Skip to main content

Reports and stored files

A report is a reviewed deliverable built from saved case evidence. Rendering a report does not rerun its source searches. Open the relevant client space or asset scope, choose a case, then Reports.

Prepare and review​

  1. Save the observations you want to cite as evidence in the case. Distinguish collected observations from user-supplied information.
  2. Create a report draft and choose its evidence, title, summary, scope and recommendations. Configure available branding and layout options.
  3. Render a version and wait for the job to complete. Check Activity if you leave the editor.
  4. Read the rendered output before sharing. Versions capture a fixed snapshot; editing the draft does not rewrite an already rendered version.

A failed or incomplete render is not a published report. Review its diagnostic and available storage before trying again. Exceeding source limits produces an explicit failure rather than a silently truncated deliverable.

Publish deliberately​

Publish a reviewed version to selected named client accounts, or create an expiring guest link where permitted. A new report is not automatically visible to every member of a client organization. Guest links are separate access capabilities: only share them with intended recipients and revoke them when no longer needed.

Publication and email delivery are distinct states. Check Email deliveries for notification status and recipient preferences. A delivery failure does not mean the report version was deleted.

For recurring deliverables, use Scheduled reports. Schedules begin paused and require explicit authorization.

Share one evidence record​

In an organization engagement, open Evidence → More actions → Share evidence on the record you want to share. This action is available to staff with write access, for evidence that is not personal. It prepares a frozen report containing that evidence and its annotation. Discussion messages are not included.

  1. Choose a link lifetime of 1–30 days (seven by default). The lifetime starts when the link is ready, not when preparation begins.
  2. Confirm that the evidence and its annotation may be read by anyone holding the link, then choose Prepare guest link.
  3. Wait for Guest link ready and review the displayed expiry. If preparation is still pending or its outcome could not be confirmed, use Check preparation to continue the same request. A pending or failed preparation is not a ready link.
  4. Choose Copy link, Copy for Jira, or Copy for Slack/Teams. Open email opens a draft in your local mail application; it does not send a message. Formatted text offers a manual copy alternative.

Nothing is posted to Jira, Slack or Teams, and no email is sent automatically. The guest link is an access secret: give it only to intended recipients. Later changes to the source evidence do not rewrite the frozen report.

Closing the dialog does not cancel preparation or revoke a link. While you remain in the engagement, reopening the same record continues its attempt. Use Reports to manage the generated report and its guest access after leaving that view.

To stop access, choose Revoke link → Confirm revocation, or manage the link in Reports. If revocation cannot be confirmed, the link may still work: retry revocation rather than assuming it succeeded. Failed, expired or revoked shares are not silently replaced; Start a new share requires a new confirmation.

Private files and downloads​

Organization report and export files use private object storage with application encryption and a key specific to the organization. Downloads are authorized through Profundis; knowing a storage path does not grant access. Storage encryption complements membership and visibility checks and does not replace them.

Reports and exports share the allowance shown in Billing: 100 MiB in trial, 1 GiB in Teams and 5 GiB in Business. Search exports expire after their advertised retention period, normally seven days; download the files you need before that date.

Delete stored files​

Owners and administrators open Settings → Stored files to inspect file size, dates and expiry, and confirm deletion. Deleting a report version revokes its client and guest access immediately and removes its associated formats. Source evidence, case notes and the report draft remain.

To produce a new version, edit and save the draft as a new revision. An old link does not restore a deleted version. Storage is released after physical cleanup; pending deletions still count until cleanup succeeds. Deleting an export does not refund its collection cost or erase usage history.

For a complete organization archive or deletion, see Data retention.

Changes since the previous publication​

Choose the Changes over a period template and save the draft. The version panel previews a comparison against the previous published revision of the same report, in the same organization, space and case. Refresh the preview after updating its selected evidence. The first publication establishes a baseline.

The comparison counts:

  • Added evidence: selected evidence IDs absent from the previous publication.
  • Updated evidence or notes: the same evidence ID with a changed content hash or annotation. Separate case comments are not included in this counter.
  • Removed from report: evidence IDs no longer selected.
  • Unchanged: selected evidence with the same content and annotation.

These are changes to the report's evidence selection, not a fresh asset scan or an automatic security assessment. A different observation of the same asset has its own evidence ID. Removing evidence from a report does not mean an exposure has disappeared or a problem has been resolved. Previous removed content and its annotations are not copied into the new deliverable.

Rendering freezes the comparison in the signed snapshot. HTML and PDF include the summary and labels on current evidence; JSON includes the counts and current added/updated evidence IDs. CSV remains an evidence table. Later draft edits or publication changes do not rewrite an existing version. Scheduled changes reports use the same comparison rules; their approval period still determines which evidence enters each version.

Previewing or rendering the comparison does not run source searches, publish a version, or notify recipients. Review and publication remain separate actions.