
What is Insights?
Insights is your organization’s security command center. While the Apps page shows you individual app status, Insights aggregates everything across your entire portfolio into a single dashboard — so you can answer high-level questions instantly:- How much of our attack surface is actually covered?
- How many active vulnerabilities do we have right now?
- How fast are we fixing issues?
- What’s our total financial risk exposure?
Top-level metrics
The four headline numbers at the top tell the story of your security program at a glance:241 Apps
Total secure and third-party apps under active testing. Every app Perfai monitors contributes to this count.
10,412 Endpoints
Total API endpoints mapped by the Vision Agent across all apps. This is your real attack surface — not an estimate.
520,600 Unique Tests
Total security test scenarios executed. Each test probes a specific permission boundary across a workflow, endpoint, and role combination.
$23.1M Bug Bounty Savings
Estimated value of vulnerabilities found internally before external researchers or attackers discovered them. This is the ROI number to show your CFO.
Active vulnerabilities
The Active Vulnerabilities donut breaks down your current open findings by severity:Security coverage
The Security Coverage donut shows how much of your mapped attack surface has actually been tested:Fixed issues
The Fixed Issues donut tracks how many vulnerabilities your team has remediated and had re-verified by Perfai:
An issue moves to “fixed” only after Perfai re-scans the endpoint and confirms the access control bypass no longer works. This is verified remediation — not self-reported.
Bottom-row metrics
Sensitive Data — 2,001
Total sensitive data types discovered across all apps — PII fields, financial data, internal IDs, and cross-user references. These are the data objects your access control model is supposed to protect.
Risk Exposure Trend — 991
Tracks how your total risk exposure changes over time. A rising trend means new issues are being introduced faster than they’re fixed. A falling trend means your program is working.
Mean Time to Remediate — 4 days
How long it takes your team to fix a confirmed issue from discovery to verified resolution. 4 days is strong performance — industry average is weeks. Use this to benchmark your security engineering velocity.
Releases — 30
Number of application releases tracked. Correlate this with your risk exposure trend to see whether new releases are introducing security regressions.
Who should use Insights
How to act on what you see
1
Check coverage first
If coverage is below 90%, go to each app and confirm all roles are configured with valid credentials. Uncovered endpoints often mean a missing role.
2
Triage critical issues
Click through to the Issues page filtered by Critical severity. Sort by CVSS score and start with the highest. Each finding has a reproduction step — confirm it’s real before assigning a fix.
3
Track MTTR over time
If MTTR is rising, your fix pipeline has a bottleneck. Correlate with releases — if a specific deploy caused a spike, that release introduced regressions.
4
Show stakeholders the savings number
The bug bounty savings figure is the single most effective way to communicate the value of your security program to non-technical leadership. It converts risk into dollars.

