Security overview

2
Critical findings open
5
Warning-level findings
38
Assets under scope
92%
Findings retested and closed

Security signals

edge-gateway-01
Normal
api-gateway
Monitored
third-party-conn
Review
svc-reporting
Critical

Activity

Penetration test — svc-reporting finding retested2m ago
Threat intelligence — third-party-conn credential scope reviewed41m ago
Architecture review — cloud IAM boundaries updated3h ago
Control review — TLS configuration on edge-gateway-01 verified1d ago

Vulnerabilities

FindingAssetSeverityStatusDiscovered
Outdated dependency, RCE classsvc-reportingcriticalOpen2026-08-19
Broad-scope third-party credentialthird-party-conncriticalIn progress2026-08-22
Partial rate limiting, public endpointapi-gatewaywarningIn progress2026-08-11
Verbose errors in staging configsvc-billingwarningOpen2026-08-14
Deprecated TLS cipher allowededge-gateway-01warningScheduled2026-08-03
Missing security.txtedge-gateway-01informationalOpen2026-07-29
Cookie lacks SameSite attributesvc-billinginformationalClosed2026-07-22

INC-2026-0143

investigating
08:14
Detection — anomalous authentication volume against idp-core.
08:20
Investigation — pattern consistent with credential stuffing, narrow IP range.
08:31
Containment — IP range blocked at edge; affected accounts reset.
Verification — pending.

Risk posture

Governance4 / 5
Identity3 / 5
Application security2 / 5
Detection & response4 / 5

Reports

ReportTypeDeliveredStatus
Q3 external penetration testPenetration test2026-08-252 open
Cloud IAM architecture reviewArchitecture review2026-07-30closed
Annual application security assessmentApplication security2026-06-12closed