Security Scorecards
Path: /reports/scorecards · Sidebar: Reporting → Reports
Scorecards grade applications, teams or products on a simple A-F scale so non-experts can see who's healthy and who needs help - and so owners have a metric to improve.
What's graded
- Posture - the deterministic 0-100 score mapped to a letter (A ≥ 90, B ≥ 80, C ≥ 70 …).
- SLA compliance - are findings fixed within their SLA windows?
- Coverage - is the asset actually being scanned across disciplines?
- Trend - improving or regressing.
Why it matters
- Accountability - every app/team has an owner and a grade; gamifies fixing.
- Leadership view - one screen shows the whole portfolio's health.
- Comparisons - rank teams, spot the outliers, target enablement.
Scorecards are deterministic (same inputs → same grade), so they're defensible in a review. They draw on the Posture engine, SLA Policy and the unified findings - see also the Exposure report for the financial cut.