The dashboard
Overview, devices, findings – what is where.
Overview #
The start page answers three questions: how are things right now?, what has changed? and what needs doing?
- How many findings are open, at which severity, and how that develops over time. No overall grade – why, is under Understanding findings.
- What's new – findings that appeared since you last looked, and fixed ones as a success.
- Device status: reporting on schedule, overdue, or silent for a while.
A device that stops sending is a signal in itself – which is why it is here and not in a side view.
Devices #
The list shows every connected system with operating system, role, open findings and last report. In the detail view of a device you find:
- the findings of this device, sorted by severity,
- questions – the few things NODE64 cannot measure,
- the upgrade plan as a script to download,
- telemetry (load, memory, disk) and the most recent uploads,
- what the logs say – counted patterns from the last 24 hours (failed logins, OOM killer, I/O errors, services in a crash loop), with the direction compared to the previous run and a link to the matching finding,
- groups and the role of the device (server, endpoint, router, firewall) – the role determines which checks apply at all.
Security #
All findings of all devices in one place, filterable by type, severity, status and device. By default you see what is open; the status filter gets you to fixed, accepted and postponed findings.
Inventory #
The only view that looks across all devices. Two questions, and the second is the more useful one:
- "Where does X run?" Search by package name, optionally by version. The result is grouped by package and version, not by package alone — "nginx on nine devices" hides exactly what matters: that eight of them are on 1.24 and one is on 1.18.
- "Which device deviates?" For a chosen device, the packages that sit at a different version there than on the majority of the others. That is almost always a device missed in the last update round — and it appears in no findings list, because there each device is considered on its own.
The second question needs at least three devices. With two there is no majority for anything to deviate from: each of them would deviate from the other, and the statement would carry nothing.
The record comes from each device's most recent report — it is as current as that report, no more.
Other areas #
| Area | For what |
|---|---|
| Alerts | rules, recipients, history – see Alerts |
| Uploads | what arrived when, and whether processing worked |
| Sonar | the measurement network – see Measurement network |
| Settings | profile, security, team, API keys, data export |
Language and appearance #
Top right you switch language (German/English) and appearance (light, dark, system setting). Both are remembered and apply to emails as well.
Where things live (as of August 2026) #
A device has six tabs, and each answers exactly one question:
| Tab | Question |
|---|---|
| Overview | Is anything going on right now? |
| Security | What is unsafe, what does the framework require, what could be better? |
| Timbre | What is normal on this system – and what deviates? |
| Pulse | How is the machine doing? |
| History | What has changed? |
| Settings | How is the device set up? |
Until August 2026 there were eight. "Security & CVEs", "Compliance" and "Best practices" sat side by side as three tabs. They answer the same question from three directions, and three tabs forced you to page between things that belong together. They are now called Security together – and live there as three cards that open individually. They stay separate on purpose: a suggestion sitting next to an open vulnerability looks like a defect.
Collapsed is the normal state everywhere. Collapsed, each card shows one sentence and a number – "7 of 9 fulfilled", "49 open findings, 3 of them critical or high". Open it and you get everything that used to be on its own page. Nothing has been cut.
And the measurement network moved out. Participation and probe setup used to sit under "Device → Settings → Measurement network". But the measurement network runs independently of the security check – you can take part in it and nothing else. Both now live with the probe, under Sonar → Probes. The old addresses redirect there.