A real report, redacted. So you know what you'll ship to your auditor.
This is the executive summary, finding structure, and evidence format you get from a SecureBlock engagement — company details replaced with a fictional "Acme" scope.
Acme Corp — web application & API assessment
SecureBlock conducted a manual penetration test of the Acme web application and API between August 17 and August 28, 2026. Testing followed OWASP WSTG and PTES methodology, performed by an OSCP + OSWE certified lead tester with a second reviewer validating all findings.
Fifteen findings were identified: one critical, three high, five medium, four low, and two informational. The critical finding — unauthenticated cross-tenant data export — was disclosed within the same business hour it was found and remediated during the engagement window. Overall security posture is moderate; the authorization model needs systematic review, but the codebase shows evidence of a mature security development practice.
