Introduction
Findings are the core deliverable of a security assessment. Each finding documents a identified vulnerability or security observation with severity, CVSS score, rich-text content, linked assets, and a remediation status.
Findings support:
- Markdown content with Live, Rendered, and PDF preview modes
- CVSS score calculation
- Status workflow (Draft, Open, Remediated, Partially Remediated, Not Remediated, Unknown)
- Comments with threaded replies and status tracking
- Content version history with diff and restore
- Import from finding templates
- Jira issue creation (when client integration is configured)
- Bulk status updates with optional email notifications

Finding Severities
| Severity | Level |
|---|---|
| Informational | 0 |
| Low | 1 |
| Medium | 2 |
| High | 3 |
| Critical | 4 |
Finding Statuses
| Status | Description |
|---|---|
| Draft | Finding is being written. Hidden from client accounts. |
| Open | Finding is confirmed and awaiting remediation. |
| Remediated | The vulnerability has been fixed. |
| Partially Remediated | A partial fix has been applied. |
| Not Remediated | The vulnerability remains unresolved. |
| Unknown | Remediation status is unclear. |
