teams and product managers: The case shows how routine development conveniences — temporarily disabling access controls to demo work — can turn into operational exposure if those changes are not reversed or are not subject to automated checks.
The episode is a compact lesson in access control and operational hygiene. In this case, the public-facing consequences were limited to editorial intellectual property because no personal user data was stored on the staging instance; still, the combination of an unprotected test site, a live database connection and the absence of a robots.txt exclusion meant a three-week window in which proprietary work was visible to anyone using search. Following the discovery, Intimeros applied immediate fixes and instituted recurring scanning to reduce the chance of repetition — and the reporting closes with a straightforward checklist of mitigations: require logins for staging, block search and AI crawling, and consider private servers plus VPNs for test environments.
Original story: https://www.theregister.com/security/2026/08/27/ai-girlfriend-review-sites-secrets-were-exposed-to-the-world-for-three-weeks/5293064




