Skip to content
Verified closure

Closed means gone.

An exposure is closed when what caused it is no longer in your environment. Checked, not assumed.

Closing the ticket starts the check. It is never the check.

Three states

Only one of these is closed.

Closed

The root cause is gone from the environment.

Route blocked

A control broke the route. The root is still there. Open, and the record says so.

Often the right call. Unizo drafts it.

No reachable path

Nothing reaches it today. The root is still there. It comes back when a route does.

One exposure, two Plans

Block the route today. Remove the cause when you can.

Unizo drafts both and drives either. Only one closes the exposure.

jdoe-laptop api key in mcp config
CHANGE WINDOW Rotate the credential
CLOSED the credential is gone from the file, confirmed against the environment
mcp-postgres
role/ai-agent-prod Breakpoint
TODAY Restrict the role
ROUTE BLOCKED the credential is still in the file, the exposure stays open
db-customers
Evidence

What you can show someone else.

Route blocked
Verdict
blocked by permission boundary
Root
api key in mcp config
Re-derived
present
Control
PB-restrict
Provider
AWS
State
open · route blocked
Checked16 Sep 2026 14:02 UTC
Closed
Root
api key in mcp config
Re-derived
not present
State
closed
Checked16 Sep 2026 14:02 UTC
By exposure type

What has to be gone.

Exposure typeWhat has to be gone
Vulnerability on a host or workloadThe finding on the asset
Cloud misconfigurationThe misconfigured setting
Identity and accessThe over-privileged grant, not the principal or the resource
Code to runtimeThe vulnerable artifact still deployed, not the repository commit
AI asset on a pathThe embedded credential

Independently re-derived, with effective-access verification where the credential terminates at a control plane Unizo can simulate against.

Straight answers

Does closing the ticket ever close the exposure?

No. It starts the check.

Does a compensating control close it?

No, and Unizo drafts one anyway when it is the right move. The exposure stays open and the record says so.

What if the cause comes back?

Closure is a checked state at a recorded time. When a root cause reappears, Unizo reopens the Exposure.

Do we need our scanner replaced?

No. The check runs against the sources that reported it.

Bring us one you have already closed.

We will check it against your environment and show you what we find.