Skip to main content
This is a real report generated by Perfai. Download the full PDF or read through each section below to understand what your team will receive after every scan.

Download Sample Report (PDF)

Application Security Report · 8 pages · June 2026

What’s in the report

Every Perfai security report follows the same structure — eight sections, always in the same order, optimized for two audiences: engineers who need to fix things, and leadership who need to understand risk.

01 — Executive Summary

The executive summary is the first thing every stakeholder sees. It answers the question “how bad is it?” in four numbers.
Critical / High — findings that require immediate action. In this report: 14 issues, all scoring 9.8 CVSS. Bug Bounty Savings — what these vulnerabilities would cost if discovered externally by a researcher. In this report: $72,000 in potential exposure avoided. Attack Surface — what the Vision Agent discovered and tested. 24 UI workflows, 14 API endpoints, 694 individual security test cases run — all automated, no manual scripting.

02 — Security Frameworks

Perfai maps every finding to three industry standards simultaneously — in a single run, with no separate scans required.
This section tells your compliance team exactly which regulatory frameworks the findings apply to — so evidence can be assembled per standard without re-running tests.

03 — Active Findings

The findings section is the technical core of the report. Every confirmed vulnerability appears as a row with five data points: Example findings from this report: Findings are also broken down by framework — showing exactly which OWASP categories fired and how many issues mapped to each:

04 — Test Coverage

This section documents every security test category Perfai ran — 44 categories across 694 individual test cases. You can verify exactly what was covered and flag anything that falls outside scope. Coverage categories include:

Access Control

RBAC matrix validation, UI/API permission mismatch (BFLA), SBAC matrix validation, broken function level authorization, API/UI contract testing

Cross-Tenant Access

Admin and all-roles cross-tenant data access, cross-tenant data contamination, BOLA, enumerable resource ID, cross-tenant takeover

Token & Session Security

Broken token signature verification, cross-environment/application token acceptance, missing token revocation, broken logout, missing issuer/audience claims, expired token acceptance

Injection & Request Forgery

Client-side request forgery (CSRF), server-side request forgery (SSRF), sensitive data exposure in responses, token data tampering, signing key reverse-engineering

Transport & Cryptography

Broken CORS policy, missing HSTS header, self-signed SSL, SSL expiration, TLS version below 1.2

Security Configuration

Unsecured observability endpoints, debug endpoint exposure, security config missing, API governance/inventory, rate limiting, pagination limits

05 — SOC-2 Compliance

Every finding is automatically mapped to SOC-2 Trust Service Criteria — so compliance evidence is built into the report, not assembled after the fact. This table tells your GRC team exactly which SOC-2 controls need remediation evidence before your next audit.

06 — Scope & Authentication

This section documents exactly what was tested and what was explicitly excluded — important for audit evidence and for understanding any coverage gaps. In scope:
  • All API endpoints (GET / POST / PUT / DELETE / PATCH)
  • Authentication flows — login, signup
  • RBAC validation across tested roles
  • Cross-tenant isolation
  • Token security — expired, invalid, revoked tokens
Out of scope:
  • Databases and internal data stores
  • Source code (SAST)
  • Internal admin tools
  • Third-party processors
  • Cross-environment token testing
Coverage stats for this report:

07 — Summary

The final page is a one-page posture snapshot — designed to be forwarded to a CISO or leadership team without context.
Not Secure means the app has at least one unresolved Critical or High finding. Status changes to Secure once all Critical and High findings are resolved and re-verified by a follow-up scan.

Report delivery

Reports are generated automatically after every scan and available in two ways:
  • In-dashboard — open from the Reports page, filterable by app, type, and date
  • PDF download — click ···Download on any report row for a formatted PDF
  • Auto-sync — connect Google Drive, OneDrive, or Dropbox to automatically archive every report after each scan (reports are deleted from Perfai after 14 days without a connected provider)
  • Scheduled delivery — set a reporting schedule in Actions → Edit to receive reports by email on a nightly, weekly, bi-weekly, or monthly cadence