Sample Reports
SOC 2 & ISO 27001-Ready Sample Penetration Testing Reports
See exactly what you get before you engage.
Every report we deliver includes an executive summary for leadership, CVSS-scored technical findings with reproduction steps, developer-ready remediation guidance, and compliance mapping for SOC 2, PCI DSS, HIPAA, ISO 27001, and GDPR — not a scanner dump, not a generic template.
Browse sample reports by engagement type below.
Download a sample report for your stack
Real engagements. All credentials, PII, and client-identifying details sanitised before publication.
Available now
Web Application & API / SaaS Penetration Test
A combined web application and SaaS/API assessment covering SQL Injection, XSS, CSRF, session fixation, BOLA, broken function-level authorization, token non-invalidation, mass assignment, and more.
Coming soon
Web Application Penetration Test
Standalone web application assessment — auth flows, broken access control, injection vulnerabilities, and business logic flaws with validated proof-of-exploit.
Coming soon
API Penetration Test
REST and GraphQL tested for BOLA, BFLA, JWT/OAuth weaknesses, rate-limit bypass, and mass assignment — mapped to the OWASP API Security Top 10 (2023).
Coming soon
Mobile App Penetration Test
iOS and Android: insecure data storage, weak transport security, and certificate pinning gaps via static and dynamic analysis.
Coming soon
Cloud Penetration Test
AWS, Azure, or GCP: misconfigured storage, IAM privilege escalation paths, and exposed services.
Coming soon
Network Penetration Test
External attack surface mapping plus internal lateral-movement simulation from a compromised endpoint.
Not sure which report matches your stack? Book a free 30-minute scoping call and we’ll walk you through it.
Why our reports hold up under audit scrutiny
Report quality that scales from your dev team to your board to your auditor — in a single document.
| Feature | Automated Scanner | Typical Pentest | Pentest Testing Corp |
|---|---|---|---|
| Manual exploitation of every finding | ✗ | Sometimes | ✅ Always |
| False positives filtered out | ✗ | Sometimes | ✅ Always |
| CVSS v3.1 score per finding | Partial | Sometimes | ✅ Always |
| Reproduction steps (sanitised) | ✗ | Sometimes | ✅ Always |
| Developer-ready remediation guidance | ✗ | Sometimes | ✅ Always |
| Compliance mapping (SOC 2 / PCI / HIPAA) | ✗ | Rarely | ✅ Always |
| Executive summary for board / CISO | ✗ | Sometimes | ✅ Always |
| Retest closure evidence | ✗ | Rarely | ✅ Always |
| Encrypted evidence package | ✗ | Rarely | ✅ Always |
Report formats your auditor will accept
Our reports are structured to serve as direct audit evidence. We’ve been through this process hundreds of times — the format is designed to pass vendor security reviews without a second request.
Frequently asked questions about our reports
What information is included in your reports?
Every report includes an executive summary, scope and methodology documentation, a consolidated findings table, detailed per-finding write-ups (description, evidence, reproduction steps, remediation guidance), a CVSS and OWASP mapping table, a prioritised remediation roadmap, a retest status tracker, and relevant appendices — OWASP reference tables, SOC 2 TSC mappings, and a tested endpoint inventory.
Are the sample reports from real engagements?
Yes. Our samples are based on real penetration test engagements. All live credentials, personally identifiable information, client-identifying details, and customer data are sanitised before publication. The findings, severity ratings, reproduction steps, and remediation guidance reflect what was actually discovered and documented.
How are findings prioritised in the report?
Each finding is assigned a CVSS v3.1 score and a corresponding severity label (Critical, High, Medium, Low, or Informational). The remediation roadmap groups findings into time-based action tracks: Immediate (0–7 days) for actively exploitable vulnerabilities, Short Term (1–4 weeks) for high-impact issues requiring architecture changes, and Medium Term (1–3 months) for process and configuration improvements.
Can your reports be submitted directly to auditors?
Yes. Our reports are structured with SOC 2, PCI DSS, HIPAA, ISO 27001, and GDPR mapping built in. We have delivered reports that passed SOC 2 Type II audits, PCI DSS QSA reviews, and enterprise vendor security assessments without requiring supplementary documentation. A Letter of Attestation can also be issued separately if your auditor requires it.
What format are reports delivered in?
Reports are delivered as password-protected PDFs. A separate encrypted archive contains raw evidence: Burp Suite request/response captures, screenshots, and tool output. All test data is destroyed or returned to the client upon engagement completion.
Can I request a sample for a specific technology stack?
Yes. If none of the published samples match your environment — say, a GraphQL API sample, a mobile app sample, or a cloud infrastructure sample — contact us and we’ll share the most relevant example under NDA.
Do you offer a retest after findings are remediated?
Yes. Every engagement includes the option of a formal retest once critical and high findings are remediated. The retest confirms fixes are correctly implemented and produces a retest closure letter suitable for auditor submission. Retest scope and pricing are confirmed at the time of the original engagement.
Ready to commission your own report?
Share your scope – URLs, API endpoints, IP ranges, or app bundle identifiers, and we’ll respond within one business day with a fixed-price quote and a proposed timeline.
NDA available on request · Fixed-price engagements · Compliance-ready reporting · Production-safe testing