Skip to main content

Reports Overview

This is the step where you export analysis results as documents to share with stakeholders or hand off to other systems. Use them for reporting, audits, and customer responses.

Reports you can produce

  • Service security report (PDF) : a PDF that organizes a service's analysis results around severity and remediation priority. What it contains depends on the service type (see the table below).
  • Organization-wide combined report : bundles multiple services into one to summarize the organization's overall security posture. Use it for executive reporting or regular security reviews.
  • Infrastructure check reports : infrastructure checks for servers and hosts (K8s / CIS / hardening) do not have separate per-bucket download buttons the way SAST, SCA, and DAST do. Instead, you export a given bucket through the organization-wide combined report by selecting the specific type and section.
Report export screenReport export screen

Report contents by service type

You produce reports from the same [Service] screen, but what they contain varies by service type.

Service typeAnalyses included in the reportSBOMVEX
Source codeSAST · SCA · Secrets · IaCOO
Container imageImage SCA · HardeningOO
Web service (DAST)Dynamic vulnerability check-O
Server · HostOS vulnerabilities (SCA) · Infrastructure checks (K8s/CIS/hardening) · RuntimeOO
SBOM uploadComponent SCA · LicenseOO
  • SBOM can be exported for most types where components are known. Web services (DAST) are excluded because external dynamic checks have no component list.
  • VEX exports the triage results of vulnerabilities with a mapped CVE as a standard document. Regardless of type, any CVE-based items make it eligible.

Two standard exports

Besides PDF reports, we provide two artifacts for exchanging with other systems and stakeholders in standard formats.