Security overview
2
Critical findings open
5
Warning-level findings
38
Assets under scope
92%
Findings retested and closed
Security signals
edge-gateway-01
Normalapi-gateway
Monitoredthird-party-conn
Reviewsvc-reporting
CriticalActivity
Penetration test — svc-reporting finding retested2m ago
Threat intelligence — third-party-conn credential scope reviewed41m ago
Architecture review — cloud IAM boundaries updated3h ago
Control review — TLS configuration on edge-gateway-01 verified1d ago
Vulnerabilities
| Finding | Asset | Severity | Status | Discovered |
|---|---|---|---|---|
| Outdated dependency, RCE class | svc-reporting | critical | Open | 2026-08-19 |
| Broad-scope third-party credential | third-party-conn | critical | In progress | 2026-08-22 |
| Partial rate limiting, public endpoint | api-gateway | warning | In progress | 2026-08-11 |
| Verbose errors in staging config | svc-billing | warning | Open | 2026-08-14 |
| Deprecated TLS cipher allowed | edge-gateway-01 | warning | Scheduled | 2026-08-03 |
| Missing security.txt | edge-gateway-01 | informational | Open | 2026-07-29 |
| Cookie lacks SameSite attribute | svc-billing | informational | Closed | 2026-07-22 |
INC-2026-0143
investigating08:14
Detection — anomalous authentication volume against idp-core.
08:20
Investigation — pattern consistent with credential stuffing, narrow IP range.
08:31
Containment — IP range blocked at edge; affected accounts reset.
—
Verification — pending.
Risk posture
Reports
| Report | Type | Delivered | Status |
|---|---|---|---|
| Q3 external penetration test | Penetration test | 2026-08-25 | 2 open |
| Cloud IAM architecture review | Architecture review | 2026-07-30 | closed |
| Annual application security assessment | Application security | 2026-06-12 | closed |