Report
A Report is a PDF deliverable from a completed Assessment. Each report presents the assessment's findings, evidence, and remediation recommendations as a shareable document suitable for stakeholders, compliance packages, and executive review.
Code-audit reports may include a tailored conclusion written after the complete finding set is known. It explains the overall exposure, business consequences, sound controls, and priorities in language suitable for company leadership. Reports omit the section when no conclusion was produced.
What's in a report
A typical AISafe report includes:
- Executive summary. High-level overview of the assessment scope, finding counts by severity, and overall security posture
- Assessment metadata. Target/source, assessment type, duration, and date range
- Finding details. Per-finding sections with severity, graphical taint flows, syntax-highlighted impacted code, HTTP captures, proof-of-concept, and suggested fixes
- Remediation recommendations. Prioritized action items by severity
- Fix Verification. When source verification exists, the exact submitted revision, source provenance, full or partial coverage, fixed and still-open counts, stale findings, and per-finding justifications. This section states that AISafe verified source, not deployment.
Review history stays in the AISafe product audit trail and is not included in the customer PDF.
Generating reports
You generate reports from the assessment detail page after an assessment completes. Click Generate report to produce a PDF. AISafe stores the report as an artifact, and you can download or share it via a URL. Report generation consumes a small number of credits.
Sharing reports
Once a report is ready, AISafe notifies you so you can deliver the report to a Slack channel, SIEM, or internal document system. You can also share the report URL directly with stakeholders.