Skip to content

Scanning

Understand Scan Results

High, Medium and Low findings are confirmed vulnerabilities; Potentially findings are unconfirmed. This guide also shows where to find the coverage and evidence behind a finding, how to check that a fix worked, and what each scan consumes from your plan or wallet.


How do I tell a confirmed finding from a potential one?

High, Medium and Low are confirmed vulnerabilities; Potentially means the vulnerability is unconfirmed. Every finding has a risk rating:

Rating What it means
Critical A severe threat to the system's security: exploitation could lead to significant damage, leakage of sensitive data or complete system compromise.
High, Medium, Low Confirmed vulnerabilities, scored by impact and complexity.
Potentially Unconfirmed vulnerabilities that may depend on context and usage.
Hardening A missing security measure that could prevent or reduce the impact of other vulnerabilities.
Secure Tests confirm the vulnerability is absent, or a security measure is in place.
Important, Info Informative findings that help with manual assessment or confirm how the application behaves.

If a rating doesn't fit your context, you can change it.

How do Deep Agentic Scans validate findings?

Deep Agentic Scans validate their findings with a proof-of-concept exploit. Inside the scan results, open the Transparent Attack Validation paths to see the decisions, tool outputs and steps the AI agent took to validate each vulnerability.

The scan effort you choose sets how much uncertainty the scan reports:

  • Core reports only high-confidence risks.
  • Advanced also reports medium-confidence risks.
  • Elite may also report speculative or lower-confidence risks for your review.

AI-agent findings have no human validation. For a pentest reviewed by experts, see the expert-validated assessment in Testing Modes at a Glance.


Where do I find the coverage and evidence behind a finding?

Coverage and evidence are in the Scan Coverage Heatmap (Deep Agentic Scans), Call Coverage, the IDE's API, Traffic, Logs, Pcap and Dynamic views, and the Full Report, Executive Summary Report and Standards Report PDFs.

To see Open Details
Which parts of the application the AI agent tested, and how deeply The Scan Coverage Heatmap in the results of a Deep Agentic Scan Mobile, Web
The screens the scan went through in a mobile app Call Coverage Check Call Coverage
HTTP requests and responses, device logs and pcap files API, Traffic, Logs and Pcap in the IDE IDE
Call traces collected during dynamic analysis Dynamic in the IDE IDE
The description, recommendation, references and technical details of each finding Vulnerabilities IDE
A report to share Full Report, Executive Summary Report or Standards Report Generate a PDF report, Share a scan report

Deep Agentic Scans remember previous findings and validated attack paths (Historical Scan Processing, on by default), so later scans focus on new or changed functionality and coverage builds up across assessments.


How do I check that a fix worked?

  • Mark the ticket as fixed. Each finding is tracked in a ticket. When a ticket is marked as fixed, later scans verify it: if the vulnerability is gone, the ticket is marked as verified; if it is found again, the same ticket is re-opened. See Ticket Lifecycle.
  • Re-test one finding. A Single Vulnerability Assessment re-tests one reported finding after a fix, without a full rescan. It uses no AI tokens. See Scan Profiles.

What does a scan consume from my plan or wallet?

Deep Agentic, multi-asset, Mobile Shielding and source code scans use AI tokens (Cyber Models) or your own key (BYOK); Fast, Full and Exhaustive scans, attack surface scans and Single Vulnerability Assessments use none; the expert-validated assessment uses Assessment Credits.

Scan AI tokens or credits
Free store scan (Community plan) None
Fast, Full and Exhaustive scans, attack surface scans and Single Vulnerability Assessments None
Deep Agentic Scan, multi-asset scan and Mobile Shielding Scan An AI provider: Cyber Models tokens or your own key (BYOK)
Source code scan (Core, Advanced or Elite effort) An AI provider: Cyber Models tokens or your own key (BYOK)
Expert-validated assessment Assessment Credits, the billing unit for the expert review (see Pricing)

With Cyber Models, the full token cost of the effort (Core 50, Advanced 200, Elite 400) is debited from your wallet when the scan starts, and unused tokens are refunded when it stops or completes. If your balance is too low, the scan is rejected. The Token Wallet tab shows your balance and every purchase and scan debit. See Purchase tokens and Use prepaid tokens in a scan.

With BYOK, your AI provider bills you directly.

For what each plan includes, see Pricing.