Security reports are useful only when readers can trace conclusions back to scope, requirements, findings, evidence, remediation, and validation. voiqq builds program-specific PDF reports from the same reviewed project records used during the assessment. It does not recreate the engagement from an unrelated document form at the end.
Supported report families
- OWASP ASVS application security assessment reports use the selected verification level and mapped ASVS requirements.
- OWASP MASVS mobile security assessment reports use mapped controls, platform scope, affected app areas, and mobile evidence.
- OWASP AISVS AI application security assessment reports use the chosen assurance level, system type, mapped requirements, and reviewed AI security evidence.
- SOC 2 readiness reports use selected Trust Services Criteria, report target, scope, control readiness, evidence status, remediation priorities, and auditor preparation notes.
Coverage is deterministic
The report engine does not ask AI to decide whether a requirement is covered. Active mapped gaps reduce coverage. Resolved findings can support a covered result. Mixed active and resolved records can produce partial coverage. Requirements without assessment evidence remain Not Assessed rather than being presented as passed. Unmapped findings are counted and raised for review.
Prepare the project
- Confirm the Program, Library, target level, assessment target, and project scope.
- Map each report-relevant finding to the most precise canonical requirement or control.
- Review status, validation, severity, owner, due date, affected target, evidence, and remediation.
- Resolve duplicate or obsolete records and document accepted limitations.
- Open Generate Report, review the summary, scope, warnings, coverage, and findings register.
- Export the PDF and inspect every page before sharing it.
Language and source evidence
Supported report headings, workflow values, and dates follow the project language. Standard identifiers and user-entered evidence remain unchanged so the export cannot silently alter a quoted result or technical reference. Translate and approve narrative evidence explicitly when the recipient needs a different language.
