Understanding your report
Risk score, severities, compliance posture, and diffs.
A report is designed to be read top to bottom: the headline numbers first, then the findings, then the compliance overlay. Here’s how to interpret each part.
Risk score
A single number from 0 to 100. It’s weighted by severity and by how exploitable each finding is — a critical with a real, actively-exploited CVE moves the needle far more than a theoretical one. Use it to track a domain over time, not to compare two different sites.
Severities
- Critical / High — fix first. These are the findings our remediation-help offer is gated on.
- Medium — worth scheduling in.
- Low / Info — hardening and hygiene; good to clear but rarely urgent.
Compliance posture
Findings are also mapped onto common frameworks (OWASP Top 10, PCI DSS, SOC 2) so you can see which controls a finding touches. The posture cards at the top summarise “how many controls came back clear.” Important: this is a non-binding view of what our scan observed — it is not an official certification, and a control with no gaps only means we found nothing mapping to it, not that your site formally passes it.
Since last scan
When a domain has been scanned before, the report shows what’s new and what’s resolved versus the previous run — so after you ship a fix you can confirm it actually cleared, and catch regressions early.
Accepting risk (suppressions)
Some findings are known and accepted — a compensating control at the edge, a false positive, a risk the business has signed off. You can suppress a finding with a reason; it moves to a collapsed section and stops appearing in the active list and the diff for that domain. The reason is logged so you can find it later, and suppressions survive re-scans.
AI explanations
For any finding you can generate a plain-language explanation, and for a whole scan you can generate a worst-case “attack narrative” that chains the findings into a realistic story. These use AI credits — see Plans & billing.
PDF export
Every report exports to a self-contained PDF — the format to hand to a developer, a client, or an auditor.