Reports & VEX
Export analysis results to share with stakeholders or deliver to other systems. You can turn risk that stayed only on screen into documents and use them directly for real communication such as reporting, audits, and customer response.
PDF reports
- Generate the security analysis results of each service as a PDF.
- Infrastructure checks provide reports by bucket (K8s / CIS / hardening).
- You can also create an organization-level unified report.

VEX (Vulnerability Exploitability eXchange)
VEX is a document that states, in a standard format, "whether this vulnerability is actually exploitable in our product".
- Export triage results (false positive / accepted risk, etc.) as OpenVEX or CycloneDX VEX (JSON).
- A PDF-format VEX is also provided.
- Only items with a mapped CVE are eligible, and the organization's triage state is converted into the VEX status.
Reduce noise with VEX
Telling a customer or auditor that "this CVE is not affected", along with the rationale, can reduce unnecessary inquiries and re-verification.