Reports and exports
Where every report format comes from and where findings can be sent.
Findings leave ScanSuite through several routes. Which ones apply depends on the engine, so this page collects them in one place.
Downloadable reports
Every finished scan has a Report button in Scan History. It downloads a ZIP archive containing the raw scanner output and the normalised reports.
| Format | Where it comes from |
|---|---|
| HTML | A standalone, scrollable report. AI reports carry the risk summary, reachability ordering and the call-path or reachability diagrams inline. |
| XLSX | Spreadsheet export, including the enriched infrastructure and dependency reports with their Exploit and Known Exploit columns. |
| JSON | The normalised findings, for feeding another system. |
| Markdown | The AI Pentest engagement write-up. |
| ZIP | The AI code documentation archive. |
Vulnerability management
Findings from every engine land in Vulnerability Management, which offers full-text search, filtering by product, severity and status, and a one-click Export to XLSX.
DefectDojo
Export is per scanner: each engine on the scan configuration page has its own Export to DefectDojo checkbox. Once findings are there, DefectDojo's own reporting, metrics and Jira integration apply — see Working with scan results.
Some engines do not export to DefectDojo at all. AI Native SAST, dependency reachability, AI DAST and AI Pentest findings are tracked in ScanSuite's own vulnerability management. Secrets and Hidden Paths are held back by default because of what the data contains.
Securitm
Nessus, OpenVAS and Nmap reports upload automatically to SGRC Securitm once the instance URL and API key are configured — see Export to Securitm.
Importing an external report
The Reports page accepts a report file produced outside ScanSuite and imports it into a DefectDojo engagement. Choose the engagement, the report type, and upload the file.
This route requires DefectDojo to be configured. Without it the import is refused, because there is nowhere to put the findings.
Alerts
Email and Telegram notifications can be configured in Settings. They cover scan events and asset changes — a new asset appearing, or an existing one changing its ports or severity.
Last reviewed 2026-08-16