Who can use this feature
Available as an Add-On for all plans. Contact your CSM to know more.
After every Full Pentest, Scrut generates two reports: a Preliminary Report and a Final Report. Both are audit-ready and can be shared with auditors, enterprise customers, and compliance teams.
Preliminary Report vs. Final Report
The Preliminary Report is generated as soon as all findings from the assessment are published. It reflects the assessment scope and findings as of that date, regardless of remediation progress.
The Final Report is generated after you complete remediation and request it. It reflects the full outcome of the engagement: what was found, what was fixed, and what was accepted or closed.
Pro Tip!
Use the Preliminary Report to meet time-sensitive compliance deadlines. Use the Final Report as your primary compliance submission.
What's in Each Report
Both reports follow the same structure. The Final Report includes additional sections covering remediation outcomes and manual testing evidence.
1. Executive Summary
A one-page snapshot of the entire engagement. Includes the assessment objective, scope, scan date, finding counts by severity (Critical, High, Medium, Low), overall risk rating, and recommended next steps.
The Final Report also includes a Key Findings table with every vulnerability mapped to its OWASP Top 10 category, severity, and re-test status, and a Vulnerability Graph showing the distribution of finding statuses.
Who is it for: Leadership, auditors, and compliance teams who need a high-level view of the assessment outcome without reading the full report.
2. Engagement Overview
Documents the scope boundary and the responsible parties for the engagement. Lists all in-scope application URLs and defines the roles of the application owner, Scrut Automation, and the Scrut Support team.
Pro Tip: Check this section first. Verify that all your target URLs are listed. If a URL is missing, it is not covered by this report.
3. Approach and Methodology
Explains how testing was conducted. In the Preliminary Report, this covers the testing technique, scan mode, scan type (authenticated or unauthenticated), tools used, and the ruleset categories applied.
In the Final Report, this section documents the full two-phase methodology: a passive reconnaissance phase followed by an active testing phase covering authentication, authorization, session management, input validation, business logic, cryptography, and client-side testing.
4. Vulnerability Scoring Criteria
Defines what each severity level means so any stakeholder can interpret findings without additional context.

Important: Do not adjust severity ratings without consulting your Scrut Security Expert. Downgrading severity without verification can compromise the accuracy of your audit evidence.
5. Summary of Findings
An organized overview of all findings by status.
Open: Active findings awaiting remediation, listed with severity and number of affected resources.
Risk Accepted: Findings formally logged as risks and tracked in your risk register.
Ignored: Findings your team has reviewed and determined as not applicable, with documented justification.
6. Detailed Findings and Remediations
The full technical record of every confirmed vulnerability.
In the Preliminary Report, each finding includes the vulnerability name, severity, number of affected resources, a description of the issue, and specific remediation guidance.
In the Final Report, each finding also includes:
Re-test Status: Whether the finding was fixed, ignored, or classified as a risk-accepted item.
Impact: What an attacker could achieve by exploiting the vulnerability.
Steps to Reproduce: The exact sequence used to reproduce the finding, written for your engineering team.
Proof of Concept: Screenshots or request and response captures showing the vulnerability in action. References: Links to relevant OWASP documentation for further reading.
Pro Tip!
Share this section with your engineering or DevSecOps team. The Steps to Reproduce and Proof of Concept entries are the most actionable inputs for developers implementing fixes.
7. Conclusions and Next Steps
Summarizes the overall risk posture of the application and recommends a remediation timeline.
The Preliminary Report conclusions recommend a remediation cadence based on the severity distribution of open findings.
The Final Report conclusions confirm the state of all findings at the close of the engagement and reflect the security posture after remediation.
8. Tools Used (Final Report only)
Lists the commercial and open-source tools used during the manual pentest phase. This section is referenced by auditors evaluating whether professional-grade tooling was used.
Heads Up!
Both reports are confidential and contain sensitive technical information. Limit distribution to internal security, engineering, and compliance stakeholders.
Reach out to support@scrut.io or contact your CSM for further assistance.