Findings Guide
What severity levels mean, how to work a finding, and how remediation guidance helps.
Severity levels
| Severity | What it means |
|---|---|
critical | Actively exploitable or already exposing you, e.g. an expired TLS certificate. |
high | A real gap in a control that's expected to exist, e.g. a missing DMARC record. |
medium | Worth fixing, lower urgency, e.g. a weaker-than-ideal security header. |
low | Minor hardening opportunity. |
info | Informational only, e.g. a newly discovered subdomain, not a problem by itself. |
Statuses
- Open: not yet addressed.
- Acknowledged: someone's seen it and is working on it, or has accepted the risk for now. The finding stays on the domain; current and past acknowledgments live on the Findings page.
- Resolved: only after a scan confirms the issue is gone. Resolve starts a scan (or queues the next scheduled one) and shows Confirming… until that scan finishes. If the issue is still there, it stays open. If it reappears later, it reopens automatically.
Due dates
Pick a date, then click Save. The calendar stays open until you confirm. It doesn't write on every click.
Remediation guidance
Every finding includes a "Recommended fix": concrete steps for that specific issue, not a generic description of the category. It shows on the Domains page, the Findings page itself, the CSV/PDF export, and the public report-link page, so it travels with the finding wherever it's viewed.
On Pro, the Domains page also lists every certificate's issuer and expiry. A daily or weekly alert schedule (Billing) emails owners and admins before a certificate lapses.
Cross-domain Findings view
The Findings page searches and filters (by severity, status, or domain) across every domain in the organization at once, grouped by domain with each subdomain's findings nested underneath its parent. Useful once you have more than a couple of domains and don't want to check each one individually.
Turning a finding into a task
Link a finding to a Project task to assign it an owner and a due date. On Pro, an overdue task sends the assignee a reminder email; unassigned overdue findings can also go to owners/admins as a recurring digest. Control both from your profile's notification preferences.