# [Engagement name]: test report

Client: [name]  ·  Scope: [systems, environments]  ·  Window: [dates]  ·  Issued: [date]  ·  Version: [1.0]  ·  Confidential

This is the Breakfirst report template, released for anyone to use. One finding per page. Severity on a five-stop scale: Info, Low, Medium, High, Critical. Every finding carries evidence, a fix and a retest status. Replace everything in square brackets.

---

## 1. Summary for the people who sign

Three to six sentences. What was tested, for how long, what was found by severity (a count per stop), what has been fixed, and the one thing to do next. No adjectives.

| Severity | Found | Fixed | Open |
| --- | --- | --- | --- |
| Critical | | | |
| High | | | |
| Medium | | | |
| Low | | | |
| Info | | | |

## 2. Scope and method

- Systems in scope, with versions or commit ids.
- Systems explicitly out of scope.
- Environments used, and how production was protected if it was in scope.
- Test accounts and roles used.
- Method: manual testing against [ASVS level / checklist], plus [tools], plus the threat model in section 3.
- Dates, hours spent, and who did the work.

## 3. Threat model

The diagram (or a link to it), the three attackers considered, and the ranked list of attacks that would hurt most. Mark which were covered by this engagement and which were not.

## 4. Findings

One finding per page, in severity order. Repeat the block below.

### [REF-0000-00] [Title that states the gap, not the symptom]

**Severity:** [stop] — [one line: who is affected and what it costs them]
**Status:** [Open / Fixed, pending retest / Fixed and retested on date]

**Summary.** Two or three sentences a non-engineer can follow.

**Steps to reproduce.** From a clean state. Numbered. Run twice before writing down.

1.
2.
3.

**Expected.** …
**Actual.** …

**Evidence.** A request and response, a log line, a screenshot with the time visible. Redacted where it carries personal data. Never edited for effect.

**Impact.** What an attacker or a customer can actually do with this, at what scale, and any regulatory consequence (for example a reportable breach under the DPDP Act).

**Fix.** The change we would make, concretely. A before and after if it is code. Then the test that will stop it coming back.

**Retest.** Date, what was checked, result. If not yet retested, say so.

## 5. Observations that are not findings

Things worth knowing that do not carry a severity: hardening suggestions, dependency age, documentation gaps.

## 6. Retest log

| Ref | Fix shipped | Retested | Result |
| --- | --- | --- | --- |

## 7. Appendix

Tools and versions. Accounts used. Full list of endpoints or screens covered. Anything the auditor will ask for.

---

Template by Breakfirst (breakfirst.dev). Use it, change it, keep the shape: title, severity, steps, evidence, impact, fix, retest.
