Reports & compliance

Report profiles, audiences, coverage, sealed issuances and branding — how a finished pentest becomes a defensible deliverable.

What a report is

A report is a sealed deliverable for a finished pentest: methodology, confirmed findings, coverage and an integrity hash. You configure a profile once (account, team or pentest override), then generate. Generation happens on the streaming backend (generate_report); download happens from the REST API as a signed URL.

Profiles

A profile is one template plus overlays, not a stack of unrelated documents. Allowed values:

FieldValues
methodologywstg, asvs_l2, ptes, nist_800_115
compliance_overlayspci_dss_11_4, soc2, iso27001, dora
audienceexecutive, technical, attestation
default_formatspdf, html, markdown, docx, json
include_unvalidated_appendixboolean

audience and default_formats can be overridden on a single generate_report call without changing the stored profile. methodology cannot.

AudienceWhat it emphasizes
executiveRanking table first (KEV → EPSS → CVSS). No HTTP dumps, no coverage matrix, no unvalidated appendix.
technicalFull body of confirmed findings.
attestationSignable letter, integrity, methodology of false positives; detail in an annex.

Branding is a visual overlay (logo, colours, footer) on the same content. It does not change which findings appear. See Branding.

What goes in the body

  • Confirmed findings (validated or legacy) appear in the body and in the remediation ranking.
  • failed findings are omitted — they were refuted.
  • unvalidated, needs_manual_review and not_validatable go in an appendix when include_unvalidated_appendix is on (PDF/HTML/Markdown/DOCX list name and status; issued JSON keeps the full objects). They never rank above a confirmed KEV.

A pentest that was killed is watermarked as interrupted.

Coverage matrix

The report includes a coverage matrix for the methodology’s framework (WSTG, ASVS, PTES or NIST): controls the run attempted, found, excluded (including RoE exclusions that map to a control) or did not attempt. The denominator is a versioned catalog; the numerators are what this execution actually did. Unmapped RoE techniques are listed as exclusions, not invented cells.

Sealed issuances

Each generated format is an issued report: hashed (payload_sha256 over the canonical JSON, without signed URLs or internal comments), stored, then listed.

GET /pentests/{id}/reports
GET /pentests/{id}/reports/{reportId}

Download is a time-limited signed URL. The file never travels inline.

generate_report on the streaming backend emails the PDF only if the issuance sealed. If sealing fails, nothing is mailed.

SARIF is not a report format

pdf, html, markdown, docx and json are report formats. SARIF (and DefectDojo) are finding exports, not issuances. Use GET /pentests/{id}/vulnerabilities/export?format=sarif when a pipeline needs SARIF.

Go deeper