---
title: "Reports & Attestation"
description: "Every completed TurboPentest generates a PDF report with CVSS-scored findings plus a formal attestation letter you can hand to auditors and customers."
canonical: https://turbopentest.com/docs/pentesting/reports-attestation
source: "TurboPentest Docs"
---

# Reports & Attestation

## PDF report

Every completed pentest generates a PDF report containing:

- **Executive summary** - AI-generated overview of security posture
- **Methodology** - Tools used and testing approach
- **Findings** - All vulnerabilities with severity, description, proof of exploit, and remediation
- **Attack surface map** - Discovered assets and entry points
- **Threat model** - STRIDE-based analysis

### Download via API

```bash
curl -H "Authorization: Bearer $TURBOPENTEST_API_KEY" \
  https://turbopentest.com/api/pentests/{id}/report \
  -o pentest-report.pdf
```

### Download from dashboard

Go to the pentest results page and click **Download Report**.

## Attestation letter

A formal letter confirming a penetration test was performed, suitable for sharing with auditors or customers. Each attestation is backed by cryptographic verification: SHA-256 hashes of the report and target are combined into a Merkle tree, and the letter embeds a public verification link and QR code so anyone can confirm the report has not been altered.

On-chain anchoring to Base (an Ethereum L2) is part of the attestation design and roadmap; on-chain publishing is not yet live, so today's verification relies on the SHA-256 hash and Merkle-tree proof plus the public verification link.

### Download via API

```bash
curl -H "Authorization: Bearer $TURBOPENTEST_API_KEY" \
  https://turbopentest.com/api/pentests/{id}/attestation \
  -o attestation-letter.pdf
```

## Report export

Export findings to third-party pentest management platforms:

- **PlexTrac** - CSV format compatible with PlexTrac import
- **Dradis** - Textile (plain text) format for Dradis projects
- **AttackForge** - JSON format for AttackForge
- **Ghostwriter** - JSON format for Ghostwriter

See [Report Export](/docs/integrations/report-export) for details.

## Sample reports

View sample deliverables without an account:

- [Sample Report](https://turbopentest.com/api/samples/report) (PDF)
- [Sample Attestation](https://turbopentest.com/api/samples/attestation) (PDF)
