Accuracy SLA
Last updated: Sep 30, 2026
Description
Reports of the risk exposure of the software of a client reach an F2 score of a minimum of 90%. Reports of its vulnerabilities reach an F0.5 score of a minimum of 90%.
This service-level agreement (SLA) indicator exists since January 2025. It addresses the pain of management (for example, critical and overlooked issues) and the pain of developers (for example, waste of time and work). Fluid Attacks breaches the Accuracy SLA when the two accuracies are below 90% with the criteria below. The first accuracy is the F2-score-measured accuracy of the risk exposure reports (henceforth, "severity accuracy"). The second is the F0.5-score-measured accuracy of the vulnerability reports (henceforth, "quantity accuracy").
Criteria
This SLA indicator applies only if your group has the Advanced plan. Also, false negative and false positive reports must satisfy the defined conditions to count as true. See the articles False negatives and False positives for the details.
Details
Together with the general measurement aspects, Fluid Attacks measures this SLA indicator with these rules:
- The risk exposure of the vulnerabilities uses the formula CVSSF = 4^(CVSS-4).
- The accuracy uses the false positives, the false negatives, and the F-Score model.
Indicator calculation
Fluid Attacks does not measure the Accuracy SLA with only the false positive rate or the false negative rate. These two rates are complementary in the assessment of security testing accuracy.
For example, a good false positive rate is possible when the tests find no actual vulnerability (that is, when the tests give no alarm, legitimate or not). A good false negative rate is possible when the tests flag everything as a vulnerability (that is, when the tests give all the possible false alarms).
This SLA indicator has two measures: severity accuracy and quantity accuracy.
Severity accuracy is equal to the value of the F2 score. This score gives more weight to the false negatives. With this model and the CVSSF metric, Fluid Attacks measures the accuracy in the terms that are most important to the management of your organization. The question is if the tests overlook a critical issue.
Quantity accuracy is equal to the value of the F0.5 score. This score gives more weight to the false positives. With this model and the number of vulnerabilities, Fluid Attacks measures the accuracy in the terms that are most important to your development team. The question is if the reported issues are correct.
Severity accuracy calculation
- Calculate the CVSSF of each vulnerability with the formula CVSSF = 4^(CVSS-4).
- Calculate the total CVSSF of the true positives, the false positives, and the false negatives.
- Calculate these intermediate indicators:
- Precision: true positives / (true positives + false positives)
- Recall: true positives / (true positives + false negatives)
- Calculate the F2 score with the formula 5 * {[Precision * Recall] / [(4 * Precision) + Recall]}
Quantity accuracy calculation
- Count the total number of vulnerabilities in the groups on the Advanced plan. Include the deleted groups that were on the Advanced plan. Count the true positives, the false positives, and the false negatives independently.
- Calculate these intermediate indicators:
- Precision: true positives / (true positives + false positives)
- Recall: true positives / (true positives + false negatives)
- Calculate the F0.5 score with the formula 1.25 * {[Precision * Recall] / [(0.25 * Precision) + Recall]}
Search for vulnerabilities in your apps for free with Fluid Attacks' automated security testing! Start your 21-day free trial and discover the benefits of the Essential plan. If you prefer the Advanced plan, which includes the expertise of Fluid Attacks' pentesting team, complete this contact form.