Framework views
The Compliance page has a tab per framework. Every finding ID is mapped to the
categories it genuinely evidences, and vulnerability findings also map dynamically through their
tags (CISA-KEV, CWE-<n>).
| Tab | What it shows |
|---|---|
| Evidence | Cadence and coverage: the view an auditor reads first (see below). |
| OWASP Top 10 (2021) | Open findings per category. A03 Injection, A04 Insecure Design, A07 Identification and Authentication Failures, A09 Logging and Monitoring Failures and A10 SSRF cannot be observed from outside and are always shown as Not assessed, never as a pass. |
| CWE | The underlying weakness behind each finding, by CWE identifier. |
| Known exploited (CISA KEV) | Every open vulnerability finding whose CVE is on the KEV catalog. These come first. |
| Privacy (GDPR) | Encryption in transit (Art. 32(1)(a)), known vulnerabilities and unsupported software, data stores exposed to the internet, third-party code on your pages, and cookies set before consent. |
| CIS v8 | The CIS Critical Security Controls safeguards an external view can evidence, such as DMARC and service exposure. |
| PCI DSS | PCI DSS 4.0.1 requirements an external view can evidence, such as strong cryptography in transit, anti-phishing controls and payment-page script integrity. Not an ASV scan. |
Each category carries a status: Action needed, No issues found, Risk accepted or Not assessed, and drills down to the hosts and findings behind it. Checks with no defensible mapping (registrar locks, CAA, blocklist listings) are deliberately left unmapped rather than forced into a category.
Framework views and CSV exports are available on every plan, and stay readable after a subscription lapses.
Evidence pack (PDF)
The evidence pack is written for an auditor or insurer rather than an engineer. It leads with cadence and coverage: scans performed, distinct weeks covered, first and latest scan per domain and the score trend, because what those readers need is proof that monitoring operated continuously. A Current posture by framework section then summarises the framework views. Every PDF is dated; reports and evidence packs are kept for a year.
Controls it is commonly filed against:
- SOC 2 CC7.1 (monitoring for vulnerabilities and configuration change) and CC4.1 (evaluating that monitoring).
- ISO 27001 Annex A 8.8 (management of technical vulnerabilities) and A.5.7 (threat intelligence).
- Cyber insurance and vendor questionnaires: "do you perform external vulnerability scanning", "how often", "how do you track remediation".
This is evidence for the external-monitoring rows of a controls matrix. It is not a penetration test, not a PCI ASV scan, and not a certification.
CSV exports
Export buttons are on the Scans dashboard (findings), the Changes page (changes, for the day window selected), the Compliance page and the Inventory page.
| Export | Columns |
|---|---|
| Findings | host domain client severity finding_id module title description remediation evidence tags triage owasp_top10_2021 cwe cis_v8 pci_dss_4 privacy cisa_kev scan_id scanned_at |
| Changes | detected_at target kind importance title detail before after scan_id change_id |
| Inventory | type value state domains client provider asn as_org ips hosts depends_on sources first_seen last_seen added_at added_by last_scanned_at score open_findings worst_severity evidence |
Files are UTF-8 with a byte-order mark so Excel opens them cleanly. Cells that would start a
spreadsheet formula are neutralised, and multiple values in one cell are joined with
;. An export larger than 4.5 MB is delivered as a download link valid for 5 minutes.
Triage and risk acceptance
Findings can be acknowledged, muted or accepted per host. Mutes and acceptances require a review date (at most one year) and resurface automatically when it passes. The weekly digest lists acceptances lapsing that week. This is the audit trail an assessor asks for when a finding is still open: who accepted it, why, and until when.