Skip to content

Pentest Reports

Browse and export reports from explicitly authorized, scoped dynamic engagements without confusing them with source scans.

A separate report workflowPermalink to A separate report workflow

Pentest Reports lets you review completed dynamic-engagement reports for your workspace. Use it to examine demonstrated findings, identify the assessed target and environment, and hand the authorized engagement's results to the responsible team.

Repository scanning is not automatically live pentesting

A Source Security Assessment reviews repository code. A Pentest Report describes a separate, explicitly authorized dynamic engagement. Running a repository scan, connecting a repository, or viewing this page does not start or authorize live testing.

This page is for browsing and exporting reports, not defining a target or launching a pentest. A report appears only when a completed authorized engagement report is available in the selected workspace. Do not infer that live testing is available for every repository or workspace from the presence of the report page.

Prerequisites and authorizationPermalink to Prerequisites and authorization

  • Have access to the workspace containing the completed engagement report.
  • Before any live testing, obtain explicit authorization covering the target and environment, permitted methods, and rate limits. Testing must remain within that agreed scope.
  • Use the report's engagement and authorization references to relate it to the agreed work. A report reference is not permission to test another target or expand the engagement.
  • Confirm that the recipient is authorized to receive the report. Arrange any additional testing or retest through the authorized engagement process, not by treating a report action as a launch control.

Find and open a reportPermalink to Find and open a report

  1. Open Pentest Reports

    Check the workspace. No Pentest Reports yet means no reports are available here, not that targets have been tested without findings.

  2. Search and filter

    Search by target label, engagement reference, report ID, or finding content. Filter by environment or finding severity, including reports with no demonstrated findings.

  3. Choose a useful order

    Sort by newest or oldest engagement, most findings, or target label. Filters operate on the loaded reports; reset them if the expected report is not visible.

  4. Open the report

    Check the target label, environment, engagement date, report creation date, and authorization reference before reading the findings.

Interpret demonstrated findingsPermalink to Interpret demonstrated findings

The report shows its target and rate-boundary statements, a severity summary, and demonstrated findings with their request method and path. Use these details to identify the affected behavior and prioritize remediation within the engagement's scope. Severity does not expand what was tested or establish impact beyond the reported evidence.

No demonstrated findings is a bounded result

An engagement with no demonstrated findings is not a guarantee of security or complete coverage. A Pentest Report is not, by itself, a pentest certification, a compliance certification, or proof that all systems and methods were tested.

Read the engagement scope and limitations with the finding count. Record follow-up work in your team's review process, and arrange any runtime reproduction or retest only with explicit authorization. Opening or exporting the report does not change a finding's remediation status.

Export the report for reviewPermalink to Export the report for review

Open the report and choose Export customer-safe JSON. The download contains the customer-facing report and its limitations. It is not a PDF or raw evidence archive, and it does not expose raw requests, responses, credentials, or full target URLs. Customer-safe does not mean public: share it only with the intended authorized recipients.

Check that the downloaded file belongs to the intended engagement. If the download fails, try again. If the report is unavailable or cannot be displayed, do not substitute an empty report; return to the list, retry, or contact support with the report and engagement references.