Update: The Attestation Report Now States What We Did Not Prove
Posted in :
We have updated the attestation report template. The change is one section, and it is the section most reports do not have.
“What I have not proven yet”
Every report we sign now carries a dedicated section stating what was not tested, what was tested without result, and what we could not reach. Named, in the report, in the same document as the findings.
The reasoning is simple. A penetration test report is read as a statement about a system’s security, but it can only ever be a statement about what one team reached in a fixed window. Absence of a finding is not evidence of strength. If the report does not say so explicitly, the silence gets read as a clean bill of health, and that reading is the customer’s risk, created by our formatting.
What else is in the template
- Reproduction calls. For every confirmed finding: the exact request, the payload where one applies, the steps, and the confirming response.
- Remediation guidance written to be actioned. What to change, where, and what a fixed system should return instead. Not a link to a generic control description.
- Scope, verbatim. The authorised target list as agreed, so a reader can see the boundary the test ran inside.
- A named author. Every result has an author. The signature is a person who will defend the finding directly, not a company logo.
Who this is for
Two readers, and they want opposite things. Your engineers want the call, so they can reproduce and fix. Your auditor or your customer’s security reviewer wants the boundary and the attestation, so they can judge what the exercise covered. Reports usually serve the first reader badly and the second reader dishonestly. The template is our attempt to serve both without softening either.
Existing customers receive the new template on their next engagement. No action needed.

