Report
A Report is a PDF deliverable from a completed Assessment. Each report presents the assessment's findings, evidence, and remediation recommendations as a shareable document suitable for stakeholders, compliance packages, and executive review.
Code-audit reports may include a tailored conclusion written after the complete finding set is known. It explains the overall exposure, business consequences, sound controls, and priorities in language suitable for company leadership. If no conclusion was produced, the report leaves this section out.
What's in a report
A typical AISafe report includes:
- Executive summary. High-level overview of the assessment scope, finding counts by severity, and overall security posture
- Assessment metadata. Target/source, assessment type, duration, and date range
- Finding details. Per-finding sections with severity, graphical taint flows, syntax-highlighted impacted code, HTTP captures, proof-of-concept, and suggested fixes
- Coverage. For a code audit, the methodology checklist with an answer for every check: tested here, already answered by other work in the run, not applicable to this application with the reason, or out of reach because the check needs a running system. See Coverage
- Remediation recommendations. Prioritized action items by severity
- Fix Verification. When source verification exists, the exact submitted revision, source provenance, full or partial coverage, fixed and still-open counts, stale findings, and per-finding justifications. This section states that AISafe verified the source and did not verify the deployment.
For an application with several repositories, source metadata lists each saved repository, ref, commit, and evidence path prefix. Regenerating a report uses the source that the assessment audited, so later project changes do not rewrite its history. Historical unknown commits and assessment-local changes are marked explicitly.
The Artifacts → Overview → Source read card also lists each audited repository, its saved reference and its commit. These values describe the source read by the assessment, even if a branch has since moved. A commit that was not recorded appears as Unavailable.
Review history stays in the AISafe product audit trail and is not included in the customer PDF.
Artifacts → Methodology shows, for each checklist pack, the checks the audit tested or analyzed. The report's coverage section is the full answer sheet, with every check and the reason for each inapplicable one.
Generating reports
You generate reports from the assessment detail page after an assessment completes. Click Generate report to produce a PDF. AISafe stores the report as an artifact, and you can download or share it via a URL. Report generation consumes a small number of credits.
If generation fails, the assessment and Reports pages keep the failed report visible and offer Retry generation. Internal rendering errors are not shown in the customer response.
Sharing reports
Once a report is ready, AISafe notifies you so you can deliver the report to a Slack channel, SIEM, or internal document system. You can also share the report URL directly with stakeholders.