Reviewing Discovery findings

Use this when VaultPilot Discovery reports a secret exposure signal, import is disabled, or an operator is unsure if a finding should become a vault record.

Symptom

  • Discovery shows a password, API key, certificate/key, credential, note, or file candidate.
  • The finding looks real, but the evidence is masked.
  • Import does not show the finding.
  • Import is available, but the operator needs a safe decision path.

First checks

CheckExpected result
Scope approvalThe scan policy shows an approved private network, Windows folder preset, local path, or SMB path.
File approvalFile scans show explicit read-only approval.
Finding statusOnly findings marked ready for import appear in the import step.
Evidence qualityStrong signals show detector id, candidate type, masked path, path hash, and redacted evidence.
Vault stateImport requires an unlocked vault because the browser encrypts the imported value.
OwnershipThe source owner confirms the value should be moved into VaultPilot instead of remaining only in the source file.

Safe resolution path

  1. Open the finding drawer.
  2. Confirm the detector id, candidate type, severity, confidence, masked path, path hash, and evidence hash.
  3. If it is noise, use Ignore or Suppress with a reason.
  4. If it is real but should not be vaulted, record the operational decision in your change record.
  5. If it should become a vault item, mark it ready for import.
  6. Unlock the target vault.
  7. Use the import step to create the encrypted vault record.
  8. Review audit events for scan, review, import preparation, and import completion.

Safe evidence to send

  • VaultPilot version and component version.
  • Scan name and timestamp.
  • Detector id, severity, confidence, candidate type, review status, path hash, and evidence hash.
  • Redacted evidence shown by the drawer.
  • Whether the vault was locked or unlocked during import.

Do not send

  • Source files that triggered the finding.
  • Unmasked paths with customer or infrastructure names.
  • Plaintext secret values, tokens, private keys, connection strings, or vault exports.
  • Database files, backups, PFX/P12 packages, or raw logs with secret values.

Escalate when

  • Import fails after the finding is ready and the vault is unlocked.
  • The finding repeats after a justified suppression.
  • The scanner reports a system path or VaultPilot data path that should have been rejected.
  • The audit trail does not show the review or import action.

Still stuck?

Check the troubleshooting guide, then write to support@vaultpilot.io with the version, the steps you took and the exact redacted error. Never attach passwords, vault exports or private keys.

Open the troubleshooting guide

Back to Knowledge base