Operational Dashboard
Real-time QA, security and compliance posture.
correlation: SEC-991-ABX · last scan: 2026-05-07
Security Score
92
OWASP API · BOLA · IDOR
Compliance Score
88
LGPD · SOC2 · ISO 27001
API Health
HEALTHY
across monitored endpoints
Threat Level
HIGH
composite risk classification
Incidents
4
open · last 24h
SLA
99.94%
rolling 7-day availability
Avg Response
218ms
p95 across endpoints
Last Validation
2026-05-07
Newman · Postman pipeline
Incident Timeline
last 7 daysCompliance Evolution
6 monthsAPI Performance
p50 / p95 (ms)SLA Analytics
weekly availabilityValidation History
14 daysIncident Center
4 openCRITICAL
/payment/processBroken Authorization
Endpoint accepted forged JWT with admin scope (BOLA/IDOR class).
Recommendation
Apply RBAC validation middleware
SEC-991-ABX2026-05-07 14:22 UTC
HIGH
/users/{id}Sensitive Data Exposure
Response leaked CPF and phone for cross-tenant user IDs.
Recommendation
Mask PII fields in response projection
SEC-984-LMN2026-05-07 11:08 UTC
MEDIUM
/auth/loginMissing Security Headers
HSTS, X-Frame-Options and CSP missing on login route.
Recommendation
Add Strict-Transport-Security and X-Content-Type-Options
SEC-977-QRP2026-05-06 19:45 UTC
LOW
/healthzSLA Drift
p95 latency drifted 8% above baseline for 12 minutes.
Recommendation
Investigate upstream cache warm-up window
SEC-971-TWX2026-05-06 08:12 UTC