Риск, бизнес-эффект, три главных решения, остаточный риск и статус remediation.
// sample deliverables
Demo Pack
Посмотрите deliverable до звонка с продажами: executive summary для руководства, technical findings для инженерной команды и JSON export для автоматизации.
Roadmap на 7/30 дней, владельцы, SLA, affected assets и критерии ретеста.
Evidence, request/response trace, attack path, standards mapping и JSON export.
Scope, rules of engagement, data handling, AI privacy и verified-only guardrails.
// evidence fields
Что внутри отчета
report_id
client
scope
test_window
target
verification_method
methodology_refs
finding_id
title
severity
cvss
cwe
affected_asset
endpoint_or_vector
exploitability
impact
reproduction_steps
request_response_or_trace
screenshots_or_video_refs
attack_path_or_attck_mapping
remediation
owner
sla_due
retest_status
audit_events
appendix_refs
// sample finding
Missing SPF/DMARC policy
Severitymedium
Ownersecurity
SLA2026-07-13
Retestpending
Brand abuse, phishing and reduced mail trust.
dig TXT example.com; dig TXT _dmarc.example.com