Pen TestingCloud PostureShadow-AI discoveryCI/CDContinuous PlatformReportsIdentity & accessAgent Trust Fabric
Reports
Three deliverables from one scan.
Every completed scan produces a professional, honest-by-construction report grounded in PTES, NIST SP 800-115, OWASP WSTG, CREST and CVSS — because the people who need proof that you tested are rarely the people allowed to see how we broke in.
3 tiers
attestation letter, full report, machine-readable twin
6 frameworks
in the compliance cross-map, plus the EU AI Act
CREST / OSCP
certified human reviewer signs off the report — available on any scan
Attestation
GET /api/runs/<id>/attestation · owner or admin
Letter of Attestation — redacted by construction
Legal name, provider and signature, dates, summary scope, methodology and severity counts. Never a PoC, never an endpoint, never per-finding detail.
What it carries
Legal entity and provider signature
included
Test window and assessment type
included
Severity counts
included
Proof of concept, endpoints, finding detail
excluded
Machine-readable twin
Send it into a TPRM review without an NDA round-trip
No exploit detail
One scan, three audiences
The same assessment, redacted to the reader.
Tier 1
Letter of Attestation
procurement · TPRM · customers
Tier 2
Full compliance report
engineering · auditors under NDA
Tier 3
JSON twin
Vanta · Drata · Secureframe
The dark bar is not a design flourish — the attestation letter genuinely omits the PoC, the endpoints and every per-finding detail, so it can leave your building.
Who each deliverable is for
01
Letter of Attestation
For downstream customers, procurement and third-party risk. Redacted and signed, with no exploit detail whatsoever — so it moves without a redaction pass.
02
The full compliance report
For engineering and auditors under NDA: executive summary and full technical report in one document, rules of engagement, a severity heat-map, per-finding detail, and a phased remediation roadmap.
03
The JSON twin
The same assessment as structured JSON, so it lands in Vanta, Drata or Secureframe as evidence against a control rather than a PDF somebody has to re-key.
What a finding actually says.
No environment-tuned vector is ever fabricatedCompliance cross-map: SOC 2 · ISO 27001 · ISO 42001 · NIST AI RMF · NIST CSF 2.0 · EU AI Act. Stated as evidence toward a control — never as a pass.