Reports

Report profiles, audiences, sealed multi-format issuances, branding and generate-and-email — how a finished pentest becomes a deliverable.

What a report is

A report is a sealed deliverable for a finished pentest: methodology, confirmed findings, coverage and an integrity hash. You configure a profile once (account, team, or a per-pentest override), then generate. Generation happens on the streaming backend; download is a time-limited signed URL from the REST API. The file never travels inline.

This page is the high-level surface. Field catalogs, hashes and HTTP are in the Reports API and the sealed reports recipe.

Profiles

A profile is one template plus overlays, not a stack of unrelated documents:

FieldValues
methodologywstg, asvs_l2, ptes, nist_800_115
compliance_overlayspci_dss_11_4, soc2, iso27001, dora
audienceexecutive, technical, attestation
default_formatspdf, html, markdown, docx, json
include_unvalidated_appendixboolean

audience and default_formats can be overridden on a single generation without changing the stored profile. methodology cannot.

A team can hold a default profile so every pentest it owns issues the same shape unless overridden. See Teams & RBAC.

Audiences

AudienceWhat it emphasizes
executiveRanking table first (KEV → EPSS → CVSS). No HTTP dumps, no coverage matrix, no unvalidated appendix.
technicalFull body of confirmed findings.
attestationSignable letter, integrity, methodology of false positives; detail in an annex.

Confirmed findings (validated or legacy) appear in the body. failed findings are omitted. Unvalidated / needs-review / not-validatable findings go in an appendix only when that flag is on. A pentest that was killed is watermarked as interrupted.

Sealed history

Each generated format is an issued report: hashed (payload_sha256 over the canonical JSON), stored, then listed. Download is a signed URL that expires. Rank emails the PDF only if the issuance sealed. If sealing fails, nothing is mailed.

SARIF (and DefectDojo) are finding exports, not report formats.

Branding

Branding is a visual overlay — company name, colours, logos, footer — on the same content. It does not change which findings appear. Configure it through the Branding API (personal on Ultra, team on Business/Enterprise). Branding is not part of the Python SDK.

Generate and email

From a completed pentest you generate against the effective profile. Pass formats and audience for that issuance if you need a one-off. extended=1 includes evidence detail. Recipients, subject and CC are optional extras on the same call.

Where to go next