What an audit
report actually
looks like.
A public sample report built on the synthetic Acme Health Network fixture, with no real client data. The full structure is shown: cover sheet, findings with observed frequency and verbatim evidence, business-impact narratives, compliance dossiers and the cross-framework mapping. Internal test IDs and pattern signatures are redacted; everything else is shown exactly as delivered.
Every finding, with its frequency.
The same ledger that opens every report: severity, OWASP or Agentic category, and how often the attack actually succeeded. A non-technical reader scans the entire risk surface in under sixty seconds. No pass/fail column: clean results carry a statistical detection bound instead.
Every finding, with its frequency.
Severity, category, and observed failure frequency, so a non-technical reader can scan the risk surface in under sixty seconds. Detail, trial count, confidence interval and verbatim evidence sit one page deeper.
ART. 15 · ISO 42001 · NIST
Coverage is capability-aware: every applicable test runs against your endpoint; tests that don't apply to your architecture are marked N/A, never padded into the score.
AI systems don't behave identically every time: the same prompt can produce different outputs, even at temperature 0. A single run therefore proves very little. Every applicable attack is run multiple times; each finding ships with its observed frequency, a confidence interval, and the trial count behind it. Where an attack was not observed to succeed and the test had at least 20 attempts, the report states a per-test bound instead of a "passed" label; severe categories run 30 attempts, so a clean severe test reads "not observed in 30 attempts, held below 10% at 95% confidence, about 1 in 10." A category-level bound appears only when every test in that category recorded zero hits, and it bounds the average failure rate across our catalog's attack mix, not any single attack. A finding that fires 35% of the time may not reproduce on a single manual retest, and that's expected: it's exactly why we report a rate, not a yes/no.
The full audit. Every finding, every frequency.
Built on the synthetic Acme Health Network fixture, with no real customer data. Every finding with its observed frequency, confidence interval and trial count. Three compliance dossiers (EU AI Act Article 15, ISO 42001, NIST AI RMF), a board-ready executive summary, and one bounded re-test within 30 days. Internal test identifiers and pattern signatures are redacted in this public version; everything else is shown as delivered.
Full sample report
Your report. Your endpoint..
Hand us an endpoint and an auth header. We hand you a report your legal team, your security team and your board can all open.