Reference
Glossary
Product terminology and definitions.
- Audience
- All users
- Plan availability
- All plans
- Last reviewed
Plain-English definitions for terms used in Cyber Health Score. Definitions match the in-product security glossary where a term appears there. Product terminology may evolve; if a label in the workspace differs from this page, follow the in-product wording.
Product and workspace
Analyst
A workspace role that can manage domains, run scans, triage findings, and work with evidence. See Roles and permissions.
Admin
A workspace role that can manage team access, review evidence submissions, and configure workspace settings alongside Owners.
Compliance Evidence
A generated compliance-oriented summary assembled from posture, findings, remediation, and audit signals. It supports audit preparation and is not compliance certification.
Configurable Reports
User-created reports that can include approved evidence from the Evidence Vault. Available on supported plans.
Evidence Vault
Where your workspace stores evidence records and attachments with a review workflow.
Owner
The primary workspace role with full administrative control, including billing context on supported plans.
Phishing simulation
Controlled test emails that mimic real attacks to train staff to recognise suspicious messages safely. Even strong DNS and TLS cannot stop every social-engineering attempt; awareness reduces click-through and credential theft.
Posture score
CHS's summary score reflecting how your domain's observed configuration compares to the checks we run. It is not a guarantee of zero incidents.
Scan
An automated posture check CHS runs against your verified domain to produce a score, findings, and reports.
Viewer
A workspace role that can review dashboards and findings but cannot change workflow or configuration.
Findings and remediation
Domain verification
Proving to CHS that you control a domain, often by publishing a unique DNS TXT record, before sensitive scans run.
Finding
A specific issue CHS observed in a scan, such as a missing header or weak TLS, often with severity and a recommended fix.
Remediation
The work to fix or accept a finding: configuration changes, patches, or documented risk acceptance.
Severity
How serious CHS considers a finding in context. Severity helps prioritise when time is limited; it is guidance, not a guarantee of business impact.
DNS, email, and web security
Attack surface
The set of internet-facing systems and entry points (sites, APIs, mail, exposed ports) that could be targeted.
CAA (Certification Authority Authorization)
DNS records that say which certificate authorities may issue TLS certificates for your domain.
CSP (Content-Security-Policy)
An HTTP header that limits where scripts, styles, and other resources may load from, reducing cross-site scripting risk.
DKIM (DomainKeys Identified Mail)
A way to attach a cryptographic signature to outgoing mail so receivers can verify it really came from your systems and was not altered in transit.
DMARC
A policy you publish in DNS that tells receivers what to do with mail that fails SPF or DKIM checks, and often includes reporting addresses.
DNS TXT record
A simple text field in your public DNS used for many standards: verification tokens, SPF, DKIM, DMARC, and more.
HSTS (HTTP Strict Transport Security)
An HTTP header that tells browsers to always use HTTPS for your site for a period of time, reducing downgrade attacks.
HTTPS
HTTP over TLS: web traffic that is encrypted in transit, shown as a padlock or secure indicator in browsers.
MX record
A DNS record that tells the internet which mail servers receive email for your domain.
SPF (Sender Policy Framework)
An email-authentication method that lists which mail servers are allowed to send email that appears to come from your domain.
SSL / TLS
Protocols that encrypt traffic between visitors and your site so passwords and data are not exposed on the network.
Subdomain
A hostname under your main domain, such as app.example.com under example.com.
Terminology note
Cyber Health Score may add or refine glossary entries over time. The in-product assistant uses the same canonical glossary where supported. If you need a definition that is not listed here, contact support or refer to the relevant guide in this help centre.
Related documentation
Related documentation
Return to the documentation home to browse all topics.
Back to documentation