Barrion Docs
Passive Scanning

Managing Findings

How to manage, ignore, and track scan findings.

After running a scan, you will likely have a mix of findings that require action, are already known, or represent accepted risks. Barrion provides tools to manage findings so your reports stay relevant and actionable.

Ignoring Vulnerabilities

Not every finding requires remediation. Some may represent an accepted risk based on your organization's threat model. Barrion allows you to ignore specific findings so they no longer affect your security score or clutter your reports.

When you ignore a finding:

  • It is marked as an accepted risk in the system.
  • It will not count against your security score in future scans.
  • It remains visible in your scan history for audit purposes, clearly labeled as ignored.

Ignoring a finding does not make the underlying vulnerability go away. Only ignore findings when you have made a deliberate risk acceptance decision and understand the potential impact.

When to Ignore a Finding

Common scenarios for ignoring findings:

  • Intentional configuration -- For example, a permissive CORS policy on a public API that is designed to accept cross-origin requests.
  • False positives -- Rare cases where Barrion flags a configuration that is actually correct for your use case.
  • Third-party dependencies -- Issues caused by external services you do not control (e.g., headers set by a CDN or hosting provider that you cannot override).
  • Compensating controls -- The vulnerability is mitigated by other measures not visible to the scanner.

Re-Scanning to Verify Fixes

After applying fixes for reported vulnerabilities, run a new scan to confirm the issues are resolved:

  1. Navigate to the domain in your dashboard.
  2. Click Scan to initiate a fresh scan.
  3. Compare the new results against the previous scan to verify that the targeted findings now pass.

Barrion tracks score history across scans, so you will see a trend indicator showing whether your score improved after remediation.

Scan History

Every scan result is stored and accessible from your dashboard. Scan history allows you to:

  • Review past results -- Go back to any previous scan to see what was reported at that point in time.
  • Compare results over time -- Track which findings were introduced, resolved, or remain open across multiple scans.
  • Identify regressions -- Spot checks that previously passed but are now failing, which may indicate a configuration change or deployment issue.

Scan history is available on all registered account tiers. Guest scans are accessible via their unique URL but are not stored in an account-level history.

Rescan Limits by Plan

Each plan tier has a daily scan limit that determines how frequently you can re-scan:

PlanScans per Day
Guest2
Free5
Essential50
Business500

Plan your re-scans strategically -- batch multiple fixes together before re-scanning rather than scanning after each individual change, especially on lower tiers.