Skip to main content
Perfai Insights — portfolio-wide security dashboard

What is Insights?

Insights is your organization’s security command center. While the Apps page shows you individual app status, Insights aggregates everything across your entire portfolio into a single dashboard — so you can answer high-level questions instantly:
  • How much of our attack surface is actually covered?
  • How many active vulnerabilities do we have right now?
  • How fast are we fixing issues?
  • What’s our total financial risk exposure?

Top-level metrics

The four headline numbers at the top tell the story of your security program at a glance:

241 Apps

Total secure and third-party apps under active testing. Every app Perfai monitors contributes to this count.

10,412 Endpoints

Total API endpoints mapped by the Vision Agent across all apps. This is your real attack surface — not an estimate.

520,600 Unique Tests

Total security test scenarios executed. Each test probes a specific permission boundary across a workflow, endpoint, and role combination.

$23.1M Bug Bounty Savings

Estimated value of vulnerabilities found internally before external researchers or attackers discovered them. This is the ROI number to show your CFO.

Active vulnerabilities

The Active Vulnerabilities donut breaks down your current open findings by severity:
A high critical count isn’t a sign of failure — it means Perfai found real vulnerabilities before attackers did. The right response is triage and fix, not alarm. Use the Issues page to start working through critical findings.

Security coverage

The Security Coverage donut shows how much of your mapped attack surface has actually been tested:
The goal is 100% covered. The Partial and Uncovered categories tell you exactly where your blind spots are. Check these in the individual app dashboards to understand why — usually it’s a missing role credential or a workflow the Vision Agent hasn’t fully mapped yet.

Fixed issues

The Fixed Issues donut tracks how many vulnerabilities your team has remediated and had re-verified by Perfai: An issue moves to “fixed” only after Perfai re-scans the endpoint and confirms the access control bypass no longer works. This is verified remediation — not self-reported.

Bottom-row metrics

Sensitive Data — 2,001

Total sensitive data types discovered across all apps — PII fields, financial data, internal IDs, and cross-user references. These are the data objects your access control model is supposed to protect.

Risk Exposure Trend — 991

Tracks how your total risk exposure changes over time. A rising trend means new issues are being introduced faster than they’re fixed. A falling trend means your program is working.

Mean Time to Remediate — 4 days

How long it takes your team to fix a confirmed issue from discovery to verified resolution. 4 days is strong performance — industry average is weeks. Use this to benchmark your security engineering velocity.

Releases — 30

Number of application releases tracked. Correlate this with your risk exposure trend to see whether new releases are introducing security regressions.

Who should use Insights


How to act on what you see

1

Check coverage first

If coverage is below 90%, go to each app and confirm all roles are configured with valid credentials. Uncovered endpoints often mean a missing role.
2

Triage critical issues

Click through to the Issues page filtered by Critical severity. Sort by CVSS score and start with the highest. Each finding has a reproduction step — confirm it’s real before assigning a fix.
3

Track MTTR over time

If MTTR is rising, your fix pipeline has a bottleneck. Correlate with releases — if a specific deploy caused a spike, that release introduced regressions.
4

Show stakeholders the savings number

The bug bounty savings figure is the single most effective way to communicate the value of your security program to non-technical leadership. It converts risk into dollars.