Reading the results

Findings

Every problem the platform found, with the evidence it was derived from.

What a finding is

A finding is one problem, on one asset, produced by one check. It carries a severity, a confidence, the evidence it was derived from, and what to do about it.

The evidence is the part worth opening. A finding that says a header is missing shows you the response. A finding about a certificate shows you the certificate. This is what lets a finding be handed to an engineer without being re-verified first.

The findings list, with severity, confidence and the asset each finding belongs to.
Findings across every asset, filterable by severity, confidence, asset and state.

State across scans

Findings are tracked between scans rather than regenerated each time. A finding is new, persisting, fixed, or regressed.

Regressed is the one to watch: it means something you already fixed has come back. Without that state it would reappear in the list as though it had always been there.

Where to start

Sort by severity, then read confidence. High severity with high confidence is the shortest path to something worth fixing today. High severity with low confidence is worth confirming before you act — and the finding will tell you what it was inferred from so you can.