Pen TestingCloud PostureShadow-AI discoveryCI/CDContinuous PlatformReportsIdentity & accessAgent Trust Fabric
Reports

Three deliverables from one scan.

Every completed scan produces a professional, honest-by-construction report grounded in PTES, NIST SP 800-115, OWASP WSTG, CREST and CVSS — because the people who need proof that you tested are rarely the people allowed to see how we broke in.

Start a scan Read the docs
3 tiers
attestation letter, full report, machine-readable twin
6 frameworks
in the compliance cross-map, plus the EU AI Act
CREST / OSCP
certified human reviewer signs off the report — available on any scan
Attestation GET /api/runs/<id>/attestation · owner or admin
Letter of Attestation — redacted by construction
Legal name, provider and signature, dates, summary scope, methodology and severity counts. Never a PoC, never an endpoint, never per-finding detail.
What it carries
Legal entity and provider signature included
Test window and assessment type included
Severity counts included
Proof of concept, endpoints, finding detail excluded
Machine-readable twin
GET /api/runs/<id>/compliance.json
→ Vanta · Drata · Secureframe
evidence against a control, never a pass
Send it into a TPRM review without an NDA round-trip No exploit detail
One scan, three audiences

The same assessment, redacted to the reader.

Tier 1
Letter of Attestation
procurement · TPRM · customers
Tier 2
Full compliance report
engineering · auditors under NDA
Tier 3
JSON twin
Vanta · Drata · Secureframe

The dark bar is not a design flourish — the attestation letter genuinely omits the PoC, the endpoints and every per-finding detail, so it can leave your building.

Who each deliverable is for
01
Letter of Attestation
For downstream customers, procurement and third-party risk. Redacted and signed, with no exploit detail whatsoever — so it moves without a redaction pass.
02
The full compliance report
For engineering and auditors under NDA: executive summary and full technical report in one document, rules of engagement, a severity heat-map, per-finding detail, and a phased remediation roadmap.
03
The JSON twin
The same assessment as structured JSON, so it lands in Vanta, Drata or Secureframe as evidence against a control rather than a PDF somebody has to re-key.

What a finding actually says.

No environment-tuned vector is ever fabricated
Field
What it states
CVSS
A real advisory score for dependency CVEs; otherwise the CVSS-B class base vector by CWE, with the score computed from it and labeled class base. Behavioral findings are severity-rated.
Attack Success Rate
successes/trials when measured — otherwise "single observation (not statistically sampled)".
Reproduction context
Timestamp and target, plus model, sampling and RAG state once the engine records them.
Traceability
Finding → OWASP LLM Top 10 (2025) → MITRE ATLAS → NIST AI RMF, ISO 42001, EU AI Act Art. 15.
Human review
Named only when a human actually reviewed. Otherwise the report states "human review not performed."

Compliance cross-map: SOC 2 · ISO 27001 · ISO 42001 · NIST AI RMF · NIST CSF 2.0 · EU AI Act. Stated as evidence toward a control — never as a pass.

Evidence your auditor and your customer can both accept.

See a sample report