# Glossary

Look up the terms and UI labels used in the Deepinfo Platform and in this guide, and what each one means.

Source: https://docs.deepinfo.com/guide/glossary/

Last updated: 2026-09-26

---
The platform shows many labels in capital letters. This guide quotes them in **bold**, exactly as they appear
on screen, so you can match them. Where the platform uses two names for one thing, the entry says so.

> [!IMPORTANT]
> The platform uses several scores and levels. They cannot be compared with each other:
> - **Security score** (External Attack Surface Management, EASM): a number with a letter grade, **A** from 800 down to **F** from 300.
> - **Risk Score** (Brand Risk Protection, BRP): 0 to 100, in bands from **INFORMATION** to **CRITICAL**.
> - **Risk level** (Cyber Threat Intelligence, CTI): labels from **CRITICAL** to **LOW**.
> - **AVG STRENGTH SCORE** (CTI): the strength of an employee's leaked passwords, out of 10.
> - **CVSS** (**SCORE/SEVERITY**): 0 to 10.
> - **EPSS** and **AVERAGE EXPLOITABILITY SCORE**: percentages.

## Account and Access

| Term | UI labels | Meaning |
|---|---|---|
| Organization | **ORGANIZATION SETTINGS** / **Organization Details** | Your company's account on the platform. Each user belongs to exactly one organization; there is no switching between organizations. |
| Admin, Member | **ADMIN** / **MEMBER** / **SET AS ADMIN** / **SET AS MEMBER** | The roles. Only admins see the organization's **Settings**, **Members** and **Security** pages. See [Manage members and invitations](/guide/settings/members/). |
| Package | **… IS NOT INCLUDED IN YOUR PACKAGE** / **TALK TO US** / "This feed is not included in your package" | What your organization has bought. A screen outside your package is covered by a notice whose **TALK TO US** button opens an e-mail to Deepinfo support. See [What you can access](/guide/basics/packages-and-roles/). |
| API key, default API key | **API Keys** / **Default API Key** / **Set as Default** / **TEAM MEMBER** | A key for calling the Deepinfo API at api.deepinfo.com (demo accounts use a different address; see [Environments & base URL](/getting-started/environments-and-base-url/)). Each key belongs to a member, shown under **TEAM MEMBER**. The default key is marked with a badge and cannot be deleted. The platform also uses it for its own calls to the API. See [Create and manage API keys](/guide/settings/api-keys/). |
| Quota | **QUOTA:** / **USED:** / **REMAINING:** | Your package's allowance for a group of API endpoints. On **API Usage**, the bar and the percentage show the share that remains. The period is not shown. See [Check API usage and quota](/guide/settings/api-usage/). |
| Two-factor authentication, recovery code | **Two Factor Authentication** / **Use a Recovery Code** / **DOWNLOAD CODE AND CLOSE** | A 6-digit code from an authenticator app, asked for at sign-in. Recovery codes let you sign in without the app. Each works once, and you can download them only when you set up two-factor authentication. See [Use two-factor authentication](/guide/basics/two-factor-authentication/). |

## Finding Your Way

| Term | UI labels | Meaning |
|---|---|---|
| Sidebar | Group headings **EXTERNAL ATTACK SURFACE MANAGEMENT** / **CYBER THREAT INTELLIGENCE** / **BRAND RISK PROTECTION** / **DEEP SEARCH & INSIGHTS**; **Collapse sidebar** / **Expand sidebar** | The menu on the left. The module items sit under the coloured module group headings, followed by **REPORTS**, **NOTIFICATION CENTER** and **SETTINGS**. Collapsed, the sidebar shows icons and the short group names **EASM**, **CTI**, **BRP** and **DSI**. See [Find your way around](/guide/basics/navigation/). |
| Breadcrumb | For example **EASM / ISSUES / ISSUE LIST** | The path at the top left of every page, from the module to the page you are on. |
| In-page tabs | **OVERVIEW**, then a list tab such as **ISSUE LIST**, then **INSIGHTS** or **SETTINGS** | Tabs under a page's title. **OVERVIEW** holds the key figures, the list tab holds the records, **INSIGHTS** holds charts and distributions, and **SETTINGS** holds the area's settings. |

## Lists and Records

| Term | UI labels | Meaning |
|---|---|---|
| Quick view, list view | Two icons: an eye and a list | The two layouts of a list: a split pane with the list on the left and the selected record on the right (quick view), or a table (list view). |
| Drawer | **OPEN IN NEW TAB** | A panel that opens on the right with a record's details. Its tabs are icons down its left side; hover over an icon to see its name. **OPEN IN NEW TAB** opens the record's full page. |
| Filter, filter rule | Filter chips; **SHOW ALL FILTERS** / **HIDE FILTERS**; **Must** / **Must Not** / **Should** | Filters sit above a list as chips. A chip opens a popover where you choose a field, a rule, an operator and a value. The rule includes (**Must**), excludes (**Must Not**) or prefers (**Should**) matching records. API search filters use the same model; see [Search & filters](/getting-started/search-and-filters/). |
| View options | **VIEW SETTINGS** / **View Options** / **Sort By** / **Result Per Page** / **Reset to Default View** / **SHOWN** | A list's display settings: the sort order, the number of rows per page and which columns are shown. |
| Export, export scope | **EXPORT** / **DOWNLOAD** / **RECORDS** (**ALL** / **FILTERED**) / **FILE FORMAT** (**CSV** / **JSON**) / **EXPORT SCOPE** (**DEFAULT** / **BASIC** / **EXTENDED**) | Download a list as a CSV or JSON file: every record, or only the records that match your filters. Some lists also let you choose an export scope. See [Search, filter and export lists](/guide/basics/lists-filters-and-exports/). |

## Assets

| Term | UI labels | Meaning |
|---|---|---|
| Asset | Tabs **DOMAINS** / **SUBDOMAINS** / **IP ADDRESSES** / **WEBSITES**; filter values **Domain** / **Subdomain** / **IP Address** / **Website** | Something you monitor: a domain, a subdomain, an IP address or a website. A website's name includes its port (`host:port`). See [Browse your asset inventory](/guide/easm/asset-inventory/). |
| Inventory ("portfolio") | **Inventory** / **Add to Portfolio** / "… in your portfolio" | Your monitored assets. Where the platform says "portfolio", it means the same thing. |
| Main asset | **MAIN ASSET** / **SET AS MAIN ASSET** / **REVERT TO NORMAL ASSET** | An asset you mark as main. The platform describes it as "the primary asset for all related assets, configurations, and reports." |
| Seems inactive | **SEEMS INACTIVE** / **THIS … IS CURRENTLY INACTIVE** | The platform's message says it found no active DNS records or WHOIS information for the asset; for a subdomain, no DNS records. |
| Parked, Redirected, Login page, IDN | **Parked** / **Redirected** / **Login Page** / **IDN:** | Icons next to an asset's name. The **Parked** and **Redirected** tooltips show the name the asset redirects to. **Login Page** means the asset has a login page. **IDN:** marks an internationalized name and shows its punycode form. Parked assets are shown muted in tables. |
| Asset weight | **ASSET WEIGHT** / **SYSTEM WEIGHT** / **NEW WEIGHT** / **SET ASSET WEIGHT** | How important an asset is to your organization. The system calculates a **SYSTEM WEIGHT**, which can be above 100. With **SET ASSET WEIGHT** you can set your own weight, from 1 to 100. The weight affects your organization's security score. |
| Security score, rating | **SECURITY RATING** / **SCORE** / **A** to **F** | The EASM security score and its letter grade: **A** from 800, **B** from 700, **C** from 600, **D** from 500, **E** from 400 and **F** from 300. Below 300, or without a score, the grade shows `-`. See [How security scores work](/guide/easm/security-score/). |
| Scan | **SCAN NOW** / **START PORT SCAN** / **LAST CHECK DATE** | An on-demand rescan of an asset (**SCAN NOW**) or of its ports (**START PORT SCAN**). **LAST CHECK DATE** shows when the asset was last checked. On an asset's page, **SCAN NOW** is unavailable for 5 minutes after a manual scan. |
| Historical records | **SHOW HISTORICAL … RECORDS** / **Compare Dates (Up to 3 Records)** | Earlier snapshots of an asset's WHOIS, DNS, SSL, website info and open ports. You can compare up to three dates side by side. |
| Expiry status | **ACTIVE** / **EXPIRES SOON** / **EXPIRED** / **INVALID CERTIFICATE** | The status of an SSL certificate or a domain registration: more than a month left, less than a month left, expired, or an invalid certificate. |
| Port state | **OPEN** / **OPEN FILTERED** / **CLOSED** / **CLOSED FILTERED** / **FILTERED** / **UNFILTERED** | The state of a scanned port. The **OPEN PORTS** tab shows open ports by default. |
| Creation method | **MANUALLY ADDED** / **MANUALLY APPROVED** / **AUTO APPROVED** | How an asset entered your inventory. |

## Discovery

| Term | UI labels | Meaning |
|---|---|---|
| Discovery, discovered asset | **DISCOVERED ASSETS** / **IN REVIEW** / **APPROVED** / **IGNORED** / **ADD TO MY ASSETS** / **IGNORE** / **UNDO IGNORE** | A discovered asset is a candidate that discovery rules found around your attack surface. It stays **IN REVIEW** until it is approved into your assets (with **ADD TO MY ASSETS**, or automatically by **Auto Approval**) or ignored. **UNDO IGNORE** reverses an ignore. See [Review discovered assets](/guide/easm/discovery/). |
| Smart and custom discovery rules | **SMART DISCOVERY RULES** / **SMART MONITORING RULES** / **Custom Rules** | Smart rules are managed by Deepinfo; you can switch them on or off and tune them. Custom rules are discovery rules you build from filters. All of them are on the **SETTINGS** tab of **DISCOVERY**. |
| Seed asset, seed value | **MANAGE EXCLUDED SEED ASSETS** / **MANAGE EXCLUDED SEED VALUES** | The assets and values a smart rule starts from. A rule skips the seeds you exclude. |
| Auto approval | **Auto Approval** / **AUTO APPROVAL** | On a discovery rule: assets in review that match the rule are approved automatically. On a BRP detection rule: suspicious domains that match the rule are marked as fraudulent automatically. |
| Global Blacklist | **Global Blacklist** | A list that Deepinfo's data team manages and updates. It excludes generic values to reduce false-positive discoveries. |
| Ignored Assets (discovery) | **Ignored Assets** | A list in the discovery settings. Domains, subdomains and IP addresses on it never appear in discovery lists, even when a rule finds them. |

## Issues and Vulnerabilities

| Term | UI labels | Meaning |
|---|---|---|
| Issue type, issue | **ISSUES** / **GROUP BY ISSUE TYPES** | An issue type is a kind of finding, such as an expired SSL certificate. An issue is one issue type found on one asset. The issue list is grouped by issue type by default. See [Triage issues](/guide/easm/issues/). |
| Issue category | **CATEGORY** / **CATEGORY STATS** | A group of related issue types. |
| Severity | **CRITICAL** / **HIGH** / **MEDIUM** / **LOW** / **INFORMATION** | The severity levels of issue types and issues. |
| State | **ACTIVE**: **NEWLY DETECTED** / **UNRESOLVED** / **REAPPEARED**; **INACTIVE**: **NOT APPLICABLE** / **VERIFIED RESOLVED** / **IGNORED** / **RISK ACCEPTED** / **MARKED AS RESOLVED** / **MARKED AS FALSE POSITIVE**; **SHOW INACTIVES** | Where an issue, or a CVE on one asset, stands. The states are grouped as active or inactive. The platform sets **NEWLY DETECTED**, **UNRESOLVED**, **REAPPEARED**, **NOT APPLICABLE** and **VERIFIED RESOLVED**. Users set the others. Lists show only active records until you tick **SHOW INACTIVES**. See [Change the state of issues and vulnerabilities](/guide/easm/change-issue-state/). |
| State actions | **CHANGE STATUS** / **IGNORE** / **ACCEPT RISK** / **MARK AS RESOLVED** / **MARK AS FALSE POSITIVE** / **REVERT IT** / **UNDO** / **CHANGE STATE** / **CHANGE ALL STATUS** | The actions that set a user state, on one record or in bulk. Only states set by a user can be reverted. A change shows a few seconds after you confirm it. |
| Active days | **ACTIVE DAYS** | The days between an issue's first and last detection, not its age up to today. After 30 days the value turns red with a fire icon. |
| Issue duration, fix duration, issue age | **AVERAGE ISSUE DURATION** / **AVERAGE FIX DURATION** / **AVERAGE ISSUE AGE** | Averages, in days. |
| Proof | **PROOF** | The evidence for an issue, shown as JSON. |
| Classifications | **CLASSIFICATIONS** | The compliance frameworks an issue type maps to, such as OWASP Top 10 2021, PCI 3.2, CAPEC, CWE, HIPAA and WASC. |
| Vulnerability (CVE), asset vulnerability | **VULNERABILITIES** / **CVE ID** | A CVE that affects at least one of your assets. Its state is changed per asset, not for the CVE as a whole. See [Prioritize vulnerabilities](/guide/easm/vulnerabilities/). |
| Certain, Potential | **CERTAIN** / **POTENTIAL** | Certain: "This vulnerability has been verified through testing and confirmed as valid." Potential: "This vulnerability has been identified through testing but not yet confirmed." |
| CVSS score | **SCORE/SEVERITY** / **CVSS SCORE** | The CVE's CVSS base score, from 0 to 10, with its severity. CVSS v3 is used, or v2 when v3 is missing. |
| EPSS | **EPSS** / **EPSS SCORE** | The CVE's EPSS value, shown as a percentage. |
| Exploitable (CISA KEV) | **EXPLOITABLE** / **EXP.** / **CISA KEV CATALOG** | Shown when the CVE is in the CISA KEV catalog. |
| Classification chips | **C/I/A: H/L/N** / **OWASP …** | **C/I/A** shows the CVE's impact on confidentiality, integrity and availability, as the first letter of each impact level. **OWASP** shows its OWASP category. |
| New vulnerability | **NEW** | "This vulnerability was first detected on your assets in the last 7 days." |
| Technology version | **LATEST VERSION** / **VERSION SCOPE** (**Out of Date**) / **EOL** | The latest known version of a technology, a filter for technologies on an out-of-date version, and the product's end-of-life table. |

## Cyber Threat Intelligence (CTI)

| Term | UI labels | Meaning |
|---|---|---|
| Compromised employee | **COMPROMISED EMPLOYEE DATA** / **COMPROMISED EMPLOYEES** | An employee account on your domains that was found in leaked credential data. See [Investigate compromised employees](/guide/cti/compromised-employees/). |
| Exposed credential | **EXPOSED CREDENTIALS** / **CREDENTIAL** / **SHOW PASSWORD** | One leaked login of an employee: the site or service, the account and the password. Passwords are masked until you reveal them with **SHOW PASSWORD** or the eye icon; revealing shows the password in plain text in your browser. See [Review exposed credentials](/guide/cti/credential-exposures/). |
| Credential state | **STATE**, for example **ACTIVE · UNRESOLVED** or **ACTIVE · NEWLY DETECTED**; **IGNORED** / **RISK ACCEPTED** / **MARKED AS RESOLVED** / **MARKED AS FALSE POSITIVE**; **CHANGE STATE** / **CHANGE ALL STATES** / **REVERT STATE**; **SHOW INACTIVES** | Where an exposed credential stands: **ACTIVE** or **INACTIVE**, with a detail, like an issue state. You can ignore a credential, accept its risk, or mark it as resolved or as a false positive, one at a time or in bulk; these states are inactive. **REVERT STATE** undoes a state you set. Inactive credentials are hidden until you tick **SHOW INACTIVES**. Client and payment credentials have a **STATE** too. See [Change the state of exposed credentials](/guide/cti/change-credential-state/). |
| Compromised client credential | **COMPROMISED CLIENT CREDENTIALS** / **COMPROMISED CLIENTS** | A login of one of your clients or customers that was found in breach data: the username and the site it belongs to. The list does not show passwords. See [Review compromised client credentials](/guide/cti/compromised-client-credentials/). |
| Compromised payment credential | **COMPROMISED PAYMENT CREDENTIALS** / **COMPROMISED PAYMENTS** / **PAN** / **CONFIDENCE** / **TIMES SEEN** | A payment card that was found in breach data. The list shows the card number (**PAN**), **CONFIDENCE**, **SOURCE**, **HACKISHNESS**, **TIMES SEEN**, **STATE** and **LAST SEEN**. See [Review compromised payment credentials](/guide/cti/compromised-payment-credentials/). |
| Risk level (CTI) | **CRITICAL** / **HIGH** / **MEDIUM** / **LOW** | An employee's priority. The platform describes it as "Composite priority based on credential, role, and recency." |
| Password strength | **VERY WEAK** / **WEAK** / **MEDIUM** / **STRONG** / **VERY STRONG**; **AVG STRENGTH SCORE** | A five-level strength label for a leaked password. **AVG STRENGTH SCORE** is the average strength of an employee's passwords, out of 10. |
| Exposure velocity, trend | **VELOCITY** / **TREND** / **EXPOSURE SPAN** | Part of an employee's security profile, which shows "how long the exposure has run and whether the rate is rising." **VELOCITY** is in credentials per month (`cred/mo`); **TREND** shows the direction, for example **STABLE**. |
| Executive | **Is Executive** / **EXECUTIVE** | A flag you set on an employee. Executives are shown with a VIP icon. |
| Target service attributes | **CORPORATE** / **MFA BY DEFAULT** (**ENFORCED** / **NOT ENFORCED**) / **RISK TIER** | Properties of the site or service a leaked credential belongs to. |
| Hackishness | **HACKISHNESS** / **Hackishness** | A score shown on dark-web search results and on compromised payment records. |
| Dark-web source | **SOURCE TYPE** / **SOURCE GROUP** | Where a dark-web result comes from: the type, such as Discord, Onion or Telegram, and the group, such as Forums, Markets or Pastes. See [Search the dark web](/guide/cti/dark-web-search/). |

## Brand Risk Protection (BRP)

| Term | UI labels | Meaning |
|---|---|---|
| Suspicious domain | **SUSPICIOUS DOMAINS** | A lookalike domain that your detection rules found. It waits for your review. See [Review suspicious domains](/guide/brp/review-suspicious-domains/). |
| Fraudulent domain | **FRAUDULENT DOMAINS** / **MARK AS FRAUDULENT** / **REMOVE FROM FRAUDULENT DOMAINS** | A suspicious domain you confirmed as fraudulent. It moves to the **FRAUDULENT DOMAINS** tab. See [Track fraudulent domains](/guide/brp/fraudulent-domains/). |
| Ignored domain | **IGNORED DOMAINS** / **UNDO IGNORE** | A suspicious domain you dismissed. **UNDO IGNORE** restores it. See [Restore ignored domains](/guide/brp/ignored-domains/). |
| Risk Score (BRP) | **RISK SCORE** / **INFORMATION** / **LOW** / **MEDIUM** / **HIGH** / **CRITICAL** | A score from 0 to 100 for a detected domain, in bands: **INFORMATION** from 1 to 20, **LOW** above 20 up to 40, **MEDIUM** above 40 up to 60, **HIGH** above 60 up to 80, **CRITICAL** above 80. It is not on the same scale as the security score. |
| Indicators | **DNS** / **DNS MX** / **SSL** / **HTTP** | Four signals shown for a detected domain. An icon is dark when the signal is present and light when it is not. |
| Match type | **Exact** / **Contains** / **Fuzzy** / **Fuzzy Contains** / **Confusable Exact** / **Confusable Contains** / **Confusable Fuzzy** / **Confusable Fuzzy Contains** | How a detection rule matches its keyword against domain names. The default is **Contains**. |
| Keywords and TLDs | **KEYWORD** / **HELPER KEYWORDS** / **NEGATIVE KEYWORDS** / **TLD MUST BE** / **TLD MUST NOT BE** | The inputs of a BRP detection rule. **KEYWORD** is required and has at least 3 characters. **TLD MUST BE** and **TLD MUST NOT BE** take extensions from a fixed list. See [Set up detection rules](/guide/brp/detection-rules/). |
| Start detection | **From Now On** / **Include Past** | Whether a new detection rule starts from now (**From Now On**, the default) or also covers the past (**Include Past**). It cannot be changed after the rule is created. |
| Ignored Assets (BRP) | **Ignored Assets** | A list in the BRP settings. Domains and subdomains on it never appear as detected, even when a detection rule matches them. |

## Deep Search & Insights (DSI)

| Term | UI labels | Meaning |
|---|---|---|
| DSI | **DEEP SEARCH & INSIGHTS** / **DSI** | The sidebar group of search and research tools: **DOMAIN INTELLIGENCE**, **DOMAIN SEARCH**, **VULNERABILITY INTELLIGENCE**, **VULNERABILITY SEARCH**, **INSTANT LOOKUP** and **FEEDS**. Its breadcrumbs start with **DSI**, which is also its short name in the collapsed sidebar. See [Deep Search & Insights (DSI)](/guide/dsi/). |
| Page tabs | **Duplicate** / **New Tab to The Right** / **Close Tab** / **Close Other Tabs** / **Close Tabs to the Right** | Browser-like tabs in Domain Search, Vulnerability Search, Instant Lookup and Dark Web Search. They are saved in your browser, so they survive a reload. |
| Reverse lookup | **SEE OTHERS** / **Domain with same IP Address** / **Domain with same Name Server** / **Domain with same Mail Exchanger** / **Domain with same Email** | Other domains that share an IP address, name server, mail server or registrant e-mail with the domain you are looking at. See [Domain details and reverse lookups](/guide/dsi/domain-details/). |
| Instant lookup | **LOOKUP** / **PARSED** / **RAW** | A real-time query about a single target: WHOIS, DNS, SSL, webdata, technology, screenshot or port scan. **PARSED** and **RAW** switch between the formatted result and the JSON. See [Run instant lookups](/guide/dsi/instant-lookup/). |
| Feeds | **DAILY FEEDS** / **EXCLUSIVE FEEDS** / **CUSTOM FEEDS** | Bulk data files you can download, such as the domains registered each day. See [Download data feeds](/guide/dsi/feeds/). |

## Reports and Notifications

| Term | UI labels | Meaning |
|---|---|---|
| General report, CSV/JSON report | **GENERAL REPORTS** / **CSV AND JSON REPORTS** / **.PDF** | A general report is a PDF that the platform generates from your data. A CSV/JSON report downloads a whole dataset as a file. See [Reports](/guide/reports/). |
| Reports history | **REPORTS HISTORY** | The copies of a report type generated so far, listed in the report's drawer. Each copy is a snapshot of your data at the time it was generated. |
| Scheduled report | **SCHEDULED REPORTS** / **SCHEDULE A REPORT** / **SCHEDULE NEW REPORT** | A PDF report that the platform generates daily, weekly or monthly and e-mails to the members you choose. See [Schedule a report](/guide/reports/schedule-a-report/). |
| Notification rule | **Notification Rules** / **Event Type** / **Rule Settings** / **Filters** / **Reviews** / **SCOPE** | A rule that e-mails chosen members when an event happens. It has one event, optional filters, a frequency and at least one recipient. The rules list shows the event in the **SCOPE** column. See [Notification Center](/guide/notifications/). |
| Frequency | **INSTANT** / **HOURLY** / **DAILY** / **WEEKLY** / **MONTHLY** | How often a notification rule sends e-mails. Scheduled reports offer **DAILY**, **WEEKLY** and **MONTHLY**. |
| Delivery channel | **Email** / **Slack** / **Webhook** | How a rule's notifications are delivered. Only **Email** can be used; **Slack** and **Webhook** are shown but not available. |
| E-mail preferences, notification rules | **SETTINGS** › **USER SETTINGS** › **Notifications** vs **NOTIFICATION CENTER** | E-mail preferences choose which Deepinfo e-mails you receive: announcements, newsletter, product updates and training. Notification rules send alerts about your organization's data. See [Choose which Deepinfo e-mails you receive](/guide/settings/email-preferences/). |
