Discovery tells you where sensitive data is; risk findings tell you where it is not protected the way it should be. TruePrivacy continuously evaluates each store’s configuration, access, and contents against policy and turns gaps into prioritized, trackable findings.
Risk findings queue with severity levels and assignment

Finding types

CategoryFindingWhy it matters
Shadow dataData store holding personal data outside your known inventoryData nobody governs is data nobody protects — and it is missing from your RoPA
ExposurePublicly accessible bucket or dataset containing personal dataDirect breach risk and a likely notification obligation
Over-broad accessSensitive dataset readable by an overly broad groupViolates least-privilege and widens the blast radius of any account compromise
Missing protectionUnencrypted store holding special category or sensitive dataElevated regulatory exposure under GDPR and India DPDP security requirements
HygieneData past its retention period, stale copies of production dataRetention violations and unnecessary attack surface

Severity levels

Each finding carries a severity computed from data sensitivity, degree of exposure, and volume:
  • Critical — special category or high-sensitivity data that is publicly exposed or unprotected
  • High — sensitive data with over-broad access or missing encryption
  • Medium — policy violations on lower-sensitivity data, or protected data past retention
  • Low — hygiene issues with minimal exposure
A public bucket with ten million health records is not the same as an internal share with a stale email list — severity ensures your team works the riskiest items first.

Remediation workflow

1

Triage

Review new findings in the DSPM → Findings queue. Filter by severity, store, data category, or owner. Dismiss false positives with a documented reason — dismissals are audit-logged.
2

Assign

Route each finding to the responsible team or individual. Findings can also be pushed into your ticketing system via integrations, keeping engineers in their own tools.
3

Remediate

The finding record describes the issue, the affected data, and recommended remediation — lock down the bucket policy, narrow the access group, enable encryption, delete expired data.
4

Verify and close

On the next scan, TruePrivacy re-checks the store. Resolved findings are verified and closed automatically; if the issue persists, the finding stays open and the assignee is notified.

Resolution tracking

  • Status lifecycle — every finding moves through Open → Assigned → In progress → Resolved (pending verification) → Closed, with timestamps at each transition.
  • SLA tracking — set target resolution times per severity; overdue findings are highlighted and escalated.
  • Audit trail — assignments, comments, dismissals, and closures are recorded, so you can demonstrate a working remediation process to auditors and regulators.
  • Trends — dashboards show open findings by severity over time, mean time to remediate, and recurring finding types per team.
Recurring findings of the same type usually indicate a process gap, not a one-off mistake — for example, a provisioning template that creates unencrypted storage by default. Fix the template, not just the finding.
Findings on data stores holding special category data automatically raise the linked processing activity’s risk profile, which can trigger a DPIA review.