Export a single scan report
1
Open the scan run
Go to Tests, select the environment, and click on the scan run you want to export.
2
Export
On the run detail page, click Export.
3
Choose format
Choose PDF for a formatted report suitable for sharing with auditors, or JSON for integration with ticketing systems or security dashboards.
Export PR review findings
1
Open the PR run
Go to the Dashboard, select a repository, and click on a PR run to open its detail page.
2
Export
Click Export and select the format.
What the PDF report includes
- Scan date, target, and scope (permission tier)
- Overall risk score
- All findings with severity, location, description, and remediation
- Attack surface summary (endpoints discovered, tests run)
- Comparison with previous scan (new, resolved, persistent, regression)
Evidence of continuous testing for SOC 2
SOC 2 Type II requires evidence that security controls operated continuously over the audit period, not just at a point in time.Observability plan or higher is required for weekly scheduled scans, which produce the recurring timestamped reports auditors typically want.
- Enable weekly scheduled scans (Observability plan) — each scan produces a timestamped report
- Export monthly JSON findings dumps from the Dashboard for each repository
- The PR findings history shows security review was applied to every code change throughout the period