Applications ranked by contextual risk — severity weighted by tier, exposure, data, regulatory scope, KEV and live attack traffic.
Accepted risk inside 30 days of expiry. No scanner knows these exist.
Absolute risk says where the exposure is. Risk per application says who is managing it badly.
What is open on applications carrying each flag. Not a compliance assessment.