---
title: SecurityRisk enum | Wartiva GraphQL API
description: Describes a type of security risk. Wartiva GraphQL API reference with arguments, fields, and examples. Browse related operations and types.
url: https://wartiva.com/api-docs/types/security-risk.html
updated: 2026-10-07
---

Policies and findings · GraphQL enum

# `SecurityRisk` enum

Describes a type of security risk.

## Values

| Enum Value | Description |
|---|---|
| `VULNERABILITY` | A known software or configuration vulnerability. |
| `EXTERNAL_EXPOSURE` | An asset or service exposed to the public internet. |
| `UNPROTECTED_PRINCIPAL` | An account or identity lacking sufficient protection (e.g. no MFA). |
| `INSECURE_USE_OF_SECRETS` | Credentials or secrets stored or transmitted insecurely. |
| `UNPROTECTED_DATA` | Sensitive data lacking encryption or access controls. |
| `HIGH_PROFILE_THREAT` | A high-profile or actively exploited threat. |
| `RELIABILITY_IMPACT` | A finding that may impact system reliability or availability. |
| `INSECURE_APPLICATION` | An application with insecure configuration or behavior. |
| `EXTERNAL_ATTACK_SURFACE` | An externally reachable attack surface. |

## Used by

- [`Rule`](https://wartiva.com/api-docs/types/rule.html) type: A policy rule evaluated against graph objects.
- [`RuleInput`](https://wartiva.com/api-docs/types/rule-input.html) input: Input variant of Rule carrying its writable fields.

## Example

### Example

```json
"VULNERABILITY"

```

---

Wartiva is in early access. Request access: https://wartiva.com/early-access.html  
All pages: https://wartiva.com/llms.txt
