Is a penetration test report genuine? Verify it yourself in the browser.

A pentest report is often the piece of evidence an auditor, client or regulator relies on. Yet a PDF can be changed in a couple of minutes: a finding removed, a date altered, or an entire report faked with the right logo. That is why every Resync report is digitally signed, so anyone can check its authenticity themselves. With no involvement from Resync, and without uploading the file.

The problem: a PDF believes anything

A pentest report passes through many hands. It goes from the tester to the client, from the client to a customer asking for evidence, and from that customer to an auditor or insurer. Along the way it is rarely checked whether the document was altered en route. That is a real risk, because editing a PDF takes no special skill.

Consider the obvious scenarios. A supplier quietly removes the two critical findings before the report goes to a large customer. Someone changes the test date so that an expired report looks "recent" again. Or a party that was never tested puts together a report of its own with a borrowed template and a familiar logo. In all three cases the end result looks perfectly normal.

As long as authenticity rests only on trust and on appearance, a report is only as reliable as the most rushed link in the chain. For a document meant to serve as evidence, that is not enough.

Why this matters to auditors and CISOs

If you receive reports rather than write them, you carry the risk. A CISO who files a supplier report, a buyer who ticks off a vendor risk assessment, an auditor who accepts a pentest report as evidence of technical security: all of them rely on the document matching what the tester actually delivered.

Under growing compliance pressure (NIS2, ISO 27001, NEN 7510, SOC 2, DORA), a pentest report is increasingly used as formal evidence. Precisely then, the question "how do I know this report is authentic and unaltered?" is no longer a detail, but a check you should be able to perform. Ideally yourself, in seconds, without having to call the supplier.

Verify right now

Received a Resync report and want to check it now? Go to re-sync.nl/verify, drop the PDF in and you will immediately see whether the report is genuine and unaltered. The file stays on your device.

The solution: a digital signature on every report

On delivery, Resync signs every report with a digital signature based on Ed25519, a modern and widely trusted form of cryptography. That signature records two things: that the report comes from Resync, and that the contents are exactly as they were at signing. Change even a single byte in the document and the signature no longer matches.

The nice part is that verifying requires no special software and does not depend on Resync. The signature belongs to a public key that is free to check. Anyone holding the report can independently establish whether it is valid. Forging a signature is only possible with the matching private key, and that key stays offline and never leaves our environment.

How to verify a report in three steps

  1. Open the verification page. Go to re-sync.nl/verify. You do not need an account and nothing to install.
  2. Choose the PDF report. Drop the PDF into the box or click to select it. The file is read locally in your browser and is not sent anywhere.
  3. Read the result. Within a moment you see whether the report is genuine and unaltered, plus the recorded details such as title and delivery date.

In practice there are only a few possible outcomes, and they are all unambiguous:

  • Genuine and unaltered. The signature is valid and the contents match exactly what was signed. You can trust the report.
  • Altered after delivery. The report was signed at some point, but the contents were changed afterwards. The signature no longer matches.
  • Not from Resync or unsigned. No valid Resync signature is present. In that case, do not treat the document as a verified Resync report.

The check deliberately fails "closed": when in doubt, the outcome is never "probably fine", but always a clear rejection. This prevents an altered or forged report from being accidentally marked as genuine.

Why it runs entirely in your browser

Verification happens entirely on your own device, using the browser's built-in cryptography (Web Crypto). There is no server, no upload and no storage. That is a deliberate choice, for two reasons.

Confidentiality. A pentest report contains sensitive information about your systems. It would make no sense to send exactly that document to an external service just to check its authenticity. With this approach the file never leaves your device.

Verifiability. Because nothing goes to Resync, you do not have to take us at our word either. The signature and the public key do the work. You verify the report with mathematics, not with a promise. A third party, such as your auditor, can run the very same check independently.

Curious what a real Resync report looks like, signature included? View a complete sample report and check it yourself straight away.

View a sample report →

What this says about how we work

Verifiability is not an extra for us, but a logical consequence of the craft. A penetration test is about making security demonstrable. That principle does not stop at the last page of the report. A report you cannot check asks you to take on trust what you should really be able to prove.

That is why every report is signed, the verification is public, and it works without us in between. It costs you a few seconds and it gives you, your customer and your auditor the same certainty: this is exactly the report that was delivered, unaltered.

In short

  • A PDF pentest report is easy to alter or fake, and is rarely checked en route.
  • Every Resync report is digitally signed (Ed25519), so tampering or forgery stands out immediately.
  • You verify it yourself at re-sync.nl/verify, entirely in the browser, with no upload and no involvement from Resync.
  • The outcome is unambiguous: genuine and unaltered, or a clear rejection.

A report you can build on

Fixed price based on scope, retest included, and a report you can verify yourself. Reply within 1 business day.

Book free intake →