ÿÿ Security Reporting & Analytics, Jira Sync | Keygraph Skip to main content
Pentest Reporting

Reporting & Analytics

Findings deduped across every scanner that feeds the pentest. Live dashboards. Bidirectional Jira sync. One source of truth, not six tabs.

Triage once, track once, remediate once. Keygraph merges what SAST, SCA, and Secrets flag with what the pentest proves into a single canonical entry per vulnerability, per repository. Each entry lives on a live security dashboard and syncs bidirectionally with Jira.

01 · Visibility

What we surface.

Live KPIs for current exposure. Trend charts for whether the team is getting ahead of risk or falling behind.

Live KPIs
Open findings by severity SLA breach count Mean time to remediation Findings by source · SAST / SCA / Secrets / Pentest
Trend charts
Risk

Open findings over time by severity: is overall risk posture improving?

Velocity

New findings discovered per day vs. findings resolved per day.

SLA compliance

Percentage of open findings meeting remediation deadline over time.

MTTR

Whether the team is getting faster or slower at remediation.

Each trend chart includes drill-down by repo, team, severity, status, source, and assignee, backed by daily snapshots that keep history accurate for compliance and audit. That history logs each vulnerability as it is found and validated, tracks responses over time, and gives you audit-ready evidence for pentest and vulnerability-scanning requirements.

02 · Deduplication

One finding per vulnerability.

When SAST, SCA, and Secrets flag a weakness and the pentest proves it with a working exploit, they merge into a single canonical entry per repo, so the team triages one proven finding instead of duplicates fighting for attention.

How dedup works
Stage 01
Content hash, milliseconds, no LLM.

Each finding gets a stable content fingerprint built from rule, file path, function signature, code scope, and organization context. Whitespace normalization ignores formatting changes, so refactors don't break dedup.

Stage 02
LLM semantic fallback, cross-scanner.

On a hash miss, candidates pass through an LLM semantic comparison gated by a confidence threshold. The same logic links matches across scanners: a SAST finding and a pentest exploit describing the same root cause become one canonical entry, with the source scanners recorded so you can see who flagged it.

What you get
Human-readable IDs

Every canonical finding gets a unique ID (e.g., KG-000042) for reference across tools and teams.

Persistent triage

Assignment, risk acceptance, and resolution status survive refactors. The hash rolls forward when non-flagged code changes.

Auto-reopen

If a resolved finding reappears in a subsequent scan, it automatically reopens.

Risk acceptance with expiry

Accept a known risk with an explicit expiration date. The finding auto-reopens when the acceptance lapses, so accepted risk stays tracked and time-bound instead of becoming a silent exception.

Immutable audit trail

Every status transition is appended to finding_status_history with timestamp and author.

Jira
03 · Workflow

Jira sync.

Bidirectional sync between canonical findings and Jira issues: one click to create, automatic to update, resilient when tickets get deleted. Remediation status stays consistent between the security system of record and the engineering backlog.

Outbound
Finding → Jira

One-click ticket creation from any canonical finding. The ticket carries title, severity, rule, and description, and Keygraph stores the ticket key, ID, and URL on the finding for round-trip sync.

Inbound
Jira → Finding

A sync worker polls every 15 minutes, refreshing status and assignee on linked findings. Broken links (deleted tickets) are detected and flagged in the integration health view.

Bidirectional
Resolution + reopen push

When a finding resolves in Keygraph, the linked Jira ticket transitions automatically, and reopens too if the finding resurfaces. An hourly sweep catches out-of-sync pairs.

One source of truth for every finding.

Schedule a demo and see canonical findings, risk trend dashboards, and bidirectional Jira sync running against your stack.

ÿÿÿÿ