Reports and Data¶
Use this section to open the right report, understand its organization, and investigate results. For what PostQ discovers, assesses, and leaves for further review, start with Product Features.
Choose a starting point¶
| Review task | Guide |
|---|---|
| Understand the scan's counts and open affected groups or files | Assessment Overview |
| Follow a result's evidence, explanation, and next actions | Interpret Results |
| Inspect individual cryptographic calls and their settings | Crypto Functions |
| Review related calls as an operation | Operation Groups |
| Identify files for loading, automation, or exchange | Report File Reference |
Open a completed scan from your IDE, or load the scan folder in the Report Viewer. Start with Assessment, open a relevant selection, and inspect the group or function evidence before recording a decision.
Keep related reports together¶
Use reports from the same scan. PostQ JSON reports include schemaVersion, generatedAt, and
scanSession to identify their format, generation time, and scan. CBOM and SARIF carry equivalent
identification in their standard metadata.
Retain manifest.json with the report set and record the source revision used for review.
Mixing scans or incompatible report versions can give an incomplete view. Loading only one file
can leave related details unavailable.
Share and retain results¶
Export a selected set of functions or groups for a focused handoff, and keep the complete scan for supporting evidence. Use Sharing Reports for CBOM, SARIF, and recipient-tool considerations.
Reports can contain source paths, excerpts, and security-sensitive settings. Store and share them through approved locations. License contents and customer identity from the license are not included in scanner reports. See Security and Privacy.