For the complete documentation index, see llms.txt. This page is also available as Markdown.

📃Viewing and acting on your pentest results

View your pentest results in Portal, and begin the remediation process.

After each penetration test, your results are uploaded into Portal. You will receive a notification by email (and Slack, if you have the integration) when results are available.


View your results

  1. In the projects bar, select the project that you would like to view.

  2. Open the Vulnerabilities tab.

  3. In the table view, you can view the status, severity, SLA status, date identified, last updated, affected compliance frameworks, and any labels. If you have any project management integrations enabled they will also be visible.

The Vulnerabilities tab includes a table of all vulnerabilities in the project.
  1. Select any vulnerability in the table to review its details, including the description, impact, mitigation tactics, replication steps, evidence, and comments.


Remediation actions

After viewing your results, there are actions your team can take to tackle remediation.

In the main menu of your project’s vulnerability dashboard, you can take the following actions:

  • Book a retest for selected issues (see Retesting your vulnerabilities).

  • Copy vulnerability information to your clipboard.

  • Export vulnerability data as a CSV file (see Viewing and downloading reports and executive summaries).

  • Add labels.

    • Labels make it easier to categorize and sort vulnerabilities. Users can add up to 50 labels per project, including (but not limited to) release versions, assigned teams, or internal priority.

  • Accept risk for a vulnerability.

    • Org Admins and Project Admins can accept risk by selecting the vulnerability and clicking Accept Risk.

    • When submitting a request to accept the risk of a vulnerability, you must provide a note to explain why the risk is accepted and timestamp for the acceptance.

    • After the request is approved, the issue is assigned the Accepted Risk state and will be treated as a Closed issue. Therefore, SLAs don’t apply to it.

  • Reopening vulnerabilities.

    • An vulnerability is reopened by Software Secured if—after it was first detected and then confirmed to be remediated—it is detected again.

    • If your team chooses to mitigate an issue that you Accepted Risk on in the past, you will need to reopen it before you can request retesting.

    • To reopen an issue, select an Accepted Risk vulnerability and click Reopen Issue. The issue is then marked with the Updated status and the original risk score is applied again. For any new report, the issue is moved back into the main report.

For more information about tracking remediation efforts, see Remediating vulnerabilities.

Last updated

Was this helpful?