
Finding types
| Category | Finding | Why it matters |
|---|---|---|
| Shadow data | Data store holding personal data outside your known inventory | Data nobody governs is data nobody protects — and it is missing from your RoPA |
| Exposure | Publicly accessible bucket or dataset containing personal data | Direct breach risk and a likely notification obligation |
| Over-broad access | Sensitive dataset readable by an overly broad group | Violates least-privilege and widens the blast radius of any account compromise |
| Missing protection | Unencrypted store holding special category or sensitive data | Elevated regulatory exposure under GDPR and India DPDP security requirements |
| Hygiene | Data past its retention period, stale copies of production data | Retention violations and unnecessary attack surface |
Severity levels
Each finding carries a severity computed from data sensitivity, degree of exposure, and volume:- Critical — special category or high-sensitivity data that is publicly exposed or unprotected
- High — sensitive data with over-broad access or missing encryption
- Medium — policy violations on lower-sensitivity data, or protected data past retention
- Low — hygiene issues with minimal exposure
Remediation workflow
Triage
Review new findings in the DSPM → Findings queue. Filter by severity, store, data category, or owner. Dismiss false positives with a documented reason — dismissals are audit-logged.
Assign
Route each finding to the responsible team or individual. Findings can also be pushed into your ticketing system via integrations, keeping engineers in their own tools.
Remediate
The finding record describes the issue, the affected data, and recommended remediation — lock down the bucket policy, narrow the access group, enable encryption, delete expired data.
Resolution tracking
- Status lifecycle — every finding moves through Open → Assigned → In progress → Resolved (pending verification) → Closed, with timestamps at each transition.
- SLA tracking — set target resolution times per severity; overdue findings are highlighted and escalated.
- Audit trail — assignments, comments, dismissals, and closures are recorded, so you can demonstrate a working remediation process to auditors and regulators.
- Trends — dashboards show open findings by severity over time, mean time to remediate, and recurring finding types per team.
Findings on data stores holding special category data automatically raise the linked processing activity’s risk profile, which can trigger a DPIA review.