Sample report
This is a genuine report produced by running the audit against one of our own internal projects, then sanitised for publication. It is a demonstration, not a client engagement.
What “sanitised” means here: file paths, exploitable specifics and internal architecture detail are removed or generalised. The verdict, score, category breakdown and the shape of each finding are real outputs of the same pipeline your audit would use. We have not fabricated a client, a testimonial, or a result.
The verdict page
Conditionally ready96.7/ 100 readiness score0 unresolved launch blockers
Note what the score does not do here: it does not buy a pass. Unresolved blockers cap the verdict regardless of how the rest of the categories score.
The scorecard
| Category | Score | Notes |
|---|---|---|
| Security and secrets | 96/100 | Open findings: 1 low. |
| Authentication and authorisation | 100/100 | No open findings in the executed checks. |
| Data integrity and tenant isolation | 100/100 | No open findings in the executed checks. |
| Reliability and failure handling | 100/100 | No open findings in the executed checks. |
| Deployment and configuration | 100/100 | No open findings in the executed checks. |
| Tests and release verification | 75/100 | Open findings: 1 high. |
| Payments and critical integrations | 100/100 | No open findings in the executed checks. |
| Privacy and data handling | 100/100 | No open findings in the executed checks. |
| Maintainability and architecture | 100/100 | Open findings: 1 informational. |
“Not inspected” scores zero and keeps its weight. We never award points for an area we did not look at, because that would let a thin audit look like a good result.
What was not checked
Every report carries this section. An audit that only tells you what it found, and never what it could not reach, is not giving you the information you need.