The same findings, written for whoever is reading.
A board paper and an engineering ticket need the same evidence and completely different language. Guardian Gaze produces five audience-tailored reports from one assessment, each carrying every finding, CVE and control rather than a filtered summary.
Delivered as PDFs with your branding.
One assessment, five audiences
Every report draws on the same evidence base, so the number the board sees and the ticket an engineer picks up cannot disagree.
Executive Summary
The rating, the trend, the material findings and what they mean commercially. Written for people who will not read a CVE list.
Technical Detailed
Every finding with evidence, affected asset, CVE identifiers, CVSS, EPSS and KEV status, remediation and SLA.
Compliance
Every mapped control across the frameworks you report against, with the specific finding that triggered each violation.
Cloud
Posture and misconfiguration across the connected AWS, GCP and Cloudflare accounts.
Attack Surface
The discovered estate: subdomains, live hosts, technologies, exposed services and how each was found.
What every report carries
Evidence-rich rather than exhaustive-for-its-own-sake. Findings are prioritised, and each one can be traced back to what was actually observed.
| Audience | Chosen per report, executive, technical, compliance, cloud or attack surface |
| Contents | Every finding, CVE and control, not a filtered summary |
| Per finding | Severity, evidence, affected asset, remediation and SLA |
| Reasoning | 5W context: what, why, where, who and impact |
| Mapping | Compliance control broken, plus MITRE ATT&CK tactic and technique |
| Format | PDF with running header and footer, carrying your branding |
Executive narrative and technical detail generated from one evidence base
One report cannot serve four audiences
A security report that satisfies an engineer will lose a board within a page, and a report a board finds useful gives an engineer nothing to act on. Most platforms solve this by producing one document and letting each reader skip the parts they cannot use, which means every reader gets a document mostly written for somebody else.
The four audiences want genuinely different things. Engineering wants the specific finding, the affected asset, and enough evidence to reproduce or refute it. Compliance wants the control the finding breaks and dated evidence they can put in a file. The board wants direction, peer comparison and named owners. A customer's security team wants assurance about the controls they asked about, and nothing else.
So reports are generated per audience from the same underlying evidence rather than assembled by hand. The facts do not change between versions; the framing, depth and vocabulary do.
Every finding carries what it was derived from
A report that asserts without showing is a report that gets disputed, and disputes are where credibility is spent. Each finding carries the observation behind it (the record, the response, the certificate, the log entry) so a reader can check rather than trust.
That matters most when the report leaves your organisation. Sending a supplier a list of findings about their estate goes very differently when each one quotes their own published configuration back to them. It converts an argument about methodology into a factual conversation about a specific record.
It also means a wrong finding can be disposed of quickly. If the evidence is stale or the attribution is wrong, that is checkable and the finding goes. A platform without that mechanism accumulates disputed findings until people stop reading the output.
Dated, versioned, and useful after the fact
Reports are timestamped against a versioned scoring model, which sounds like housekeeping and turns out to be the feature people value most a year later.
It means a report shows what the posture was on a given date, derived by a model whose version is recorded. Quarter-on-quarter comparison is therefore meaningful, a change reflects the estate rather than a change in how we score it.
That matters in three specific situations: an insurer asking what controls were in place before a loss, an auditor asking for evidence across a period rather than at a point, and a board asking whether two years of security investment has moved anything.
Common questions
See a report against your own domain
The fastest way to judge a reporting format is to read one about a company you already know well, yours.
Free for your own organisation.