FeatureCompliance & Remediation

Enterprise Reporting

Professional-grade PDF penetration test reports with compliance mapping against 14 frameworks. Executive summaries, CVSS v3.1 scoring, attack graphs, and actionable remediation guidance — generated automatically after every scan.

penetration-test-report.pdf 2.4 MB
Executive SummaryCVSS v3.1
3
Critical
7
High
12
Medium
example.com 2026-07-17 14 frameworks
14
Compliance Frameworks
60s
Report Generation
PDF
SARIF · HTML · JSON
7
Remediation Languages
Capabilities

Audit-ready reports. Automatically generated.

PDF Reports

PDF

Professional-grade PDF penetration test reports with executive summary, severity cards, CVSS v3.1 scores, and remediation priorities.

Compliance Mapping

Compliance

Every finding mapped to 14 compliance frameworks — SOC 2, ISO 27001, PCI DSS, GDPR, HIPAA, and more — with cross-reference tables.

SARIF Output

SARIF

Standard SARIF output for integration with GitHub Advanced Security, GitLab SAST, and any SARIF-compatible code scanning tool.

Auto-Remediation

Remediation

PR-ready code fix snippets for 6 vulnerability types across 7 programming languages — SQLi, XSS, CSRF, SSRF, IDOR, RCE.

Attack Graphs

Visualization

Visual attack path graphs showing how findings chain together — from initial recon through exploitation and lateral movement.

Executive Dashboard

Dashboard

Role-based dashboards for executives, security teams, and developers — tailored views with relevant metrics and drill-downs.

Frameworks

14 compliance frameworks, one report

Every finding automatically mapped to relevant compliance controls across all major frameworks. Generate a single report that satisfies multiple audits.

SOC 2 Type IIISO/IEC 27001NIST SP 800-53NIST CSF 2.0NIST 800-171PCI DSS v4.0GDPRHIPAACMMCEU DORANIS 2 DirectiveTISAXEU AI ActACSC Essential Eight
Process

From raw findings to audit-ready reports

01

Aggregate

All findings from across the attack lifecycle — recon, vulnerability scanning, exploitation, and post-exploitation — are gathered into a unified findings database.

02

Map

Each finding is automatically mapped to relevant CVEs, CWEs, and compliance controls across 14 frameworks. AI-assisted mapping ensures accuracy and completeness.

03

Generate

Reports are generated in PDF, SARIF, HTML, and JSON formats — each with executive summary, severity breakdown, CVSS scores, attack graphs, and remediation guidance.

04

Deliver

Reports are automatically delivered to configured destinations — email, Jira, Slack, SIEM, or CI/CD pipeline — with version tracking and historical comparison.

Report Formats
PDFSARIFHTMLJSONGraphML
Deep Dive

Reports that speak to every audience

PDF Reports

Professional-grade PDF reports suitable for auditors, executives, and security teams.

Executive summary with risk overview
Severity cards with CVSS v3.1 scores
Finding details with evidence and replay
Attack graph visualizations
Compliance cross-reference tables
Remediation priorities and guidance

Compliance Mapping

Every finding mapped to 14 compliance frameworks with cross-references.

SOC 2 Type II control mapping
ISO/IEC 27001 Annex A mapping
PCI DSS v4.0 requirement mapping
GDPR article cross-reference
HIPAA security rule mapping
NIST SP 800-53 / CSF 2.0 mapping

Auto-Remediation

PR-ready code fixes generated automatically for every confirmed finding.

SQLi fix snippets (Python, Java, Go, Node, C#, PHP, Ruby)
XSS remediation with context-aware encoding
CSRF token implementation guidance
SSRF URL validation patterns
IDOR authorization check patterns
RCE input sanitization libraries

CI/CD Integration

Reports integrated directly into your development workflow.

GitHub Advanced Security SARIF upload
GitLab SAST report integration
PR comments with severity breakdown
Auto-remediation PR creation
Webhook notifications on new findings
Regression reports with trend analysis
Integrations

Reports where you need them

GitHub Advanced SecurityGitLab SASTJiraServiceNowSlackEmailSplunkElasticsearchGrafanaDatadogSARIFPDFHTMLJSON
Get Started

Audit-ready reports in under a minute

From scan completion to an audit-ready PDF report in under 60 seconds. Support for 14 compliance frameworks and 5 output formats.