Findings Overview
Each finding includes:Severity Rating
Critical, High, Medium, Low, Informational
Vulnerability Type
Category (XSS, SQLi, IDOR, etc.)
Evidence
Screenshots, requests, payloads
Remediation
Step-by-step fix guidance
Severity Levels
| Level | Description | SLA Recommendation |
|---|---|---|
| Critical | Immediate exploitation risk, data breach potential | Fix within 24 hours |
| High | Significant security impact | Fix within 7 days |
| Medium | Moderate risk with mitigating factors | Fix within 30 days |
| Low | Minor security concern | Fix within 90 days |
| Informational | Best practice recommendations | Review at discretion |
Finding Details
Summary
Summary
Brief description of the vulnerability and its impact.
Technical Details
Technical Details
- Affected endpoint
- Vulnerable parameter
- Attack payload used
- Request/response data
Proof of Concept
Proof of Concept
Working exploit demonstrating the vulnerability:
Business Impact
Business Impact
Analysis of how this vulnerability affects your business:
- Data exposure risk
- Compliance implications
- Reputation impact
Remediation Steps
Remediation Steps
Specific guidance for fixing the vulnerability with code examples.
Workflow States
1
New
Newly discovered vulnerability awaiting review.
2
Confirmed
Validated by team, acknowledged as genuine issue.
3
In Progress
Fix is being developed.
4
Fixed
Remediation deployed, awaiting verification.
5
Verified
Retest confirmed the fix is effective.
Filtering Findings
Use filters to focus on what matters:Bulk Operations
Manage multiple findings at once:- Bulk Status Update: Move multiple findings to new state
- Bulk Assignment: Assign to team member
- Bulk Export: Download selected findings
- Bulk Ignore: Mark false positives
Retesting
After applying fixes:- Mark finding as Fixed
- Click Request Retest
- AI agent verifies the fix
- Finding moves to Verified or returns to Confirmed
False Positives
If a finding is not a genuine vulnerability:- Click Mark as False Positive
- Add justification explaining why
- Finding is excluded from future reports
- AI learns from feedback to reduce similar false positives
Integration with Issue Trackers
Export findings to:- Jira
- GitHub Issues
- GitLab Issues
- Linear
- Custom webhooks
Configure integrations in Settings → Integrations.