Reports & compliance
Report profiles, audiences, coverage, sealed issuances and branding — how a finished pentest becomes a defensible deliverable.
What a report is
A report is a sealed deliverable for a finished pentest: methodology, confirmed findings, coverage and an integrity hash. You configure a profile once (account, team or pentest override), then generate. Generation happens on the streaming backend (generate_report); download happens from the REST API as a signed URL.
Profiles
A profile is one template plus overlays, not a stack of unrelated documents. Allowed values:
| Field | Values |
|---|---|
methodology | wstg, asvs_l2, ptes, nist_800_115 |
compliance_overlays | pci_dss_11_4, soc2, iso27001, dora |
audience | executive, technical, attestation |
default_formats | pdf, html, markdown, docx, json |
include_unvalidated_appendix | boolean |
audience and default_formats can be overridden on a single generate_report call without changing the stored profile. methodology cannot.
| Audience | What it emphasizes |
|---|---|
executive | Ranking table first (KEV → EPSS → CVSS). No HTTP dumps, no coverage matrix, no unvalidated appendix. |
technical | Full body of confirmed findings. |
attestation | Signable letter, integrity, methodology of false positives; detail in an annex. |
Branding is a visual overlay (logo, colours, footer) on the same content. It does not change which findings appear. See Branding.
What goes in the body
- Confirmed findings (
validatedorlegacy) appear in the body and in the remediation ranking. failedfindings are omitted — they were refuted.unvalidated,needs_manual_reviewandnot_validatablego in an appendix wheninclude_unvalidated_appendixis on (PDF/HTML/Markdown/DOCX list name and status; issued JSON keeps the full objects). They never rank above a confirmed KEV.
A pentest that was killed is watermarked as interrupted.
Coverage matrix
The report includes a coverage matrix for the methodology’s framework (WSTG, ASVS, PTES or NIST): controls the run attempted, found, excluded (including RoE exclusions that map to a control) or did not attempt. The denominator is a versioned catalog; the numerators are what this execution actually did. Unmapped RoE techniques are listed as exclusions, not invented cells.
Sealed issuances
Each generated format is an issued report: hashed (payload_sha256 over the canonical JSON, without signed URLs or internal comments), stored, then listed.
GET /pentests/{id}/reports
GET /pentests/{id}/reports/{reportId}
Download is a time-limited signed URL. The file never travels inline.
generate_report on the streaming backend emails the PDF only if the issuance sealed. If sealing fails, nothing is mailed.
SARIF is not a report format
pdf, html, markdown, docx and json are report formats. SARIF (and DefectDojo) are finding exports, not issuances. Use GET /pentests/{id}/vulnerabilities/export?format=sarif when a pipeline needs SARIF.