Skip to content

Track Vulnerabilities and Remediation SLAs

A pentest report is a snapshot. The findings in it are not. Faction keeps tracking every finding after the report is delivered, through remediation, retest and closure, so vulnerability management is part of the assessment workflow rather than a separate tool fed by copy and paste.

Every finding is tracked, not just reported

Each vulnerability gets a unique tracking ID when it is created and keeps it in every assessment it appears in. When a retest is scheduled, the original findings are carried forward under the same ID, so an issue that was open in Q1 and still open in Q3 is one issue with a history, not two rows that happen to have the same name. A finding that was fixed and has come back is recorded as a regression with a fresh clock.

Remediation with owners, dates and SLA clocks

Findings have a remediation owner, a planned remediation date and a status that moves through the stages your organization defines, such as fixed in development, fixed in staging and closed. SLAs are set per severity, and the clock starts when the finding is opened. As the deadline approaches, the owner is warned; when it passes, reminders escalate on a schedule you configure. Every date, including when it was opened, closed in each environment and closed for good, is available in the report.

Exceptions, recorded and time-limited

Not everything gets fixed. When a finding is accepted as risk, Faction records the exception: its number, who approved it, its state, a justification, supporting files and an expiry date. An accepted risk stays visible and comes back up for review when the exception lapses, instead of quietly disappearing.

Retests that close the loop

A retest is scheduled against an assessment's findings. Each one is re-verified, closed or left open with notes, and the retest report is generated from the same template with open and closed counts. Comments and an activity log on each finding keep the conversation with the fixing team in one place.

Dashboards and exports

Managers see open risk by application, organization and severity, and how much of it is past its SLA. Remediation owners see what is theirs. Findings can be exported to CSV and to a machine-readable format for feeding other systems, and a REST API exposes all of it.

A foundation for application security posture management

Because every finding carries its application, its asset location, its severity, its owner, its SLA state and its full remediation history, Faction is a system of record for application security posture, not only a report generator. Application inventory can be pulled from external systems through extensions, and findings pushed out to ticketing through the same App Store SDK.

Try it

Remediation tracking, SLAs, retests and exceptions are all part of the open source edition. Run Faction and configure SLAs under Assessment Config.