← ALL DOCS

REPORTS & EXPORTS

Six export formats per scan, twelve compliance framework presets, and a per-target penetration test report. Every export includes what passed as well as what failed.

Per-scan exports

Open a scan and switch to the Report tab.

Export Contents Use it for
PDF Full assessment report with executive summary. Customers, auditors, due diligence.
PDF (anonymized) Same report with the target domain and emails redacted. Public sharing, investor decks, forums.
JSON Machine-readable findings. CI/CD gates, ticketing sync.
CSV ID, Title, Severity, CWE, OWASP, CVSS, Status, Target, Description. Spreadsheets, risk registers.
LLM export (Markdown) The report as Markdown for coding agents. Claude Code, Cursor, Lovable.
Copy for LLM Same Markdown, copied to the clipboard. Quick paste into a chat.

PDF exports open a print-ready branded page; use your browser’s print dialog to save as PDF.

Report structure

Header · Target, date, profile, risk score · Summary counts (Critical / High / Medium / Low / Passed) · Security Researcher Review and Out of scope (not covered) from the on-call pass · Issues table · Passed Checks table · footer.

Info-severity items and passed checks appear under Passed Checks, not Issues.

Anonymization rules

The anonymized PDF strips: the target host and all its subdomains, brand labels of five or more characters derived from the domain, every email address, and backend-as-a-service project identifiers (Supabase, Firebase). The filename gets an -anon suffix.

Compliance reports

Reports → New report lets you select one or more scans, a format (PDF, JSON, or Markdown), and a framework:

Pentest Reports · SLA Insights and Issues · ISO 27001:2022 · SOC 2 · OWASP Top 10 · CIS v8.1 Controls · CIS AWS Benchmark · NIS2 · NIST 800-53 · PCI DSS · HIPAA · DORA.

Clicking a framework card on the Reports page pre-selects it. A report shows generating and then completed; the list refreshes every three seconds meanwhile. Completed reports offer Markdown and PDF downloads.

Compliance mapping (OWASP Top 10, PCI-DSS, CWE) in the generated document is an Enterprise feature; other plans get the framework-structured report with findings only.

Pentest reports per target

The AI Pentests page aggregates scans by target and offers a Penetration Test Report download in Markdown or PDF per domain, covering issues found, endpoints tested, and the review notes across runs.

Full data export

Settings → Data → Request Full Export produces a ZIP with all scans, findings, team data, and settings. Large exports take a few minutes; you get an email with the download link.

Formal pentest engagements

For a scoped, human-led engagement with rules of engagement and a signed report your buyer or auditor will accept, see pentest services. Exports above are smoke-test outputs, not a substitute.

COMMON QUESTIONS

01
Can I share a report with investors without revealing the domain?
Yes. Export as PDF (anonymized) redacts the target host and its subdomains, brand names derived from the domain, all email addresses, and Supabase or Firebase project references.
Q&A
02
Which format should I feed into CI?
JSON. It carries every finding with id, severity, CWE, OWASP, CVSS, status, and evidence, and is stable enough to gate a pipeline on.
Q&A
03
Do reports include passed checks?
Yes. PDF and Markdown reports have a Passed Checks table listing the checks that ran and found nothing, so a reader sees coverage, not only failures.
Q&A

SEE IT ON YOUR OWN APP

Docs explain the product. A scan shows you what it finds on your deployed URL — keys, RLS, auth, and API gaps in under 60 seconds.

14-day free trial · No credit card · Cancel anytime

START FREE SCAN