This is a real report generated by Perfai. Download the full PDF or read through each section below to understand what your team will receive after every scan.
Download Sample Report (PDF)
Application Security Report · 8 pages · June 2026
What’s in the report
Every Perfai security report follows the same structure — eight sections, always in the same order, optimized for two audiences: engineers who need to fix things, and leadership who need to understand risk.01 — Executive Summary
The executive summary is the first thing every stakeholder sees. It answers the question “how bad is it?” in four numbers.02 — Security Frameworks
Perfai maps every finding to three industry standards simultaneously — in a single run, with no separate scans required.03 — Active Findings
The findings section is the technical core of the report. Every confirmed vulnerability appears as a row with five data points:
Example findings from this report:
Findings are also broken down by framework — showing exactly which OWASP categories fired and how many issues mapped to each:
04 — Test Coverage
This section documents every security test category Perfai ran — 44 categories across 694 individual test cases. You can verify exactly what was covered and flag anything that falls outside scope. Coverage categories include:Access Control
RBAC matrix validation, UI/API permission mismatch (BFLA), SBAC matrix validation, broken function level authorization, API/UI contract testing
Cross-Tenant Access
Admin and all-roles cross-tenant data access, cross-tenant data contamination, BOLA, enumerable resource ID, cross-tenant takeover
Token & Session Security
Broken token signature verification, cross-environment/application token acceptance, missing token revocation, broken logout, missing issuer/audience claims, expired token acceptance
Injection & Request Forgery
Client-side request forgery (CSRF), server-side request forgery (SSRF), sensitive data exposure in responses, token data tampering, signing key reverse-engineering
Transport & Cryptography
Broken CORS policy, missing HSTS header, self-signed SSL, SSL expiration, TLS version below 1.2
Security Configuration
Unsecured observability endpoints, debug endpoint exposure, security config missing, API governance/inventory, rate limiting, pagination limits
05 — SOC-2 Compliance
Every finding is automatically mapped to SOC-2 Trust Service Criteria — so compliance evidence is built into the report, not assembled after the fact.
This table tells your GRC team exactly which SOC-2 controls need remediation evidence before your next audit.
06 — Scope & Authentication
This section documents exactly what was tested and what was explicitly excluded — important for audit evidence and for understanding any coverage gaps. In scope:- All API endpoints (GET / POST / PUT / DELETE / PATCH)
- Authentication flows — login, signup
- RBAC validation across tested roles
- Cross-tenant isolation
- Token security — expired, invalid, revoked tokens
- Databases and internal data stores
- Source code (SAST)
- Internal admin tools
- Third-party processors
- Cross-environment token testing
07 — Summary
The final page is a one-page posture snapshot — designed to be forwarded to a CISO or leadership team without context.Report delivery
Reports are generated automatically after every scan and available in two ways:- In-dashboard — open from the Reports page, filterable by app, type, and date
- PDF download — click
···→ Download on any report row for a formatted PDF - Auto-sync — connect Google Drive, OneDrive, or Dropbox to automatically archive every report after each scan (reports are deleted from Perfai after 14 days without a connected provider)
- Scheduled delivery — set a reporting schedule in Actions → Edit to receive reports by email on a nightly, weekly, bi-weekly, or monthly cadence

