Sample Penetration Test Reports
The report is the product you actually receive, so judge us by it. Download real TrustFoundry sample reports for application, network, and cloud engagements, no form required.
Application Penetration Test
A full web application assessment report: scoped targets, methodology, and findings from authorization flaws to injection, each with evidence and remediation guidance.
Download Sample PDFExternal Network Penetration Test
An external network engagement report covering reconnaissance, exposed services, and exploitation attempts across an internet-facing perimeter.
Download Sample PDFCloud Penetration Test
A cloud security assessment report: identity and access findings, misconfigurations, and attack paths through a cloud environment.
Download Sample PDFHow to Read One
What a good penetration test report contains
If you're comparing vendors, ask each one for a sample report and look for these four things. A thin report after a two-week engagement usually means thin testing.
Executive summary
A plain-English assessment of risk posture that a board member or customer can read: what was tested, what was found, and how much it matters.
Findings with evidence
Each finding carries a severity rating, business impact, reproduction steps, and proof. Your engineers should be able to reproduce and verify every issue without calling us.
Remediation guidance
Specific, actionable fixes rather than generic advice, written by the tester who exploited the issue.
Methodology and scope
What was in scope, what standards the testing followed, and who performed it, which is exactly the documentation auditors and enterprise customers ask for.
One more thing the PDF can't show: at TrustFoundry the report is a snapshot of a living engagement. Findings stream into our client portal in real time as they're approved, retests are one click, and the whole history stays queryable long after the PDF is filed. That delivery model is described on our What is PTaaS page.
FAQ
Questions about pentest reports
Why do you publish sample reports without an email gate?
Because the report is what you're actually buying, and we think you should be able to evaluate it before a sales conversation, not after. If the sample doesn't convince you, no form was going to.
Are these real reports?
They're real TrustFoundry report templates populated with representative findings, sanitized so no client data appears. The structure, severity model, evidence style, and remediation guidance are exactly what a real engagement produces.
Is the PDF the whole deliverable?
No. The PDF is the formal snapshot. During and after the engagement, findings live in our client portal with real-time delivery, one-click retest requests, risk acceptance records, and a field-level audit trail. The portal is the working system; the report is the document of record.
Will this report satisfy my auditor or my customer's security team?
That's what it's designed for. Reports document scope, methodology, tester qualifications, findings with evidence, and remediation, the documentation SOC 2 auditors and PCI QSAs ask to see. Many of our clients share their reports (or a letter of attestation) directly with their own customers.
Want a report like this with your name on it?
Tell us what you need tested and we'll scope it. You've already seen exactly what you'll get back.