Skip to main content
A report summarizes an engagement and captures the relevant vulnerabilities and evidence at the time it is written. The report preserves those results while the vulnerabilities continue through their lifecycle. Use reports to share the results of testing with your team, customers, or auditors.

What a report contains

  • Executive summary: an overview of the engagement and its results.
  • Scope and methodology: what was tested and how the testing was performed.
  • Vulnerabilities: the security weaknesses identified, including their severity and descriptions.
  • Evidence: the material supporting those vulnerabilities.
Reports can also map vulnerabilities to compliance frameworks such as HIPAA, PCI DSS, SOC 2, and NIST 800-53.

View and export a report

Open Reports in the platform and select a report to read it. You can review the engagement summary, inspect individual vulnerabilities, and examine their supporting evidence. Select Export to download a PDF for sharing outside the platform.

Reports and ongoing work

A report describes the engagement at a particular point in time. Work on its vulnerabilities can continue after the report is written. For example, a vulnerability may be open when it appears in a report and verified after your team deploys a fix. The report preserves the original results; the Vulnerabilities page shows the current status and subsequent work.