No Email Gate. Just the PDFs.

Sample Penetration Test Reports

The report is the product you actually receive, so judge us by it. Download real TrustFoundry sample reports for application, network, and cloud engagements, no form required.

Application Penetration Test

A full web application assessment report: scoped targets, methodology, and findings from authorization flaws to injection, each with evidence and remediation guidance.

Download Sample PDF

External Network Penetration Test

An external network engagement report covering reconnaissance, exposed services, and exploitation attempts across an internet-facing perimeter.

Download Sample PDF

Cloud Penetration Test

A cloud security assessment report: identity and access findings, misconfigurations, and attack paths through a cloud environment.

Download Sample PDF

How to Read One

What a good penetration test report contains

If you're comparing vendors, ask each one for a sample report and look for these four things. A thin report after a two-week engagement usually means thin testing.

Executive summary

A plain-English assessment of risk posture that a board member or customer can read: what was tested, what was found, and how much it matters.

Findings with evidence

Each finding carries a severity rating, business impact, reproduction steps, and proof. Your engineers should be able to reproduce and verify every issue without calling us.

Remediation guidance

Specific, actionable fixes rather than generic advice, written by the tester who exploited the issue.

Methodology and scope

What was in scope, what standards the testing followed, and who performed it, which is exactly the documentation auditors and enterprise customers ask for.

One more thing the PDF can't show: at TrustFoundry the report is a snapshot of a living engagement. Findings stream into our client portal in real time as they're approved, retests are one click, and the whole history stays queryable long after the PDF is filed. That delivery model is described on our What is PTaaS page.

FAQ

Questions about pentest reports

Why do you publish sample reports without an email gate?

Because the report is what you're actually buying, and we think you should be able to evaluate it before a sales conversation, not after. If the sample doesn't convince you, no form was going to.

Are these real reports?

They're real TrustFoundry report templates populated with representative findings, sanitized so no client data appears. The structure, severity model, evidence style, and remediation guidance are exactly what a real engagement produces.

Is the PDF the whole deliverable?

No. The PDF is the formal snapshot. During and after the engagement, findings live in our client portal with real-time delivery, one-click retest requests, risk acceptance records, and a field-level audit trail. The portal is the working system; the report is the document of record.

Will this report satisfy my auditor or my customer's security team?

That's what it's designed for. Reports document scope, methodology, tester qualifications, findings with evidence, and remediation, the documentation SOC 2 auditors and PCI QSAs ask to see. Many of our clients share their reports (or a letter of attestation) directly with their own customers.

Want a report like this with your name on it?

Tell us what you need tested and we'll scope it. You've already seen exactly what you'll get back.