Who This Topic Is For
Users who need to interpret, share, and operationalize vulnerability findings.
Use report outputs to prioritize remediation, communicate findings, and maintain repeatable review quality.
Users who need to interpret, share, and operationalize vulnerability findings.
Use this checklist to make sure the workflow guidance applies cleanly to your current task.
Use this section to set the right outcome before you start the workflow.
Credit-scan reports include a security score. Penetration Test and Comprehensive Pentest HTML and PDF use do-this-week lists and color-coded severity instead of a 0-100 circle.
Team and Enterprise agencies use Copy client link so the recipient opens a branded /r/ view for 14 days. Clients do not log in. Free and Pro keep Vulnify branding.
A dashboard URL, a generated artifact, a public-safe /report/ page, and a branded /r/ client link have different access and lifetime. Confirm which one you are sending.
Follow these steps in order for a reliable and repeatable outcome.
Start with critical and high-signal issues before lower-priority hardening opportunities.
Pair what was observed with the recommended corrective action so fix plans stay concrete and auditable.
Use the output that matches the workflow: in-app views for private review, HTML/PDF/JSON artifacts when they are generated, copied URLs when a route or artifact needs to be referenced, and supported public-safe pages only when that workflow is intentionally used.
API spec scans now follow the same stored-report pattern, so imported-spec findings can be reviewed later from scan history rather than being treated as throwaway output. Team and Enterprise agencies should use Copy client link for a branded /r/ view rather than forwarding a dashboard URL.
See White-Label Reports documentation for logo, overlay, and expiry behavior.
Dashboard credit scans use a security score.
Penetration Test and Comprehensive Pentest reports do not: there is no 0-100 score circle and no PCI, SOC 2, or ISO badge. Use the do-this-week list, numbered remediation, and color-coded severity (Critical red, High orange, Medium amber).
Comprehensive adds an attack-surface appendix, authorization matrix, a detailed, actionable PDF for security specialists and developers, and an auditor-ready evidence pack that is not a certificate.
Revalidate after fixes and compare outcomes so score movement and finding closure can be verified.
These scenarios show how the workflow looks in practice, including the result you should see.
Engineering opens the saved scan, sorts Critical then High, assigns owners, and exports PDF for the weekly risk meeting.
After branding is saved, Copy client link asks for Prepared for and engagement title. The agency pastes Acme Retail and Q3 checkout review, then emails the client.
A buyer expected a 0-100 circle on the $297 report. The PDF uses severity colors and a do-this-week list. They use the included retest from the pentest workspace, not a credit rescan, to prove closure.
Use this checklist to confirm the workflow was completed correctly.
If something does not match expectation, check these common failure modes first.
Before sharing externally, summarize highest-priority findings and remediation status so reports remain actionable.
A copied URL can point to an app view, a temporary report artifact, or a public-safe route depending on the workflow. Confirm what the recipient is meant to open before distributing it.
Always rerun after remediation to verify closure and avoid reporting assumptions.
API spec scans are saved in account history and can generate stored report artifacts. Review the result from scan history when you need to share or compare the imported-spec workflow later.
Use these links to continue your workflow without losing context.
Open Scans And Depths to continue this workflow.
Open Help: Reports And Sharing to continue this workflow.
Open Premium Assessments to continue this workflow.
Open Tools And Guides to continue this workflow.
Open How to Fix Missing Security Headers to continue this workflow.
Open White-Label Reports to continue this workflow.
Common questions for this topic.
No. Reports can be used by technical and decision stakeholders when paired with clear remediation context and risk prioritization.
Continue to the best next page based on where you are in your workflow.