Skip to content

Compliance reports

Reports in the portal answers the two questions an auditor asks about patching: how quickly do you install security fixes, and is anything outside the targets you set yourself. It is on the Business and Enterprise plans.

For a period you choose (30 days to 12 months), every exposure that ended in it, grouped by the advisory’s severity: how many, the median, the 90th percentile and the mean time to fix, and how many were fixed within your target. The same numbers per host group follow.

An exposure is one host, one package and one advisory. It ends when the host no longer has a vulnerable version — the fix was installed or the package was removed. Upgrading to a version that is still vulnerable does not end it and does not restart its clock.

Latency is measured from when a fix was available to the host, not from when the advisory was published: time spent waiting for your distribution to ship a fix is not your latency. An exposure that ended before Updawg ever saw a fix on offer — the fix was installed between two inventories — is measured from when the exposure was first seen.

Latency is recorded from the day reports were switched on for your organization; fixes installed before then have no record.

Days to install a fix once it is available, per severity. The defaults are 7 for critical, 30 for high, 90 for medium and 180 for low; set them to what your security policy says (1 to 365 days) under Reports → Patch targets. Changing them is audited. Advisories rated none, or not rated, have no target.

As of when the report is generated:

  • Within targets — hosts with no fixable exposure that has been on offer for longer than its severity’s target.
  • Overdue fixes — those exposures, longest overdue first.
  • Stale — hosts that have stopped checking in.
  • End of life — hosts whose release is out of every support tier, and how many are past standard support.
  • Reboot required.

The summary is the sum of the per-host rows in the hosts export, so the two always agree. Groups are as they are now: a host that moved group last month reports under its current group.

  • Hosts CSV — one row per host: status, release, end-of-life flags, open fixable exposures per severity, overdue count and whether it is within targets.
  • Fixes CSV — one row per ended exposure in the period, with when it was first seen, when a fix was available, when it ended, the latency and whether it was within target.
  • Print or save as PDF — the report page prints without the portal’s navigation; use your browser’s Save as PDF.

Both CSVs come from GET /v1/orgs/{org}/compliance/export?dataset=hosts|resolutions and the report from GET /v1/orgs/{org}/compliance/report, so the same evidence can be collected on a schedule with an API token.