Last reviewed: 2026-09-15
Reports and proof exports
Export security evidence and proof records with plan-based access and retention, including proof export availability from Starter onward.
Export evidence for a known context
Reports let you export results and proof records for a repository, project unit, branch, and commit. Before sharing an export, verify that context so the evidence matches the work being reviewed.
The app loads the canonical report-type list (and which types support PDF) from GET /reports/types — the server allowlist is authoritative; clients must not hardcode it.
For a single ZIP that bundles reports, SBOM, audit trail, and policies for auditors, see Auditor Export Pack. By default the pack uses latest on-file scans; you can optionally refresh evidence first (billed scans). Report generation itself stays free when your plan allows it.
You can optionally refresh evidence before generating a report (select repositories, enable refresh). History lives under Evidence refreshes.
Stack trends shows observed root-library usage by dependency category (share of project units). You choose which libraries become category-governance whitelist rules; nothing is auto-applied from a majority. This type is not available as PDF. Optional evidence refresh uses the same billed BulkEnsure path as other reports; classification of unknown names runs when the report is built from those scans.
PDF proof export is limited to compliance overview and vulnerabilities summary (same subset as in the auditor pack).
Plan access and retention
Proof export is not available on Free. Starter and higher plans include proof export. Auditor Export Pack requires Team or Regulated. Retention is also plan-based: an export cannot recover findings that have aged out of your organization’s retained history. Export evidence before a plan change that reduces retention.
Use exports safely
Exports may contain repository and dependency metadata. Store them according to your organization’s data-handling rules, give recipients only what they need, and do not include credentials or unredacted secrets. An export is evidence of the selected context, not an assurance that every risk was found.