Documentation
Griffin

REPORTS AND STANDARDS

Understand reports and OWASP coverage

Read Griffin report snapshots, interpret OWASP Top 10:2025 and ASVS 5.0.0 evidence states, and export the same redacted results.

Generate and select a report

  1. Open Reports and keep the Reports tab selected.
  2. Choose the application whose completed scan history and findings should be included.
  3. Select Generate report once and wait for the reproducible report confirmation.
  4. Select the application name in the reports table to use that immutable snapshot in Coverage and Exports.

Interpret OWASP Top 10:2025 coverage

The Coverage tab lists all ten categories from the 2025 edition. Mapping set 2026.2 identifies the versioned Griffin mapping rules used by the report.

  • Observed — a related passive observation produced a warning or failure. Griffin did not fully test the category.
  • Tested no finding — a related passive observation completed without a finding. This is not a category pass.
  • Not tested — no approved passive observation in this report snapshot tested the category.
  • Not applicable — the related passive observation did not apply to the authorized target response.
  • Not externally testable — the related observation was unavailable from Griffin's bounded external response.
  • Explanation and provenance name the related measurement and report evidence boundary without exposing response bodies, cookies, credentials, or other secret values.

Interpret ASVS 5.0.0 coverage

The Coverage tab includes all 345 requirements from the pinned ASVS 5.0.0 edition. Use Requirement, Level, and Disposition filters to narrow the immutable report snapshot without changing it.

Each row identifies the evidence pathway and explains what Griffin observed or why another review method is needed.

  • Automated observational evidence — a related bounded response observation is available. It informs the requirement but does not verify the whole requirement.
  • Customer or manual evidence — customer-supplied records or reviewer work are the appropriate evidence pathway and remain separate from scanner output.
  • Not tested — the report snapshot contains no approved evidence for the requirement.
  • Not applicable — a recorded review determined that the requirement does not apply.
  • Not externally testable — the requirement is outside Griffin's bounded public-origin observation boundary.
  • Evidence provenance names the scan, target, checker version, mapping set, measurement, evaluation state, result, and observation completeness without exposing evidence values.
  1. Open Reports, select an immutable report, and choose Coverage.
  2. Find OWASP ASVS 5.0.0 below the Top 10 matrix.
  3. Search by version-qualified requirement ID or description, then optionally select a level and disposition.
  4. Review the evidence channel, provenance summary, and explanation before deciding what customer or reviewer evidence is still required.

Export and reproduce the same snapshot

  • JSON contains the complete redacted report contract, including ten Top 10 categories and 345 ASVS requirements.
  • CSV contains bounded finding and coverage rows with ASVS levels, dispositions, evidence channels, explanations, and separate provenance counts without evidence payloads.
  • PDF presents the management summary, findings, authorized scope, requirement dispositions, coverage states, and risk decisions in a readable report.
  • Every export is generated from the selected immutable report, is tenant-authorized, and expires according to the tenant retention policy.
  1. Select a report on the Reports tab.
  2. Open Exports and select Generate JSON, Generate CSV, or Generate PDF.
  3. Wait for the success message, then use Download while the artifact remains available.
Was this page helpful?