Skip to main content
Migration Notice
We're migrating documentation from the old portal into this one. Some things may look a little different or out of place in the meantime — we know, and we're working to get it right. If something's unclear or doesn't look right, let us know.

Security Metrics

The Security Metrics page gives you a time-bucketed view of how the unique-file population scanned by the AI Risk Pipeline changes over time. It rolls scan results up into time buckets so you can follow two trends: the percentage of files that contain PII, and the percentage of files with anomalous Linguistic Coherence (LC) verdicts.

Where: Security Metrics

Use it to spot a sudden increase in sensitive data, confirm that a fix brought the PII percentage back down, or establish what normal looks like in your environment.

Each bucket counts unique physical files. Re-scans and modifications of the same path count as one file, so the numbers reflect the real file population rather than the number of scan events.

Overview​

The page reads the pipeline's scan results. It does not change pipeline behavior or any stored data. From top to bottom, it contains:

  1. Header controls — the Window and Granularity selectors, an auto-refresh countdown ring, and a Refresh button.
  2. Summary cards — four key figures.
  3. File-population trend chart — a combined bar and line chart for the selected window.
  4. Per-bucket detail table — the figures behind each bucket.

The page refreshes automatically every 30 seconds. The countdown ring shows the time until the next refresh. Click Refresh to load new data immediately. While data loads, Refresh shows a spinner and is disabled.

Controls​

  • Window — how far back the chart and table reach. Options are Last 24 h, Last 7 d (default), Last 14 d, Last 30 d, and Last 90 d. Changing the window reloads the data.
  • Granularity — the size of each time bucket, either Daily (default) or Hourly. Use Hourly with a short window, such as Last 24 h, to see spikes during the day. Use Daily with a longer window to read the trend.

Summary cards​

The first three cards use the latest bucket. The last card covers the whole window.

CardDescription
Latest bucketThe timestamp of the most recent bucket and the number of unique files in it. Shows no data yet when the window has no buckets.
% with PIIThe share of unique files in the latest bucket with a PII verdict, with the underlying count shown as pii_files of unique_files.
% anomalous LCThe share of unique files in the latest bucket with an anomalous LC verdict, with the underlying count shown as anomalous_lc_files of unique_files.
Window totals (Nd)The total PII files over the total unique files scanned across the selected window, shown as PII files / unique files scanned. Nd is the number of days in the window.

File-population trend chart​

The chart plots absolute counts and percentages over time.

SeriesAxisDescription
Unique files (grey bars)Left, countThe total unique files in the bucket.
PII files (pink bars)Left, countUnique files with a PII verdict.
Anomalous LC (yellow bars)Left, countUnique files with an anomalous LC verdict.
PII % (red line)Right, percentagePII files as a percentage of unique files.
Anomalous LC % (amber line)Right, percentageAnomalous LC files as a percentage of unique files.

The horizontal axis is time. Hover over any point to see the bucket timestamp in your local time and the value of every series for that bucket.

The bars show absolute volume, such as a spike in scanning. The lines show the rate. A rising PII % line means a growing proportion of your files contain PII, even when the absolute count is steady.

Per-bucket detail table​

The Per-bucket detail table below the chart lists every bucket, newest first. Its columns are Bucket (the local-time timestamp), Unique files, PII files, PII %, Anomalous LC, and Anomalous LC %. Use it to get the exact numbers behind a spike in the chart or to copy figures into a report.

Workflows​

Find when a PII increase started​

  1. Set Window to Last 30 d and Granularity to Daily.
  2. Find the day when the red PII % line rises.
  3. In the Per-bucket detail table, read the PII files and unique files counts for that day.
  4. Open the Pipeline or File Activity page to see what was scanned around that time.

Check today's trend​

  1. Set Window to Last 24 h and Granularity to Hourly.
  2. Look at the bars to find the hours with the most scanning.
  3. Look at the lines to find the hours when the PII or anomalous LC rate rose.

Troubleshooting​

The page shows "No data yet". This view includes only newer scans, so older scan results are excluded. If the chart is empty, the pipeline has not produced new scan results in the selected window. The chart fills in after new scans run. A wider Window can also show older buckets.

An error banner appears instead of the chart. The metrics request failed. Click Refresh to retry. If the error continues, confirm that the backend pipeline service is running and that the AI Risk Pipeline is producing scan results.

Percentages show 0%. A bucket with no unique files shows 0% for both PII and anomalous LC. This is expected for quiet buckets with no scanning.

Timestamps look shifted. Bucket timestamps are shown in your browser's local time. The chart and tooltips convert the stored UTC bucket boundaries to local time.