Whitespots.io
Pricing
Enterprise License
Scan Online
Platform
Whitespots Platform Your self-hosted AppSec HQ Explore platform →
Products
DevSecOps Platform Self-hosted AppSec platform. Unlimited developers. Online Scanning Scan a public target from the browser. No install. How It Works Scan, deduplicate, prioritise, assign — end to end. IDE Integrations Findings where the code is written.
Compare
GitLab Jit Aikido OX Security DefectDojo
Industries
By Industry
iGaming Fintech Insurance Telecom Healthcare Life Sciences Public Sector Defense Marketplaces Mobility Technology Capability Centers
All industries →
Clause map What the regulator asks, and what self-hosting answers Every industry page separates what the published text demands from what a self-hosted deployment actually does about it. Browse all twelve →
Resources
Learn
Documentation Deployment, configuration and API reference. Blog AppSec practice, and what we argue with. DevSecOps Challenges The problems this category keeps failing to solve.
Company
About Us Who builds this, and why self-hosted. Revenue Advisor Program Refer us, and take a share of what closes. Customer Feedback What the teams running it say. Contact Us Talk to an engineer, not an SDR.
Start here Scan a target before you talk to us Point the online scanner at a public host and read the findings yourself. No install, no call. Run a scan →
Pricing
Whitespots Wiki
  • AppSec Portal
    • 📥 Deployment
      • License obtaining
      • Installation
      • Get started with the AppSec Portal
        • Configuration options
      • Update
      • Accessing the AppSec Portal API Endpoints
      • Database transfer guide
      • FAQ: typical errors in deployment process
    • ⚙️ Post install Configuration
    • 🎯 Features
      • 🎣 Auto Validator
        • Rule creation
        • Rules view
      • Deduplicator
        • ⚙️ Basic deduplicator rules
        • ⚙️ Advance Deduplicator rules
      • 🔦 Vulnerability discovery
        • ✔️ Audits
        • ⚙️ Auditor settings
          • Auditor config
          • Sequences
            • Sequences creating
            • Sequences setting
        • 🔎 Run audit
          • Run Audit Manually
          • Scheduled Audit Run
      • 🎯 Recommendations
      • Security Metrics
        • Severity Statistics Dashboard
        • WRT (Weighted Risk Trend)
        • How to work with WRT (for team leads)
        • Metrics settings
          • SLA
        • CVSS
          • CVSS Rule
      • Custom Reports
      • 📈 Active tasks
      • 🧺 Asset management
        • How to import repositories from version control
        • Default product
        • Adding a product asset
        • Asset Transfer Between Products
      • 🕷️ Findings view
        • All findings view
        • Grouped findings as a result of
        • Grouping of findings into groups
        • Available bulk actions
        • Viewing specific findings
        • Usable filters and easy sorting
      • 📊 Jira
        • Jira integration configuration
        • Setting up Jira webhook
      • 👾 Move from DefectDojo
      • 🔬 Scanners
        • 🔌 Importing reports from scanners to AppSec Portal
          • 🖐️ Manual Import using Report File
          • Importing reports via Terminal using a Report File
          • Importing reports via Lambda Function using a Report File
        • Scanner description
          • Code Scanners
            • Bandit
            • Brakeman
            • Checkov
            • CodeQL
            • ESLint
            • Gemnasium
            • Gosec
            • Hadolint
            • KICS
            • PHPCodeSniffer
            • Retire.js
            • Semgrep
            • SpotBugs
            • Terrascan
          • Secret Scanners
            • Gitleaks
            • Trufflehog3
          • Image and code dependency Scanners
            • Trivy
            • Trivy vulners.com plugin
            • Snyk
          • Web Scanners
            • Arachni Scan
            • Acunetix
            • Burp Enterprise Scan
            • OWASP Zap
          • Infrastructure Scanners
            • AWS Security Hub Scan
              • Importing reports via AWS Lambda Function within AWS Security Hub
            • Prowler
            • Subfinder
            • Nessus
            • Nuclei
          • Mobile Security Scanners
            • MobSFScan
          • Other Scanners
            • Dependency-Track
            • Whitespots Portal
      • 📦 Working with products
        • Product Creation
        • Product options
        • Finding groups
        • Risk assessment
        • Product Asset
      • Quality Gate
      • Bring your own scanner
    • 🛠️ General Portal settings
      • Version Control Integration
      • Profile
      • Managing user roles and access control
        • User management
        • Creating and editing roles
      • SSO settings
        • GitLab SSO
        • Microsoft SSO
        • Okta SSO
      • Scanner settings
        • Auto Closer
        • Group findings by
        • Custom Jira description
        • Custom severity mapping
        • Auditor Job Config
      • Notification settings
        • Integration
        • Criteria & Schedule
        • Status change notification
        • Manage notification schedule
      • Repository Link Configs
      • CWE list
      • Tag screen
    • 🗒️ Release notes
  • Auditor
    • 📦 Deployment
    • 🎯 Features
      • 🚀 Run Audit
        • AppSec Portal cooperation
        • Direct use of Auditor
      • ⚙️ Settings
        • AppSec Portal cooperation
        • Direct use of the Auditor
          • Cleaner
          • Docker Credentials
          • Workers
          • Personalization
        • Jobs
          • Technical Jobs
          • Scanner Jobs
          • Job configuration
    • 🗒️ Release notes
    • 🩼 Maintenance
  • Documentation backlog
Home / Docs / Whitespots Wiki / AppSec Portal / 🎯 Features

Security Metrics

03.12.2025
  • Severity Statistics Dashboard
  • WRT (Weighted Risk Trend)
  • How to work with WRT (guide for team leads)
  • Metrics settings
  • CVSS
Previous
🎯 Recommendations
Next
Severity Statistics Dashboard

Products

  • DevSecOps Platform
  • Online Scanning
  • How It Works
  • IDE Integrations

Compare

  • GitLab
  • Jit
  • Aikido
  • OX Security
  • DefectDojo

Industries

  • iGaming
  • Fintech
  • Insurance
  • Telecom
  • Healthcare
  • Life Sciences
  • Public Sector
  • Defense
  • Marketplaces
  • Mobility
  • Technology
  • Capability Centers
  • All industries

Resources

  • Documentation
  • Blog
  • DevSecOps Challenges

Company

  • About Us
  • Revenue Advisor Program
  • Customer Feedback
  • Contact Us

Get security done inside your own perimeter.

Self-hosted only. Unlimited developers. Talk to an engineer, not an SDR.

Book a demo
Scan online
Whitespots.io

© 2026 Whitespots OÜ. Whitespots® is a registered trademark of Whitespots OÜ.

  • Privacy Policy
  • Cookie Policy
  • Cookie Settings
  • Terms of Use
LinkedIn GitHub YouTube Telegram Mastodon Bluesky