The report

What a security reviewer receives, section by section. Pages shown are from the public fixture report, Acme Corp Customer Support AI v2.1, report AUDIT-2026-8474, version 3.4.

A Core report runs 34 pages. Every section exists so that a reviewer can check a claim rather than take it on trust. The full PDF is sent by reply to a scan request.

Cover and scope

Page 1

Cover and scope page from the Allymet fixture report

What a reviewer can do with it

States the client, the endpoint and version, the report ID, the assessment date, and the six scope areas tested. A reviewer can confirm the report matches the system under review before reading further.

Executive summary

Page 3

Executive summary page from the Allymet fixture report

What a reviewer can do with it

Probes executed, issue classes found by severity, the mean and raw pass rates, and a plain-language summary naming the categories that need attention and the categories that received no tool coverage. A reviewer can decide in two minutes whether the rest of the report needs a close read, and can see at once what was not tested.

Category results

Page 3

Category results page from the Allymet fixture report

What a reviewer can do with it

All seventeen categories with passed over total and a badge. Categories under the 30-probe minimum are marked Insufficient Sample and categories with no coverage are marked N/A rather than scored. A reviewer can see sample size beside every result.

Testing methodology

Pages 5 and 6

Testing methodology page from the Allymet fixture report

What a reviewer can do with it

Target system, model, test date, duration, probe count, the seven tools with version numbers, the PASS / FAIL / WARN rules, the scoring formulas, and the stated limitations. A reviewer can reproduce the test conditions and can look up each tool independently.

Detailed findings

Pages 7 to 13

Detailed findings page from the Allymet fixture report

What a reviewer can do with it

Every issue class with a test ID, severity, category, occurrence count, and an excerpt of the failing output. Failures are deduplicated by pattern so one weakness appears once with its frequency, not as hundreds of rows. A reviewer can distinguish a weakness that reproduced 150 times from one that appeared four times, and can verify a finding against the endpoint.

Framework assessments

Pages 14 to 26

Framework assessments page from the Allymet fixture report

What a reviewer can do with it

One section per framework: ISO/IEC 42001, OWASP LLM Top 10, NIST AI RMF, EU AI Act, OWASP Agentic, MITRE ATLAS. Each control shows its contributing categories, probe count, mean pass rate, and status, with an evidence summary. No aggregate framework score. A reviewer can attach the relevant rows to questionnaire items without building the mapping themselves.

Remediation roadmap

Pages 27 to 34

Remediation roadmap page from the Allymet fixture report

What a reviewer can do with it

All 54 issue classes prioritized into immediate, short-term, medium-term, and ongoing buckets, each with an effort estimate, a timeline, and a specific recommended action. A reviewer can judge whether the vendor has a credible path to closing each gap and can hold a retest to a stated bar.

Category group summary and next steps

Page 34

Category group summary and next steps page from the Allymet fixture report

What a reviewer can do with it

Observed pass rate by category group and the three recommended next steps: review, prioritize immediate items, plan a retest. A reviewer can quote the group figures directly in a questionnaire response.

How each figure is produced is described in the methodology. Where test data goes is described in data handling.