What has been changed in this copy
Every identifying detail has been removed. There is no client name, no hostname, no address and no identifier anywhere in the document, and no customer data appears in it. Where a real report would print a target, this copy prints a redaction marker instead. It does not describe any real environment.
Everything else is the real output: the structure, the severity model, the evidence format, the framework mapping and the remediation guidance are what the platform actually produces. Your own report carries the same sections with your systems named in full.
A real report belongs to the client who commissioned it and stays confidential to them. We do not publish customer reports, which is why this sample is redacted rather than borrowed from an engagement.
How this report is produced
Reports are generated from validated findings rather than raw scanner output. A finding reaches the report once it has been checked for false positives and, where the engagement allows it, confirmed through safe exploitation under your signed Rules of Engagement. That is what lets the attack-path section show a proven route rather than a theoretical one.
The same content is available as PDF, CSV and JSON over the API, so the findings can go straight into your own tracking rather than being retyped. The full process is set out in our methodology.