Skip to Content
FeaturesExecutive Reports

Executive Reports

Download professional PDF security reports from CodeStax for engineering review, management communication, and supporting audit evidence.

Report Types

Repository and Scan Reports

Repository and scan-detail downloads use the same report design. Each PDF is bound to an exact completed scan and includes:

  • Repository, branch, scan ID, scan type, health, and generated timestamp
  • Executive summary with finding totals and severity distribution
  • Coverage and scope notes so incomplete evidence is not presented as a clean result
  • SOC 2 and ISO 27001 relevance expressed as mapped findings, not certification
  • Prioritized findings with file location, impact description, and remediation guidance
  • Repeating report header, confidentiality footer, and page numbers

SCA Reports

The SCA dashboard provides separate human-readable reports for:

  • Full SCA evidence
  • Vulnerabilities and recommended upgrades
  • Dependency inventory
  • License compliance
  • SPDX or CycloneDX SBOM summaries

The PDF SBOM is a human-readable summary. Retain the SPDX or CycloneDX JSON export as the canonical machine-readable SBOM.

How to Download

From a Repository

  1. Open a repository detail page.
  2. Ensure the repository has a completed scan.
  3. Select Download Report.

From a Scan

  1. Open a completed scan from scan history.
  2. Select Download PDF.
  3. CodeStax verifies that the response belongs to the displayed scan before saving it.

Interpreting a Report

A CodeStax report describes automated security evidence within its recorded scope. Framework mappings identify possible control relevance; they do not certify compliance or prove that a control operated effectively. Review scan health, coverage, exclusions, and omissions before relying on a score or result.

Permissions

Organization members can download reports only for repositories and scans available to their organization. The PDF preserves scan provenance inside the document so the downloaded file remains attributable after it leaves CodeStax.