Reports
Reports your board will actually read.
The board wants a number and a direction. The engineers want rule IDs and evidence hashes. The customer's security questionnaire wants control statements. All three are the same scan, rendered differently, not three documents somebody assembles by hand the night before.
- Templates
- 3
- Export formats
- 4
- Reads a specific scan
- Point-in-time
- Your branding
- White-label
One scan, three audiences.
Switch template and the document changes substantially, because a summary for a board and a finding table for an engineer are genuinely different documents, not one with a different cover page.
- 1. Revoke the payment key found in the public JavaScript bundle, then move the call server-side.
- 2. Renew the API certificate. It lapses in twelve days and the renewal job has not run since June.
- 3. Deploy the header policy that exists in staging but has never reached production.
The report is where the work becomes visible
Security work that nobody outside the team can read gets budgeted like work nobody outside the team can see.
Written for the reader
Every finding already carries a plain-language explanation and a business impact, because that requirement is enforced in the shape of a finding, not added at export time by a summariser.
Backed by stored evidence
A report is a read over immutable findings and their evidence rows, each with a content hash and the scanner version that produced it. Nothing in it is generated fresh at render time.
Point-in-time, reproducible
A report is generated from a specific scan, so regenerating last quarter's document produces last quarter's document, not today's data in an old wrapper.
Internal notes stay internal
Comments marked internal are excluded from client-facing output. The distinction is a field on the comment, so it can't be forgotten during an export.
Your branding on it
White-label configuration lives on the template, which is what makes this usable by an agency delivering to their own clients rather than only by the team that ran the scan.
Trends, not just today
Score movement, resolved counts, and average time to resolve come from history that was already being kept, so a report can show direction rather than a single snapshot.
The pieces a report is assembled from
Each is a read of data that already exists. That's what makes generating one cheap enough to do whenever someone asks.
Score and trend
The overall security score with its movement since the previous scan, and per-category deltas underneath it.
Findings by severity
Open findings grouped by severity and shown with priority, so the ordering in the document matches the ordering in the product.
Evidence references
Content hashes, scanner version, and capture timestamps per finding. Secret values themselves stay redacted.
Recommendations
Prioritised remediation steps drawn from each finding's own fix guidance, ordered by what would move the score most.
From a scan to a document
Report generation runs as its own low-priority job, so producing one never slows a scan down.
- 1
Choose a scan and a template
Reports are generated against a specific scan, not against 'now'. Picking an earlier one is how you reproduce what was true at the time rather than reconstructing it.
- 2
The template decides the audience
Executive, technical, and compliance templates read the same findings and render different documents: summary and direction, evidence and rule IDs, or control statements.
- 3
Internal content is filtered out
Comments marked internal are removed from client-facing templates as part of rendering, rather than relying on whoever generates the report to remember.
- 4
It renders in the background
Rendering runs as its own queued job at low priority, independent of scan queues, and requests carry an idempotency key so a retried click doesn't produce two documents.
- 5
You download or fetch it
Finished reports are stored as artifacts and retrievable through the dashboard or the API, in PDF, HTML, CSV, or JSON.
Reports, answered.
Yes. Scans, findings, and evidence are append-only, so a report generated against an earlier scan reproduces that point in time rather than re-rendering today's data in an old format.
Answer the questionnaire in an afternoon.
Run a scan, pick a template, and hand over a document backed by stored evidence.