Use this when VaultPilot Discovery reports a secret exposure signal, import is disabled, or an operator is unsure if a finding should become a vault record.
Symptom
- Discovery shows a password, API key, certificate/key, credential, note, or file candidate.
- The finding looks real, but the evidence is masked.
- Import does not show the finding.
- Import is available, but the operator needs a safe decision path.
First checks
| Check | Expected result |
|---|---|
| Scope approval | The scan policy shows an approved private network, Windows folder preset, local path, or SMB path. |
| File approval | File scans show explicit read-only approval. |
| Finding status | Only findings marked ready for import appear in the import step. |
| Evidence quality | Strong signals show detector id, candidate type, masked path, path hash, and redacted evidence. |
| Vault state | Import requires an unlocked vault because the browser encrypts the imported value. |
| Ownership | The source owner confirms the value should be moved into VaultPilot instead of remaining only in the source file. |
Safe resolution path
- Open the finding drawer.
- Confirm the detector id, candidate type, severity, confidence, masked path, path hash, and evidence hash.
- If it is noise, use Ignore or Suppress with a reason.
- If it is real but should not be vaulted, record the operational decision in your change record.
- If it should become a vault item, mark it ready for import.
- Unlock the target vault.
- Use the import step to create the encrypted vault record.
- Review audit events for scan, review, import preparation, and import completion.
Safe evidence to send
- VaultPilot version and component version.
- Scan name and timestamp.
- Detector id, severity, confidence, candidate type, review status, path hash, and evidence hash.
- Redacted evidence shown by the drawer.
- Whether the vault was locked or unlocked during import.
Do not send
- Source files that triggered the finding.
- Unmasked paths with customer or infrastructure names.
- Plaintext secret values, tokens, private keys, connection strings, or vault exports.
- Database files, backups, PFX/P12 packages, or raw logs with secret values.
Escalate when
- Import fails after the finding is ready and the vault is unlocked.
- The finding repeats after a justified suppression.
- The scanner reports a system path or VaultPilot data path that should have been rejected.
- The audit trail does not show the review or import action.
Related
Still stuck?
Check the troubleshooting guide, then write to support@vaultpilot.io with the version, the steps you took and the exact redacted error. Never attach passwords, vault exports or private keys.