Loading VAPT findings tracker…
Baseline not commissioned
The repository defines a typed finding shape, proposed remediation targets, and an empty registry. No baseline VAPT engagement has been completed or scheduled in the evidence registry, and an empty list must not be read as proof that the system has no vulnerabilities.
Recorded findings
0
Past-due fixes
0
Recorded critical
0
Engagement status
PLANNED
Proposed remediation policy
Fix-time targets are set in our policy register and only change after source review. A deployed enforcement gate and governance approval record are not established by this page alone.
| Severity | Target fix time (calendar days) | Open findings today | Current evidence state |
|---|---|---|---|
| Critical | 7 days | 0 | Target is defined in source; exact-candidate enforcement has not been proven. |
| High | 30 days | 0 | Target is defined in source; exact-candidate enforcement has not been proven. |
| Medium | 60 days | 0 | Target is defined in source; exact-candidate enforcement has not been proven. |
| Low | 90 days | 0 | Target is defined in source; exact-candidate enforcement has not been proven. |
| Informational | Tracked, not enforced | 0 | INFO findings are recorded for trend analysis only. |
Lifecycle
Status transitions are validated by assertFindingWellFormed; terminal record shapes require evidence fields. This validates structure, not the operation of a production remediation program.
Step 1
OPEN
Finding accepted into the tracker; severity assigned; SLA clock starts.
Step 2
IN_REMEDIATION
Owner has scoped the fix; PR or change ticket linked; remediation under way.
Step 3
RESOLVED
Fix shipped to production; awaiting independent verification.
Step 4
VERIFIED
Assessor has retested and confirmed the fix; finding closed.
Proposed risk-acceptance boundary
The source model permits ACCEPTED_RISK only with a written justification and a named approver role. Any real use still requires an authorized governance process and must not replace a technically feasible remediation.
Source registry
No findings recorded yet.
The platform has not yet undergone a recorded baseline VAPT engagement. Zero recorded findings means “not assessed,” not “secure” or “no vulnerabilities.” When an approved, redacted result is added to the registry, this page can surface it.
Researchers and partners can submit findings via our coordinated disclosure path. The published scope explains what is authorized; it does not promise an unverified response or publication SLA.