FAQ

Answers for infrastructure teams

The separate Security Center scanner is not enabled in the current production Monitor. Existing checks are limited to registered monitoring assets; do not use them as an arbitrary external scanning tool.

No. It is one piece of evidence. Security coverage depends on the scan mode, registered asset, agent capability, provider freshness, and checks that actually completed.

Yes, when your role and workspace permissions allow the scoped report download. Reports include coverage and limitation details.

The platform shows freshness and cached/grace state according to its configured contract. It does not silently claim current coverage or invent an all-clear result.

No. Customer data endpoints re-check authentication, role, active workspace, membership, entitlement, and asset ownership server-side.

Check the last agent report, the time range, and which resource and service checks actually completed. A stale or missing signal is not proof of health.

Each registered asset is associated with an authorized workspace. The application checks role, membership and ownership again when data is requested.

The deployed Monitor includes certificate inventory and expiry context for registered HTTPS assets. Review the last completed check before planning a renewal.

Review the original target, redirect path and final HTTP/TLS result. A redirect alone does not establish that the intended application is available.

Notification preferences and deduplication can suppress repeat delivery while the underlying event remains visible. Inspect the event history and channel configuration.

No. A report covers a selected period and whatever data was collected then. Always check the current asset state and data freshness before acting.

No. Remote operations require the relevant role, workspace authorization and enabled capability. Access is not granted by merely knowing a server ID.

No. An authorized operator selects registered targets and a permitted operation. Per-target results and audit history should be reviewed afterward.

Authorized website administrators can edit each published plan, price, currency, features, action and visibility in the CMS. Commercial changes should be checked against the active E4S licensing catalog before publication.

Use a unique password and enable TOTP in account security. Store the one-time recovery codes offline and never include them in a ticket or email.

No data and a failed check are different states. The portal reports unavailable Monitor data honestly instead of generating simulated telemetry.

Signed-in clients can open a ticket, follow the conversation, and view only their own ticket history. Staff-only notes remain private.