Findings are detected vulnerabilities with severity ratings, CVSS scores, and remediation guidance.
Each finding's severity is computed from a three-axis matrix:
Every finding includes a CVSS 4.0 vector string and score. The vector is adjusted based on the agent's actual response. Refused responses get lower CIA impact, while immediate compliance receives full severity.
Each finding has an evidence viewer showing the raw agent response, the probe payload, CVSS breakdown, and attack path steps. Compliance framework badges link findings to relevant controls.
Each finding includes a confidence score (0-1) combining the LLM evaluator's signal strength with probe consistency. Labels: HIGH (≥0.85), MEDIUM (≥0.65), LOW (≥0.40), or UNCERTAIN.
Every finding moves through a lifecycle: new → triaged → confirmed, false positive, or accepted risk. Confirmed findings resolve to fixed or suppressed. Dismissed or fixed findings that reproduce in a later scan automatically reopen — statuses can never silently drift. Transitions that dismiss a finding (false positive, accepted risk, suppressed) require a written reason, and every transition is recorded in the finding's status timeline.
Suppression rules auto-triage future matches: match by probe key, attack-path pattern, or severity-plus-probe. Deleting a rule never rewrites history — already-triaged findings keep their status.