The same findings,
written for whoever is reading.
A board paper and an engineering ticket need the same evidence and completely different language. GuardianGaze produces five audience-tailored reports from one assessment, each carrying every finding, CVE and control rather than a filtered summary.
Delivered as PDFs with your branding.
One assessment, five audiences
Every report draws on the same evidence base, so the number the board sees and the ticket an engineer picks up cannot disagree.
Executive Summary
The rating, the trend, the material findings and what they mean commercially. Written for people who will not read a CVE list.
Technical Detailed
Every finding with evidence, affected asset, CVE identifiers, CVSS, EPSS and KEV status, remediation and SLA.
Compliance
Every mapped control across the frameworks you report against, with the specific finding that triggered each violation.
Cloud
Posture and misconfiguration across the connected AWS, GCP and Cloudflare accounts.
Attack Surface
The discovered estate: subdomains, live hosts, technologies, exposed services and how each was found.
What every report carries
Evidence-rich rather than exhaustive-for-its-own-sake. Findings are prioritised, and each one can be traced back to what was actually observed.
| Audience | Chosen per report, executive, technical, compliance, cloud or attack surface |
| Contents | Every finding, CVE and control, not a filtered summary |
| Per finding | Severity, evidence, affected asset, remediation and SLA |
| Reasoning | 5W context: what, why, where, who and impact |
| Mapping | Compliance control broken, plus MITRE ATT&CK tactic and technique |
| Format | PDF with running header and footer, carrying your branding |

Executive narrative and technical detail generated from one evidence base
Common questions
What format do reports arrive in?
PDF, with a running header and footer and your branding. Every finding, CVE and control is included rather than summarised away, so the report stands on its own when it is forwarded to an auditor or a vendor.
Can we send a report to a vendor or an auditor?
Yes, and that is the usual case. Findings and ratings produced for your account are licensed for internal business use including sharing with your vendors as part of the dispute workflow.
Are the executive narratives written by a person?
The narrative, business-impact summary and remediation plan are AI-assisted, then presented alongside the underlying evidence so any claim can be traced back to the finding that produced it. Indicators in the brand modules are analyst-verified before they reach a report.
How often can we generate them?
On demand, on top of continuous monitoring. A rescan can be triggered when you have fixed something and want the report to reflect it.
One report cannot serve four audiences
A security report that satisfies an engineer will lose a board within a page, and a report a board finds useful gives an engineer nothing to act on. Most platforms solve this by producing one document and letting each reader skip the parts they cannot use, which means every reader gets a document mostly written for somebody else.
The four audiences want genuinely different things. Engineering wants the specific finding, the affected asset, and enough evidence to reproduce or refute it. Compliance wants the control the finding breaks and dated evidence they can put in a file. The board wants direction, peer comparison and named owners. A customer's security team wants assurance about the controls they asked about, and nothing else.
So reports are generated per audience from the same underlying evidence rather than assembled by hand. The facts do not change between versions; the framing, depth and vocabulary do.
Every finding carries what it was derived from
A report that asserts without showing is a report that gets disputed, and disputes are where credibility is spent. Each finding carries the observation behind it (the record, the response, the certificate, the log entry) so a reader can check rather than trust.
That matters most when the report leaves your organisation. Sending a supplier a list of findings about their estate goes very differently when each one quotes their own published configuration back to them. It converts an argument about methodology into a factual conversation about a specific record.
It also means a wrong finding can be disposed of quickly. If the evidence is stale or the attribution is wrong, that is checkable and the finding goes. A platform without that mechanism accumulates disputed findings until people stop reading the output.
Dated, versioned, and useful after the fact
Reports are timestamped against a versioned scoring model, which sounds like housekeeping and turns out to be the feature people value most a year later.
It means a report shows what the posture was on a given date, derived by a model whose version is recorded. Quarter-on-quarter comparison is therefore meaningful, a change reflects the estate rather than a change in how we score it.
That matters in three specific situations: an insurer asking what controls were in place before a loss, an auditor asking for evidence across a period rather than at a point, and a board asking whether two years of security investment has moved anything.
See a report against your own domain
The fastest way to judge a reporting format is to read one about a company you already know well, yours.
Free for your own organisation.