Sample deliverables
See exactly what you get before you commission it.
Most security vendors will not show you a report until you have signed. We will. Every deliverable below is a real Threatsys artefact with the client details removed.

- PDF, redacted
VAPT assessment report
The full structure: executive summary, risk methodology, findings with reproduction steps, payloads and remediation guidance.
- Board-readable executive narrative
- One worked finding, end to end
- Severity model explained
- Re-test record
- PDF
Certificate of assessment
What your auditor or customer receives, and what the verification page checks against. Every certificate carries a unique ID.
- Scope statement
- Assessment window and methodology
- Unique verifiable ID
- Signatory and empanelment reference
- XLSX
ISO 27001 evidence register
Annex A control to evidence mapping with owner, frequency and retention, so nothing is missing on audit day.
- Control by control mapping
- Owner and cadence per artefact
- Common non-conformities
- Internal audit checklist
- PDF
DPDP gap assessment
Where you stand against the DPDP Act 2023, what it will take to close each gap, and in what order.
- 150 obligations assessed
- Gap severity and effort
- Sequenced remediation plan
- Evidence requirements
- XLSX
Vendor risk assessment pack
Tiered questionnaires, scoring model and escalation thresholds for your third-party programme.
- Tiered by vendor criticality
- Scoring and thresholds
- Contract clause suggestions
- Reassessment cadence
- PDF
Re-test and closure report
Issued free after you remediate. Confirms each finding is closed, with the evidence that proves it.
- Finding by finding verification
- Residual risk statement
- Closure sign-off
- Included in every engagement
Want the full unredacted set under NDA?
We will share complete samples, including a full report from an engagement in your sector, once an NDA is in place.












