Skip to content

Governance

The Governance section covers security findings, reporting, compliance, and automated workflows. Use it to review issues, track remediation, and prepare audit evidence.

Key Topics

  1. Results, Issues & Triage: Start here to understand how to interpret security findings, manage issues, and triage vulnerabilities from all Escape products (ASM, Business Logic Aware DAST, and AI Pentesting). See Results, Issues & Triage for guidance.

  2. Issue Management: Learn how to identify, prioritize, and remediate security issues or sensitive data leaks detected by Escape's security testing products. Use bulk editing, ignoring, and analytics to triage findings and track recurring issues.

  3. Security Score: Understand issue severity, CVSS data, risk tags, and the Security Score of scans and profiles.

  4. Reporting: Generate detailed insights into your security posture. Escape's reporting capabilities allow you to track historical scan data, trend analyses, and share these findings with internal teams or external stakeholders.

  5. Compliance: Review how Escape maps findings to frameworks such as PCI-DSS, OWASP Top 10, NIST, and SOC-2. Export reports to support your audits.

  6. Integrations: Configure connections to external systems like Jira before using them in workflows. Set up authentication and connection settings for each integration.

  7. Workflows & Notifications: Automate the creation of tickets, webhook calls, or Slack messages whenever new vulnerabilities are found. Escape's workflows let you define custom triggers (WHEN), conditions (IF), and actions (THEN) to ensure swift and effective responses to emerging threats.

Who Should Use This Section?

  • Security Engineers & AppSec Teams looking to streamline vulnerability remediation and ensure consistent adherence to security standards.
  • DevOps & Platform Teams wanting to embed security checks and notifications into continuous delivery pipelines.
  • Compliance Officers & Auditors aiming to understand how Escape supports and simplifies regulatory mandates.
  • Team Leads & Project Managers needing a clear view of security risks, open remediation tasks, and reporting for stakeholder communication.

Next Steps

  • Results, Issues & Triage: Understand how to interpret and manage security findings from all products
  • Issue Management: Learn about risk-based prioritization, ignoring mechanisms, bulk editing, and more.
  • Compliance & Reporting: Generate automated compliance reports and gain insight into your overall security posture.
  • Integrations: Set up integrations (for example, Jira) before using them in workflows.
  • Workflows & Ticketing: Configure workflows to trigger actions (for example, Slack messages, Jira tickets) whenever a new issue is discovered.

Use these pages to turn findings into remediation tasks and reports for your team.