What a report looks like.
You see the results in the console in the customer area and as a PDF report. The sample report shows a fictitious company with the domain example.com and typical findings.

PDF, approx. 250 KB, opens in a new tab
The demo console
In the customer area you don't work with PDFs but with the console: all findings from all services, filterable by service, severity and status. The demo console shows this with sample data, no sign-in needed.
Open demo consoleWhat the report contains
Summary
Time, scope and number of systems checked. Plus the exposure score: the average priority of all findings from 0 to 100. Lower is better.
Most important first
The five findings you should tackle first, with the affected system and a concrete recommendation.
All findings per system
Every host with its findings, sorted by priority. Systems without findings are listed as well.
Methodology
Which sources and testing methods were used, so that auditors can follow the approach.
Reports for management and evidence
- Management report: development of findings over 30, 90 or 365 days, remediation times and open risks in a form management can follow
- NIS2 evidence report: mapping of results to Art. 21 NIS2, inventory of the systems checked, remediation times against targets, audit log and accepted risks with justification
- All reports in German, English, Spanish, Portuguese or French, in the Professional plan with your company logo
- In the Professional plan also CSV export and an API for your own analyses
Excerpt from the sample data
This is how findings appear in the console: priority, severity, affected system and status.
| Prio | Finding | Asset | Severity |
|---|---|---|---|
| 100 | Apache Log4j remote code execution (Log4Shell)EXPLOITED | srv-web-01 | Critical |
| 94 | Citrix NetScaler session token leak (Citrix Bleed)EXPLOITED | vpn.example.com | Critical |
| 88 | Legacy authentication not blocked by conditional accessEXPLOITED | entra:tenant | High |
| 81 | OpenSSH signal handler race condition (regreSSHion)EXPLOITED | srv-db-02 | High |
| 74 | SQL injection in search parameter | shop.example.com | Critical |
| 65 | S3 bucket publicly readable | aws:prod-account | High |
What does your attack surface look like?
We scan your external attack surface for free and walk you through the results in 30 minutes.