Executive Security Overview
Authorization Gate
Integration Truth Panel
Authorized Testing
SQL injection, XSS and related categories appear only when supported by real scanner evidence. Burp remains external/unavailable until connected.
CVSS / Vulnerability Heatmap
OWASP / CWE / CVSS Findings
Authorize an assessment and run a real scan.
Live Risk Analytics
Dynamic GRC Report
ISO 27001 · ISO 42001 · NIST · OWASP mappings derived from stored findings.
No report loaded.
Gemini Remediation
AI analysis is advisory and never replaces scanner evidence.
No AI analysis requested.
Evidence Document Review Vault
Persistent PostgreSQL-backed storage · SHA-256 integrity · assessment binding · audited deletion · 20 MB/file limit. Executables/scripts are rejected.
Raw Scanner Evidence
Scanner evidence will appear here.
Multi-Format Report Center
Exports are generated from this assessment's stored findings and evidence. Choose the report purpose and native output format.
GRC Framework Crosswalk
Evidence-driven control references. This is not a claim of certification and does not reproduce copyrighted standards text.
Generate a framework-specific evidence/gap report. Downloads require fresh MFA.
Evidence-Derived Architecture
Only observed components are shown as observed. Private/internal tiers require document or source evidence.
Authorized URL
Not assessed
DNS / Address
Awaiting evidence
HTTP / TLS Edge
Observed externally
Exposed Services
Nmap evidence
Internal Architecture
Requires documents/source
Control-plane workflow
Authenticated Operator
│ Password + TOTP
▼
Authorization / Scope Gate
│
├── Nmap ──────┐\n ├── OWASP ZAP ─┤
├── Wapiti ────┼──► Evidence + SHA-256 ─► Findings / CVSS ─► GRC Mapping
└── Semgrep ───┘ │
├──► Gemini Remediation
└──► Reports / Audit
External: Burp Suite = optional provider (truthfully unavailable until configured)