Skip to main content

Reports & Compliance

BleedWatch generates security reports for executive briefings, compliance audits, and ongoing monitoring. Download PDF reports, export findings data, build custom report templates, and generate compliance evidence packs for SOC 2, ISO 27001, and PCI DSS.

Report Types

TypePurposeFormat
Executive SummaryHigh-level security posture overview for leadershipPDF
Monthly ReportMonth-over-month trend analysisPDF
Quarterly ReportQuarterly security reviewPDF
On-Demand ReportAd-hoc report generated on requestPDF
Compliance Evidence PackAudit-ready documentation bundleZIP (multiple PDFs)

Executive Summary

The Executive Summary provides a snapshot of your security posture designed for CISOs and leadership teams. Access it from Reports → Executive Summary.

Key Metrics

MetricDescription
Risk ScoreOverall score from 0–100 with trend delta from previous period (color-coded: green = improving, red = declining)
MTTDMean Time to Detect — average time between a secret being exposed and BleedWatch finding it
MTTRMean Time to Remediate — average time between detection and resolution
FP RateFalse positive rate — percentage of findings marked as false positives

Sections Included

  • Findings Summary — Breakdown by severity (critical, high, medium, low)
  • Validity Summary — Active vs. invalid vs. unchecked findings
  • Top Exposures — Most significant findings ranked by secret type, source, and exposure duration
  • Remediation Status — This period vs. previous, with average remediation time in hours
  • Coverage — Total assets monitored, assets scanned, asset types, and last scan timestamp

The Executive Summary supports both monthly and quarterly period views. Toggle the period from the report header.

Generating Reports

On-Demand Generation

  1. Navigate to Reports and click Generate Report
  2. Select the report type and date range
  3. Click Generate

Reports are queued and processed in the background. You'll receive an email notification when the report is ready for download.

Downloading Reports

Click the Download button on any completed report to get the PDF. Reports are retained and available for download from the Reports list.

Compliance Evidence Packs

For organizations undergoing compliance audits, BleedWatch generates comprehensive evidence packs as a single ZIP download.

Supported Frameworks

FrameworkCoverage
SOC 2Continuous monitoring evidence, finding remediation timelines, alert configuration proof
ISO 27001Asset inventory, vulnerability management records, incident response evidence
PCI DSSScript integrity (Req 6.4), vulnerability scanning records, remediation evidence

What's Included

Each compliance pack contains six PDF documents:

  1. Executive Summary — Overall security posture and risk score
  2. Scan Coverage — Proof of continuous monitoring across all asset types
  3. Findings Remediation — Complete finding lifecycle from detection to resolution
  4. Alert Configuration — Evidence that alerting is configured and active
  5. Continuous Monitoring — Scan frequency and asset coverage over the reporting period
  6. MTTR/MTTD Metrics — Detection and remediation performance metrics

Generating a Compliance Pack

  1. Navigate to Reports → Compliance
  2. Select the framework (SOC 2, ISO 27001, or PCI DSS)
  3. Select the reporting period (e.g., "Q1-2026")
  4. Click Generate Pack

The ZIP file is prepared in the background and available for download once complete.

Audit Preparation

Generate compliance packs before your audit window opens. The evidence is timestamped and period-specific — generating it in advance ensures your auditors receive consistent data covering the exact review period.

Data Export

Export raw findings data for custom analysis or SIEM ingestion:

FormatDetails
CSVSpreadsheet-compatible, up to 10,000 rows, formula injection protected
JSONMachine-readable, up to 10,000 rows

Access exports from the Reports section or from the Findings page filter toolbar.

Report Builder

The Report Builder lets you create custom report templates with a drag-and-drop interface.

Creating a Template

  1. Navigate to Reports → Templates and click New Template
  2. Drag widgets from the palette onto the 12-column grid layout
  3. Configure each widget (data source, date range, visualization type)
  4. Set a schedule (manual or recurring) and distribution list (recipient email addresses)
  5. Click Save Template

Managing Templates

Saved templates appear in the Templates tab. You can:

  • Edit — Modify layout, widgets, or schedule
  • Run — Generate a report from the template immediately
  • Delete — Remove the template

Troubleshooting

Report Generation Stuck

If a report shows "Processing" for more than 15 minutes:

  1. Try generating a new report — the original job may have encountered an error
  2. Check that your account has findings data for the selected date range (empty reports may fail silently)

Compliance Pack Missing Data

If a compliance pack has incomplete sections:

  1. Verify that alerts are configured (the Alert Configuration section reflects your current setup)
  2. Ensure scans have run during the reporting period
  3. Check that findings exist for the selected timeframe

Export Hitting Row Limit

CSV and JSON exports are capped at 10,000 rows. If you need more data:

  1. Narrow the date range or add severity/source filters
  2. Generate multiple exports for different time periods
  3. Use the webhook integration for continuous data streaming to your SIEM