Reports and artefacts
Two audiences without compromising either: engineers who need full reproduction detail, and buyers and assessors who need assurance without exploitable detail. Every artefact renders from the immutable evidence captured at the time, so regenerating a past report yields the same content.
Separately releasable. States what was tested, what was found and what is being done, with no detail that would assist an attacker.
Full reproduction steps and evidence for every confirmed finding, with attack paths and their business impact. Unconfirmed output is a separate appendix.
Owner, severity, target date and closure evidence for every tracked finding, with service-level breaches called out.
Evidence that remediated findings have been retested and confirmed closed. Remediated-but-unverified is reported as unverified.
A dated, point-in-time statement of scope, method and outcome. The artefact buyers ask for most often.
Generated artefacts
- Delivery is encrypted and access-limited: downloads are short-lived, single-object links, never a shared folder or an attachment.
- Every download is recorded in the tamper-evident audit trail, with the identity that requested it.
- Reports are stored and processed in Australia and follow a defined retention and destruction schedule.