Report
What the report contains
Every weakness found, every CVE tested, our own pentesting methodologies and a record of what we did.
01 · Findings
Every weakness found, classified by CWE
Each finding is mapped to a CWE (Common Weakness Enumeration) and rated for severity. The report lists every CWE that occurred and the number of findings per CWE.
- CWE ID and name for every finding
- Severity rating
- Evidence and reproduction steps
- Remediation advice
02 · Known vulnerabilities
Every CVE tested
In a whitebox run we scan your codebase and its dependencies for known CVEs. The report lists all of them, not only the hits: the component and version, and whether it is affected, present but not reachable, or not affected.
- The complete list of CVEs tested
- Component, version and reachability per CVE
- Result per CVE
- Exploitation evidence for every confirmed one
03 · Methodology and coverage
What else we did
The report records what was done: the areas and techniques covered, the tools and model versions used, when testing took place and what was not tested.
- Our own pentesting methodologies
- Areas and techniques covered
- Tools, model versions and test window
- Areas not tested
- Discarded candidates with reasoning
Sample report
Request the sample report
You first receive a confirmation email. The download link follows after you confirm.
- No disclosure of your data to third parties.
- No newsletter unless you tick it.
- Unsubscribe at any time via the link in every email.
Details on processing are in the privacy policy.
Book an intro call
30 minutes, non-binding. We clarify scope, test mode and price.
- No test without written authorization and a defined scope.
- Source code and test data never go to cloud AI providers.
- Every finding is verified by a person before delivery.