Skip to main content

Security Scorecards

Path: /reports/scorecards · Sidebar: Reporting → Reports

Scorecards grade applications, teams or products on a simple A-F scale so non-experts can see who's healthy and who needs help - and so owners have a metric to improve.

What's graded

  • Posture - the deterministic 0-100 score mapped to a letter (A ≥ 90, B ≥ 80, C ≥ 70 …).
  • SLA compliance - are findings fixed within their SLA windows?
  • Coverage - is the asset actually being scanned across disciplines?
  • Trend - improving or regressing.

Why it matters

  • Accountability - every app/team has an owner and a grade; gamifies fixing.
  • Leadership view - one screen shows the whole portfolio's health.
  • Comparisons - rank teams, spot the outliers, target enablement.

Scorecards are deterministic (same inputs → same grade), so they're defensible in a review. They draw on the Posture engine, SLA Policy and the unified findings - see also the Exposure report for the financial cut.