Reports & Attestation
PDF report
Every completed pentest generates a PDF report containing:
- Executive summary - AI-generated overview of security posture
- Methodology - Tools used and testing approach
- Findings - All vulnerabilities with severity, description, proof of exploit, and remediation
- Attack surface map - Discovered assets and entry points
- Threat model - STRIDE-based analysis
Download via API
curl -H "Authorization: Bearer $TURBOPENTEST_API_KEY" \
https://turbopentest.com/api/pentests/{id}/report \
-o pentest-report.pdfDownload from dashboard
Go to the pentest results page and click Download Report.
Attestation letter
A formal letter confirming a penetration test was performed, suitable for sharing with auditors or customers. Each attestation is backed by cryptographic verification: SHA-256 hashes of the report and target are combined into a Merkle tree, and the letter embeds a public verification link and QR code so anyone can confirm the report has not been altered.
On-chain anchoring to Base (an Ethereum L2) is part of the attestation design and roadmap; on-chain publishing is not yet live, so today's verification relies on the SHA-256 hash and Merkle-tree proof plus the public verification link.
Download via API
curl -H "Authorization: Bearer $TURBOPENTEST_API_KEY" \
https://turbopentest.com/api/pentests/{id}/attestation \
-o attestation-letter.pdfReport export
Export findings to third-party pentest management platforms:
- PlexTrac - CSV format compatible with PlexTrac import
- Dradis - Textile (plain text) format for Dradis projects
- AttackForge - JSON format for AttackForge
- Ghostwriter - JSON format for Ghostwriter
See Report Export for details.
Sample reports
View sample deliverables without an account:
- Sample Report (PDF)
- Sample Attestation (PDF)
Retest Commands
Verify fixes automatically: every repeat TurboPentest re-checks each previous finding against fresh evidence and records a fixed-or-unresolved verdict.
Cloud EASM & Assets
Discover your external attack surface with authenticated multi-cloud API discovery across 9 providers, track new and removed assets, and launch one-click pentests from verified assets.