Vulnerability scanning FAQ for MSPs
Straight answers about Nessus and Greenbone / OpenVAS exports, scan quality and client-ready reporting — so you can explain what the evidence supports before you make a recommendation.
Start with the export
The quality of a client report starts with knowing what the scanner export actually contains.
What is Varaxon Scan Hub?
Varaxon Scan Hub turns Tenable Nessus and Greenbone / OpenVAS XML exports into structured PDF vulnerability reports. It keeps scanner evidence attached to findings, makes coverage limits visible and flags conflicting records instead of silently choosing a value.
Does Varaxon Scan Hub run the vulnerability scan?
No. Scan Hub processes an export you already generated; it does not replace Nessus or Greenbone / OpenVAS and does not need scanner credentials or an agent for this workflow. Run the scan in your normal tooling, then use the report to explain what that export can support.
Which scanner exports are supported?
The supported formats are a Tenable Nessus
.nessus XML export and a Greenbone / OpenVAS XML export. The Nessus report guide and Greenbone / OpenVAS guide show how each export family is handled.Read scan quality honestly
A missing field is a data-quality signal, not evidence that the environment is clean.
Does a missing CVE mean a finding is harmless?
No. It means the export did not provide a usable structured CVE reference for that finding. The report marks CVE-based assessment as Unknown or unavailable so an MSP does not accidentally present incomplete evidence as a clean result.
Why might CVSS or remediation data be missing?
Scanner exports can omit, vary or leave parts of the supporting metadata incomplete. Scan Hub preserves the fields that are present and calls out gaps rather than inventing a score, remediation step or certainty that the export cannot support.
What does credentialed scan coverage tell an MSP?
Credentialed coverage can give the scanner deeper visibility into installed software, patches and configuration. A credentialed percentage is still a scope and evidence measure, not proof that every asset was assessed. The report surfaces coverage, credential failures and missing host context so you can explain the boundary to a client.
How are findings prioritized?
Scan Hub validates the plugin and CVE relationship first, then uses the exploitation intelligence and severity context available in the export and trusted enrichment. If records conflict or the evidence is incomplete, that uncertainty is kept visible and the affected finding is flagged for review instead of being given a misleading rank.
Make the report client-ready
A useful report gives the client enough context to decide what to do next without hiding uncertainty.
Can MSPs brand reports for their clients?
Yes. You can identify the MSP as the provider, identify the client separately and add an optional provider logo. Scan Hub sizes the supplied logo to fit the report cover so the exported PDF reads as a clear, client-ready deliverable.
Is Varaxon Scan Hub a penetration test?
No. It is an export parser and reporting layer for vulnerability assessment data. It does not perform a penetration test, replace remediation work or establish that an environment is secure. Use the report alongside the scope, scan configuration and any manual validation your engagement requires.
Privacy, cadence and pricing
These answers cover the practical questions that come up before an MSP makes Scan Hub part of its workflow.
Is uploaded scan data stored?
The public report flow processes the upload in request-scoped memory to produce the report and does not retain scan history. Do not upload a real client export without the client authorization and review the Privacy Policy for the complete terms.
How can I try Varaxon Scan Hub?
Start with the free, anonymous pre-flight assessment — no account, card or email address is required. You receive your first three reports free; after that, choose a plan or a pay-as-you-go report. Visit sample reports first if you want to review the output before uploading your own export.
How often should an MSP scan a client environment?
There is no single schedule that fits every client. Set cadence from the environment's exposure, asset criticality, change rate, contractual commitments and the time needed to act on findings. A recurring authenticated process is usually more useful than a one-time scan, and some security guidance recommends at least monthly vulnerability checks. Document the scope and date every time so the report's age is clear.
Want to see the output first?
Download the synthetic Nessus and Greenbone / OpenVAS samples, then run the free pre-flight assessment on your own export when you are ready.
