Reporting by Web Forms
Overview
Fortworx is built around a few principles:
- Make it very easy to report a security vulnerability.
- Use AI to help triage and respond to security communications.
- Keep track of everything so you can comply with security and cyber insurance requirements.
The first step to make reporting easy is to allow vulnerability disclosure by email. To use Fortworx, all you need is to forward your security email to your workspace.
However, sometimes you might want to allow reports to be submitted via a web form as well. The most common reason for this might be to allow anonymous reports to be submitted. Using web forms also lets you enforce some structure on the submissions.
Enabling Web Forms
To enable the web form for your workspace, follow these steps:
- Go to the Settings page in your workspace.
- Enable the Report via Web option.
- Configure the form fields you’d like to include (see below).
- Click the Save button.
You can now visit the web form by clicking on the View Form button.
Form Customization
You can customize which fields are available on the web form from your workspace settings. The following options can be individually enabled or disabled:
- AI Analysis — Enable Fort AI analysis for web form submissions.
- Severity Selection — Allow reporters to select a severity level.
- Scope Selection — Allow reporters to select the affected scope.
- Attachments — Allow reporters to upload file attachments.
- Vulnerability Type — Allow reporters to select a vulnerability type.
- CVE Selection — Allow reporters to link a known CVE.
Receiving Web Form Reports
All reports submitted by web forms are shown on your dashboard, exactly the same way an email report is shown. When AI analysis is enabled for web forms, submissions are analyzed by Fort AI just like email reports.
You can change the status of the report the same way you would for an email report.