Reports

Reports your board will actually read.

The board wants a number and a direction. The engineers want rule IDs and evidence hashes. The customer's security questionnaire wants control statements. All three are the same scan, rendered differently, not three documents somebody assembles by hand the night before.

Templates
3
Export formats
4
Reads a specific scan
Point-in-time
Your branding
White-label
The output

One scan, three audiences.

Switch template and the document changes substantially, because a summary for a board and a finding table for an engineer are genuinely different documents, not one with a different cover page.

Export as
PDFHTMLCSVJSON
Vantage Rail
vantagerail.com · scan #4182 · 20 Aug 2026
PulseGuard
72
Security score
+9
Since last month
4.2d
Avg time to resolve
Open by severity
Critical1
High3
Medium6
Low2
What to do first
  1. 1. Revoke the payment key found in the public JavaScript bundle, then move the call server-side.
  2. 2. Renew the API certificate. It lapses in twelve days and the renewal job has not run since June.
  3. 3. Deploy the header policy that exists in staging but has never reached production.
Why it matters

The report is where the work becomes visible

Security work that nobody outside the team can read gets budgeted like work nobody outside the team can see.

Written for the reader

Every finding already carries a plain-language explanation and a business impact, because that requirement is enforced in the shape of a finding, not added at export time by a summariser.

Backed by stored evidence

A report is a read over immutable findings and their evidence rows, each with a content hash and the scanner version that produced it. Nothing in it is generated fresh at render time.

Point-in-time, reproducible

A report is generated from a specific scan, so regenerating last quarter's document produces last quarter's document, not today's data in an old wrapper.

Internal notes stay internal

Comments marked internal are excluded from client-facing output. The distinction is a field on the comment, so it can't be forgotten during an export.

Your branding on it

White-label configuration lives on the template, which is what makes this usable by an agency delivering to their own clients rather than only by the team that ran the scan.

Trends, not just today

Score movement, resolved counts, and average time to resolve come from history that was already being kept, so a report can show direction rather than a single snapshot.

What's in one

The pieces a report is assembled from

Each is a read of data that already exists. That's what makes generating one cheap enough to do whenever someone asks.

Score and trend

The overall security score with its movement since the previous scan, and per-category deltas underneath it.

scoredeltacategory

Findings by severity

Open findings grouped by severity and shown with priority, so the ordering in the document matches the ordering in the product.

severitypriorityScore

Evidence references

Content hashes, scanner version, and capture timestamps per finding. Secret values themselves stay redacted.

contentHashscannerVersion

Recommendations

Prioritised remediation steps drawn from each finding's own fix guidance, ordered by what would move the score most.

remediationfixExample
How it works

From a scan to a document

Report generation runs as its own low-priority job, so producing one never slows a scan down.

  1. 1

    Choose a scan and a template

    Reports are generated against a specific scan, not against 'now'. Picking an earlier one is how you reproduce what was true at the time rather than reconstructing it.

  2. 2

    The template decides the audience

    Executive, technical, and compliance templates read the same findings and render different documents: summary and direction, evidence and rule IDs, or control statements.

  3. 3

    Internal content is filtered out

    Comments marked internal are removed from client-facing templates as part of rendering, rather than relying on whoever generates the report to remember.

  4. 4

    It renders in the background

    Rendering runs as its own queued job at low priority, independent of scan queues, and requests carry an idempotency key so a retried click doesn't produce two documents.

  5. 5

    You download or fetch it

    Finished reports are stored as artifacts and retrievable through the dashboard or the API, in PDF, HTML, CSV, or JSON.

Reports, answered.

Yes. Scans, findings, and evidence are append-only, so a report generated against an earlier scan reproduces that point in time rather than re-rendering today's data in an old format.

Answer the questionnaire in an afternoon.

Run a scan, pick a template, and hand over a document backed by stored evidence.