Vetted Scans Page - Overview

Last updated: September 30, 2026

Summary

Vetted Scans are automated scans that Astra’s security engineers have reviewed (or are reviewing) for accuracy. After you request vetting on a completed scan, that engagement moves to the dedicated Vetted Scans page which is separate from your regular DAST Scans list so you can track expert review, review confirmed findings, and request a rescan after you fix issues.

What is a Vetted Scan?

Vetting is an expert review of a completed automated scan. Astra’s security engineers:

  • Manually review reported vulnerabilities for accuracy and relevance

  • Confirm findings that reflect real security risks

  • Remove false positives where appropriate

  • Deliver a high-confidence, actionable result set

Where to Find Vetted Scans

From the left navigation:

Product

Menu path

Web DAST

Web DAST → Vetted Scans

API Security

API Security → Vetted Scans

Cloud Security

Cloud Security → Vetted Scans

Regular automated scans stay on DAST Scans. Once you request vetting, the scan appears on Vetted Scans.

How to Request Vetting

Prerequisites

  • A completed automated scan (status Scan Completed)

  • Available vetting credits for that target

  • Request made within the scan’s vetting / rescan validity window

  • Vetting is not available for cancelled or failed scans, static analysis, or scans already under vetting

From the Scans list (recommended for one or many scans)

  1. Open DAST Scans (or Vulnerability Scans for Cloud).

  2. In Scan Completed, select one or more eligible scans.

  3. Click Request Vetting in the selection bar.

  4. Confirm credit usage and then submit.

From a scan details page

  1. Open a completed scan from DAST Scans / Vulnerability Scans.

  2. Click Request Vetting.

  3. Review remaining credits (Available Vetting Requests (per target)) and confirm.

After a successful request, you are taken to that scan under Vetted Scans.

How to Track a Vetted Scan

On Vetted Scans, engagements are grouped by stage:

Section

Meaning

Under Review

Security engineers are vetting the scan results

Vetting Completed

Expert review is done; review findings and remediate

Re-Scan In Progress

A rescan is verifying your fixes

Failed / Cancelled

The engagement did not complete successfully

Open any row to see progress, ETA / deadline when set, vulnerabilities, and actions. Delivery status and email updates work similarly to other analyst-backed work - see How to Track the Progress of a Pentest.

How to Request a Rescan on a Vetted Scan

After Vetting Completed, you can request a rescan to verify remediation, the same remediation loop as other reported scans.

  1. Open Vetted Scans and open a scan in Vetting Completed.

  2. Fix vulnerabilities and mark them ready for review (Unsolved / eligible items).

  3. Click Rescan (from the details header or vulnerability selection).

  4. Choose the available rescan type for those findings (automated and/or manual, depending on eligibility).

  5. Confirm. The scan moves to Re-Scan In Progress.

Rescan is available once the vetted scan is in Vetting Completed (or already in a rescan state). For general rescan rules and quotas, see How to: Request a Rescan After Fixing Vulnerabilities.

Best Practices

  • Request vetting on scans that matter for compliance or release gates, and watch per-target credit usage

  • Wait until vetting finishes before a large remediation push so you are not fixing false positives

  • Before rescan, fix and mark as many eligible issues as practical so one rescan covers more ground

  • Use Vetted Scans as the home for anything already sent for expert review

Troubleshooting

I don’t see Vetted Scans in the sidebar

Confirm you are in Web DAST, API Security, or Cloud Security. Vetted Scans is not shown for products that don’t support this flow.

Request Vetting is disabled

The scan may still be running, already vetted, cancelled/failed, outside the validity window, or your target may have no remaining vetting credits. Trial plans may need an upgrade for vetting.

My scan disappeared from DAST Scans after I requested vetting

That is expected. After you request vetting, track it under Vetted Scans.

Rescan is disabled on a vetted scan

Rescan unlocks at Vetting Completed. If review is still Under Review, wait for engineers to finish. Also check rescan window and quota rules in the rescan help article.

No vetted scans yet

Complete an automated scan, then request vetting from DAST Scans / Vulnerability Scans → Scan Completed.