Securitain Docs
On this page

Reports & Evidence

Turn Securitain security analysis into information that can be reviewed, shared and governed.

Different audiences need different views of the same AWS security posture. A cloud security engineer may need exact IAM findings and attack paths. A CTO or CISO may need a risk overview and high-impact identities. A compliance reviewer may need control mappings and account context. Securitain provides multiple report types for these different questions.

Where to find Reports

IAM AnalyzerReports

The current page is named Reports & Exports. Report availability can depend on the organization's Securitain plan.

Current report types

The current product includes ten IAM report types.

Executive Summary

A high-level security and identity overview covering active finding counts, severity overview, identity inventory, administrative identities, access-key risk context and top identity blast-radius context. Use for CTO/CISO review, cloud leadership and security program reporting.

IAM Findings

A finding-level export covering title, severity, status, category, affected entity, AWS account, first seen and last seen. Use for security operations, finding review and evidence export.

Privilege Escalation

Summarizes detected privilege-escalation paths including source identity, target identity or capability, path type, severity and description. Use for IAM engineering, security architecture and high-risk access investigation.

Cross-Account Exposure

Summarizes supported cross-account trust relationships and associated risk context. Use for multi-account governance, third-party access review and shared-services review.

Federation / OIDC Risk

Summarizes supported federation findings involving OIDC, SAML and external identity providers. Use for CI/CD trust review, GitHub OIDC governance and enterprise federation review.

Least Privilege

Summarizes least-privilege opportunities including entity, granted actions, used actions, unused actions and risk-prioritization context. Use for permission right-sizing and developer or workload access review.

Identity Blast Radius

Summarizes supported consequence-oriented identity context including overall blast score, admin capability, assumable roles and reachable supported resources. Use for privileged-identity prioritization and executive risk review.

Compliance Mapping

Summarizes supported finding-to-control mappings by framework, control and mapped finding count. Use for technical audit preparation and compliance engineering.

Important

Do not interpret the compliance report as certification. See Compliance Mapping for accuracy context.

Attack Paths

Represents escalation information as source-to-target security paths. Use for attack-path investigation, identity-risk review and architecture discussion. Related to the Privilege Escalation report but presents information in an attack-path-oriented shape.

Access Key Hygiene

Summarizes access-key security context such as key age, rotation status, administrative attachment risk and recommendation. Use for credential hygiene, IAM user cleanup and operational security review.

Output formats

FormatBest for
PDFHuman review, executive sharing, formal evidence packages
MarkdownTechnical documentation, Git-based workflows, internal security notes
CSVSpreadsheet analysis, sorting and filtering, importing into other tools
JSONProgrammatic processing, custom analysis, automation and integration

Branding

Current PDF and Markdown outputs include Securitain branding with account context, generation timestamp and a confidential footer. CSV and JSON remain more data-oriented.

Report generation time vs evidence collection time

Important

Report generation time and evidence collection time are different. A report generated at 10:00 AM may reflect AWS data last collected at 8:30 AM.
Report Generated At
        ≠
AWS Evidence Collected At
Always evaluate a report together with the underlying scan freshness — they answer different questions.

The report generation timestamp tells you when the document was created. Scan Status tells you when the displayed assessment data was last successfully collected. Check Scan Status & Freshness before using a report for time-sensitive decisions.

Account context

Reports can be scoped to all connected accounts or a selected AWS account where supported. Always include enough account context to avoid confusing the origin of findings. For multi-account reports, preserve account identity per finding or result where possible.

What “evidence” means in Securitain

Evidence is the security context supporting a conclusion. Depending on the finding or analysis, evidence can include identity details, policy details, trust relationship, AWS account, affected resource, relevant permissions, scan time, first and last seen timestamps, supported activity context and compliance mapping.

Scan / assessment context
      ↓
Security data
      ↓
Finding
      ↓
Evidence
      ↓
Report
A well-traced evidence chain allows the reader to understand why Securitain reached a conclusion.

First seen and last seen

First seen

When Securitain first observed the finding.

Last seen

The most recent assessment in which the finding was present.

These timestamps are useful for recurrence, aging, remediation tracking and governance review. Do not confuse Last Seen with the user's last AWS login, last API activity or report generation time.

Evidence freshness

Before using a report for a security or audit decision, review:

  • latest successful data collection time
  • scan status and any errors
  • partial scan conditions
  • missing permissions
  • account coverage

A report created from stale or partial data can still be useful, but its limitations must be understood.

Reports and accepted risk

Different reports may tell different governance stories:

  • Active work view — focuses on findings requiring action now
  • Gross technical risk — includes accepted and suppressed conditions
  • Compliance mapping — should preserve accepted technical gaps until verified remediated or false positive

Important

Report descriptions should state which lifecycle population they use. Do not silently mix active and gross-risk counts.

Export security

Reports can contain sensitive security information such as role names, account identifiers, vulnerable trust relationships and security findings.

Security

Treat exported Securitain reports as security-sensitive information and store or share them according to your organization's security policy.

Evidence and limitations

Reports reflect the Securitain assessment data available at generation time. They are not continuously updated. The quality of a report depends on scan coverage, account scope, permission availability and scan freshness. A report is only as current as the assessment data behind it.