Reports
Issue signed technical, executive summary and retest reports for a scan, in PDF, CSV, JSON and SARIF, and share them.
Issuing a report
Reports are issued on request, not after every scan.
- Go to Reports → New report, or choose Issue a report on a finished scan.
- Choose the scan and the kind of report. You can map findings to a framework. This is a mapping for your readiness work, not a certification.
- LaunchSafe generates the files and signs them, usually within a minute. The report's page then opens it.
Kinds of report
| Report | For | Contains | Files |
|---|---|---|---|
| Technical | Your own team | Scope, method and limits, coverage, what was not tested, every finding with its location, evidence summary, impact, fix, pull request and retest | PDF, CSV, JSON, SARIF |
| Executive summary | Founders, boards, buyers | Headline, counts by severity, retests, scope and coverage, what was not tested, open findings by category with fix-by dates, at most two pages. No exploit detail | PDF, CSV, JSON |
| Retest | Buyers, auditors | The result of each retest since the test: fixed, still present, or not checked with the reason | PDF, CSV, JSON |
A shareable report names a finding that is still open only by its category, never by its location.
What a report says honestly
- It names the areas the scan covered, and what it did not test.
- Accepted risks and false positives are never counted as open.
- The organization's name is shown as you typed it and marked not verified. What LaunchSafe verified (the code host account and repository) is shown separately.
- Secrets and personal data are masked before anything is stored or signed.
- Every report says LaunchSafe is not an auditor. It is evidence for your review.
Versions and withdrawing
Issue a new version makes a report from today's findings, fixes and retests. The version it replaces is marked superseded but stays downloadable and verifiable.
Owners and admins can withdraw a report, with a recent sign-in. The public verify page then says it was withdrawn. The reason is not shown publicly, and withdrawing cannot be undone.
Checking a report
Every report has a verify ID and a signature. Anyone can check a file without an account. See signed reports and the verify page.
Limits
A report is refused with a reason if the scan has not finished, was a retest scan, or recorded no coverage. An organization can have 3 reports generating at once and request 50 in 24 hours.
For sharing with one buyer or auditor, see Settings → Share rooms and Settings → Security page.