PathixDataverse Forensics

← All 40 findings

Secrets & transmission security

A webhook or service endpoint using plaintext HTTP

Severity High

What it is

Integration endpoint sends payloads over plaintext HTTP.

Why it matters

A service endpoint or webhook uses http, so record data, execution context, and any credential in the message cross the network unencrypted.

Find it yourself

List your service endpoints and webhooks and read the URL scheme on each. Anything starting http rather than https is the finding, and any credential that has been travelling over it should be treated as exposed.

How to fix it

Re-register against https, verify the certificate, and rotate any credential sent in the clear.

Related controls

SOC 2 CC6.7ISO 27001 A.8.24 / A.5.14NIST SC-8 / SC-13

These mappings are indicative. Pathix detects a condition relevant to a control. It does not certify your compliance, and a finding is not an audit opinion. You stay responsible for your control environment.

Pathix checks this across every environment you scan, along with 39 other conditions. Self-hosted in your own Azure, read-only, metadata-only.

More in secrets & transmission security

← Back to all 40 findings

Pathix

Forensics for Dynamics 365 and the Dataverse.

See it on sample data →
USE CASES
CAPABILITIES
  • What we check
  • Dataverse MCPsoon
  • Dependency analysissoon
  • Migration impactsoon
PRODUCT
COMPANY
© 2026 Pathix · self-hosted · metadata-onlyNot affiliated with Microsoft. Dynamics 365, Dataverse, and Power Platform are trademarks of Microsoft Corporation.