Reporting & exports
Turn findings into reports your auditors, board and customers can read.
What is included in a Vulny security report?
A Vulny report turns raw findings into a document your auditors, board and customers can actually read. Every report uses your Vulny-branded template and opens with a severity breakdown — how many critical, high, medium and low issues were found — followed by each finding with its description, the affected asset and a plain-language fix. Crucially, every finding cites the data sources behind it: ISO 27001 control references, the CVE identifier, NVD/NIST, Exploit-DB, the CISA KEV known-exploited catalogue, EPSS exploit probability and the relevant CWE weakness type. That provenance is what makes a report defensible in an audit or a customer security review — a reviewer can trace any claim back to an authoritative source rather than taking your word for it. The result is professional output you can share externally without reformatting or redacting.
Can I export reports as PDF and Word (DOC)?
Yes. Vulny exports every report in two formats: a polished PDF for sharing and archiving, and an editable DOC (Word) file for when you need to adapt the content. You can export vulnerability assessments, incident reports, the risk register, the Statement of Applicability and third-party risk assessments — each as a standalone document. The DOC format matters for compliance work: you can drop a Statement of Applicability or risk report straight into an existing evidence pack, management-review pack or customer questionnaire and edit it to match your house style, without rebuilding it from scratch. Both formats are generated on demand from your current data, so an export always reflects the latest scan results and ISMS state rather than a stale copy saved weeks ago.
Who are Vulny’s reports designed for?
Vulny’s reports are built for three audiences, each needing a different level of detail. Auditors and assessors get the provenance and control mapping they require to verify ISO 27001, SOC 2 or PCI DSS evidence. Management and the board get the severity summary and trend at the top, so they can grasp risk posture without reading every technical finding. Customers and prospects running a vendor security review get a clean, branded document that shows you test continuously — often enough to answer a security questionnaire outright. Because all three come from the same live data set, there is no risk of the figures you show an auditor disagreeing with the ones you send a customer. One export, tailored by audience, instead of three hand-maintained documents that drift apart over time.
See it on your own site
Run one scan for security, SEO and AI-search (GEO) — and get a branded, ISO 27001 ready PDF report.
Scan my site →