How to read your Zoltra report without a security background
The dashboard is designed so the first thing you see is the one thing that matters. This page explains the rest: the labels, the numbers, the evidence, and the honest edges of what a report can tell you.
September 2026 · Zoltra
If you shipped a real app with AI help and no security team, the report is for you. It should read like a colleague who looked at your site and is telling you what they found, in order. Here is how to get through it in five minutes.
Start with the sentence at the top
The briefing header is one plain sentence about your current posture. If it says nothing needs you, that is the real answer — no critical or high findings are open. If it points at one finding, that is the one to open first. You do not have to read the whole report in order. The order is built for you.
Severity and confidence are different things
Every finding carries two labels that people mix up:
Severity is how bad it is if the thing is real and exploited. Critical and high mean it needs you soon. Medium and low mean you should fix it, but it is not the difference between a bad day and a bad quarter.
Confidence is how sure the check is about what it observed. A high severity with low confidence is a "this looks wrong, verify it" situation. A low severity with high confidence is just a fact about your app. When the two disagree, read the evidence before deciding how to feel.
What we observed means literally what it says
Every finding has a "What we observed" section with the actual data behind it: the header that was missing, the URL that redirected, the response that came back. This is evidence, not interpretation. You can reproduce most of it with a curl command in the same panel.
If the evidence looks empty or generic, that is a signal too — it means the check saw less than it wanted to. We would rather show you a thin finding than pad it with confident-sounding text. Nothing in the report is generated to sound scary.
The categories are questions, not grades
Alongside security, the report scores a handful of other things about your public surface: search visibility, AI search readiness, speed, accessibility, availability. Those are not security findings and we do not treat them the same way. They are answers to questions like "can search engines understand your important pages?" or "does the first visit feel slow?"
When a category says "Not scored yet", that is honest — some checks only run on deeper scans. It does not mean zero. It means we have not measured it yet.
What to fix first
The report gives you up to three next actions, ranked. The ranking is simple: open critical and high findings first, oldest first. Then failed or incomplete scans, then domain authorization problems.
A useful rule of thumb from the guides we have written: a finding that leaks data or lets someone act as your server beats a finding that is about hygiene. Missing database protections and open routes first. Injection and SSRF next. Then the smaller doors.
Fixes, pull requests, and what "verified" means
For a confirmed code-level vulnerability, Zoltra can prepare the repair on a separate branch and open a pull request in your connected GitHub repository. It never merges or deploys anything; you review the change like any other diff.
And "verified" has a specific meaning in this product: only a fresh check that passes marks a finding resolved. A fix that was written but not confirmed live stays open, with its history intact. That is deliberate. Security tools that mark things fixed because a ticket moved have done real damage to the word.
What your report honestly cannot see
This part matters as much as the findings. Without configuration, a scan sees what an unauthenticated visitor sees. It cannot see behind your login, inside your business logic, or into code paths that never touch the public internet. If your app has a members area, most of what is inside it is unmeasured by today's report unless you have set up the deeper lanes.
It also cannot prove absence. "No critical findings" means exactly that: none were observed. It is not a certificate, and we will not let the product imply otherwise.
How often to actually look
You do not need to sit in the dashboard. That is the point of the weekly summary and the alerts: if something urgent appears, you hear about it where you already work — Slack, Discord, or email. Open the dashboard when a message brings you there, or once a week over coffee. The report is designed to be readable after a week away, not only in the minute it was generated.
And if you never connect a channel, connect one. A finding that lives only on a page you have not opened yet is a finding you paid for and did not receive.
The how-to-fix side of the report lives in the guides: security headers, RLS, open API routes, email authentication, SSRF, injection, and redirects.