TL;DR: Direct answer: A legitimate penetration testing deliverable consists of three core components: an Executive Summary explaining business impact for board and commercial buyers; an Attestation Letter suitable for sharing with clients and auditors; and a detailed Technical Findings section with CVSS v3.1 scoring, step-by-step developer reproduction curl commands, and remediation validation.
The Three Core Components of a Real Deliverable
First-time penetration test buyers are often uncertain about what will actually be delivered once fieldwork wraps up. Will you receive a raw CSV spreadsheet? A 100-page automated tool export? Or a strategic, board-ready asset?
At Lorikeet Security Canada, our deliverables are engineered to satisfy two very different audiences simultaneously: the executive leadership team (and their enterprise prospective clients) who need a clear commercial risk assessment, and the software engineering team who must fix the identified vulnerabilities immediately.
A complete deliverable package consists of three integrated documents:
- The Comprehensive Assessment Report: The primary confidential document detailing the kill chain, attack narratives, and technical reproduction steps.
- The Executive Letter of Attestation: The public-facing, audit-ready document designed to be shared with enterprise buyers, insurance brokers, and CPA auditors.
- Remediation Retest Verification: The updated attestation certifying that identified vulnerabilities were re-evaluated and confirmed resolved.
Section 1: The Executive Summary and Risk Profile
The first section of our comprehensive report is written for non-technical leadership: CEOs, CTOs, legal counsel, and board members. It translates technical vulnerability data into actionable business risk context.
Rather than simply tallying CVE numbers, the executive summary answers the core operational questions:
- Could an unauthenticated attacker gain access to customer databases or personal information?
- Were testers able to cross organizational boundaries in our multi-tenant SaaS architecture?
- Did internal telemetry or monitoring alert the engineering team when attacks were launched?
- What are the top three strategic remediation investments that will deliver the highest risk reduction?
Red Flag: If an executive summary consists merely of an automated pie chart displaying "5 High, 12 Medium, 20 Low" without narrative context, your testing firm utilized automated reporting software rather than manual offensive analysis.
Section 2: The Letter of Attestation
The Letter of Attestation is the commercial engine of the deliverable. It is deliberately separated from the confidential technical report so your sales and compliance teams can provide it to prospective customers, CPA auditors, and cyber insurers without hesitation.
It explicitly states:
- The independent testing organization (Lorikeet Security Canada).
- The precise scope tested (domains, web apps, APIs, cloud environments, and user role levels).
- The testing framework adhered to (OWASP Web Security Testing Guide, PTES, NIST).
- The fieldwork dates and final retest completion date.
- A formal statement that identified high-risk vulnerabilities have been remediated and verified closed.
Section 3: Technical Findings & Reproducible Proofs
For your engineering team, our report provides an exhaustive, developer-ready breakdown for every finding. We follow a strict documentation standard that eliminates guesswork:
| Finding Field | What Lorikeet Security Canada Provides | Why Developers Value It |
|---|---|---|
| CVSS v3.1 Score | Full vector string (Base, Temporal, Environmental) with severity rating. | Enables objective prioritization against internal SLAs. |
| Proof of Concept (PoC) | Exact, copy-pasteable curl commands with request headers, parameters, and bodies. | Developers reproduce the vulnerability locally in under 60 seconds. |
| Root Cause Analysis | Explains the architectural failure (e.g., missing middleware authorization check). | Prevents recurring regressions across related API endpoints. |
| Remediation Guidance | Framework-specific code examples (Node.js, Python, PHP, Go, AWS IAM). | Saves hours of developer research with concrete implementation patterns. |
How to Inspect Our Specimen Demo Report
We believe in total transparency before you sign an engagement. You can review our complete, specimen penetration testing deliverable directly on our website.
Our sample report showcases real-world attack scenarios, including broken object-level authorization (BOLA) exploitation, SQL injection parameter chaining, cross-site scripting (XSS), and privilege escalation paths, formatted to enterprise audit standards.
Frequently Asked Questions
We deliver an encrypted, professionally styled PDF report, along with an official executive Letter of Attestation. We can also provide a structured JSON or CSV export of findings for direct import into Jira, Linear, or vulnerability management platforms.
Yes. Every engagement includes a 45-minute technical readout call where our lead offensive tester walks your developers through each finding, demonstrates the exploit live, and answers architectural remediation questions.
Draft reports are delivered within 2 to 3 business days following the completion of active fieldwork.
Want to inspect our authentic specimen report?
Download our complete demo penetration test report to review our reporting methodology, exploit proofs, and attestation letter format.