Orientation

Understand results and reports

Distinguish observations, unsigned snapshots, reports, signed Local Audit packages and receipt checks.

Read the scope before the conclusion

An asset identifies what you want to observe. An observation records one check at a particular time. A report presents that observation for reading; it is not a security score or source evidence by itself.

Open Assets to inspect history, or Reports to find a saved report. Read the target, time, method, findings and unresolved checks together. An undetermined result needs more information; it is not a pass. Exporting a report does not expand what was checked.

Different outputs have different checks

OutputWhat it containsWhat it does not establish
External Exposure snapshotRecorded public observations and digests identifying the source bytesSnapshots are unsigned; a digest does not authenticate an issuer or prove the target is secure
ReportA readable presentation derived from an observationIndependent source evidence, certification or a security guarantee
Local Audit ProofpackA signed receipt and detached ZIP signature, checked against pinned trust policy in the supported app flowHost security, source-system truth or permission to collect merely because package checks pass
Public receipt-only resultThe checks named by /verify for supported receipt JSONFull bundle verification, artifact-byte revalidation or universal acceptance of every package format

For the legacy public_exposure_review receipt profile, a conforming public receipt remains indeterminate when the required evidence and trust checks have not been independently completed. Read receipt verification for that separate technical path. Do not upload a whole Proofpack ZIP to the receipt-only tool.

Share a fixed report

An Owner previews the recipient projection, reviews its content and explicitly publishes a fixed revision. Sharing does not grant workspace membership. Recipients see only the selected report projection, not raw source attachments, member details or workspace history. Material unknowns and synthetic labels remain visible.

Use the existing password, expiry and revocation controls where offered. Revocation blocks subsequent access; it cannot recall a copy already viewed or downloaded. Email delivery and copying a link are separate actions. Review the recipient and report before sending. A later observation does not update an already published revision.

Comparison, Share, report/export and supported Linux imports are available under the free policy; no paid upgrade is required. Live purchasing is not activated.

Keep access and retention separate

The workspace retains saved assets and observations across sign-ins. Signing out does not delete them. Automatic retention/deletion is not implemented yet; contact Support about removal. Illustrative paid-plan retention periods are not a guarantee of current enforcement.

A later result can differ because the target, time or observation method changed. Compare the recorded scope and limitations before concluding that a risk appeared or was fixed. Expert interpretation is available through Expert help, under separately agreed scope.

Understand results and reports | WitnessOps