Import Findings
Path: /import · Sidebar: Findings → Import Findings
Bring results from external scanners into apPosture so everything lives in one unified, deduplicated view. Imported findings are correlated against native findings just like any other source.
Supported formats
20+ formats from common commercial and open-source tools, including Burp Suite, Qualys, Nessus, Checkmarx, SonarQube, Fortify and others (SARIF and common JSON/XML exports).
Import a file
- Open Import Findings.
- Choose the tool/format (or let apPosture auto-detect).
- Upload the export file and select the application to attribute findings to.
- Submit - the import is recorded as an Assessment.
What happens on import
- Findings are normalised into the unified model.
- CVSS/EPSS re-scoring is applied for consistent prioritisation.
- Automatic deduplication merges them with native findings describing the same issue, so you don't get duplicates in the Vulnerabilities hub.
One source of truth
Importing third-party results means your posture, priorities and reports reflect all your tooling - not just apPosture's native scanners.