Reports

Issue signed technical, executive summary and retest reports for a scan, in PDF, CSV, JSON and SARIF, and share them.

Edit on GitHub

Issuing a report

Reports are issued on request, not after every scan.

  1. Go to Reports → New report, or choose Issue a report on a finished scan.
  2. Choose the scan and the kind of report. You can map findings to a framework. This is a mapping for your readiness work, not a certification.
  3. LaunchSafe generates the files and signs them, usually within a minute. The report's page then opens it.

Kinds of report

ReportForContainsFiles
TechnicalYour own teamScope, method and limits, coverage, what was not tested, every finding with its location, evidence summary, impact, fix, pull request and retestPDF, CSV, JSON, SARIF
Executive summaryFounders, boards, buyersHeadline, counts by severity, retests, scope and coverage, what was not tested, open findings by category with fix-by dates, at most two pages. No exploit detailPDF, CSV, JSON
RetestBuyers, auditorsThe result of each retest since the test: fixed, still present, or not checked with the reasonPDF, CSV, JSON

A shareable report names a finding that is still open only by its category, never by its location.

What a report says honestly

  • It names the areas the scan covered, and what it did not test.
  • Accepted risks and false positives are never counted as open.
  • The organization's name is shown as you typed it and marked not verified. What LaunchSafe verified (the code host account and repository) is shown separately.
  • Secrets and personal data are masked before anything is stored or signed.
  • Every report says LaunchSafe is not an auditor. It is evidence for your review.

Versions and withdrawing

Issue a new version makes a report from today's findings, fixes and retests. The version it replaces is marked superseded but stays downloadable and verifiable.

Owners and admins can withdraw a report, with a recent sign-in. The public verify page then says it was withdrawn. The reason is not shown publicly, and withdrawing cannot be undone.

Checking a report

Every report has a verify ID and a signature. Anyone can check a file without an account. See signed reports and the verify page.

Limits

A report is refused with a reason if the scan has not finished, was a retest scan, or recorded no coverage. An organization can have 3 reports generating at once and request 50 in 24 hours.

For sharing with one buyer or auditor, see Settings → Share rooms and Settings → Security page.

On this page