Featured guide
Create and assess a risk
Learn how to complete CIA and FAIR assessments, add controls, assign treatment actions and manage risk exceptions.
Read the guideConfigure the supported provider centrally through Admin → Integrations, review imported scanner findings, inspect evidence and connect selected technical vulnerabilities to Risk Management.
PurpleWASP keeps scanner observations separate from business Risks. The integration imports Assets and technical findings into Asset Management. Risk Management references selected findings as technical evidence instead of turning every finding into a separate Risk.
Provider credentials, jobs and scheduling are owned by the shared Integration Management service. The web request only queues the work; the background worker performs the provider API call. Asset Management owns the resulting vulnerability-domain records, matching and technical-exposure lifecycle.
Open an Asset and select Vulnerabilities. PurpleWASP groups related observations by the provider/source vulnerability identity so one QID or plugin does not appear as dozens of unrelated Risk items simply because it was observed on several ports.
Use status, severity, search and Risk-link filters to focus the list. Summary cards show active findings, Critical/High exposure, vulnerability groups and groups already linked to Risks.
Select Details on a vulnerability group or finding. The detail view combines the provider vulnerability definition with the observation on this Asset where the data is available.
Scanner output is rendered as evidence text rather than executable HTML.
The link does not alter or delete the underlying Asset finding. It creates traceability from the Risk back to the observed evidence.
Resolved findings remain evidence. If the provider later reports the same issue as reopened, PurpleWASP can show the current technical state while completed Risk assessments retain their historical snapshots. Resolving every linked finding does not automatically close the business Risk.
Confirm the integration is active, a successful run has completed, the imported integration Asset is mapped to the PurpleWASP Asset and the provider returned detections for that host.
This can be valid. Configuration, information-disclosure and product-specific findings do not always have a CVE. Use the provider definition and observation evidence rather than treating the absence of a CVE as an invalid finding.
Archived, closed or pending-exception Risks may not be linkable. A completed but still-active Risk can accept evidence for the next reassessment.