Free client-ready template

A website security report your client can follow

Document a specific website security check, who fixed it, and what the retest showed. Read the fictional completed example, then copy the blank template or print it for your own authorized work. This template records security remediation; it is not a general SEO or performance audit.

Example: documenting a security header fix

Fictional example for illustration. These values are not a live scan or a customer report.

Client and scope
Example Studio · example.com · authorization recorded for this hostname.
Before the fix
14 Sep 2026, 09:00 UTC: the HTTPS response did not include X-Content-Type-Options.
Remediation and owner
The hosting engineer added X-Content-Type-Options: nosniff to the response configuration.
Same check, after the fix
14 Sep 2026, 09:15 UTC: the response included X-Content-Type-Options: nosniff.
Evidence to retain
The hostname, rule, timestamps and before-and-after header observations, alongside the configuration change record.
Client-ready conclusion
The expected header was observed on the retest. This example does not assess other headers, subdomains, application vulnerabilities or overall website security.

Client and authorized scope

Client
Add the reviewed value.
Authorized hostname
Add the reviewed value.
Scope and authorization reference
Add the reviewed value.
Report prepared on
Add the reviewed value.

Baseline observation

Finding or rule
Add the reviewed value.
Observation timestamp (UTC)
Add the reviewed value.
Observed value
Add the reviewed value.
Expected or reviewed baseline
Add the reviewed value.

Remediation

Owner
Add the reviewed value.
Action taken
Add the reviewed value.
Provider or interface
Add the reviewed value.
Change timestamp (UTC)
Add the reviewed value.

Same-rule retest

Retest timestamp (UTC)
Add the reviewed value.
Retest result
Add the reviewed value.
Observed value
Add the reviewed value.

Before and after comparison

Rule
Add the reviewed value.
Baseline
Add the reviewed value.
Retest
Add the reviewed value.
Change observed
Add the reviewed value.

Evidence reference

Evidence or content-hash reference
Add the reviewed value.
Related provider evidence
Add the reviewed value.
Immutable record or export reference
Add the reviewed value.

Residual limits

What was not checked
Add the reviewed value.
Point-in-time or environmental limitations
Add the reviewed value.
Follow-up owner
Add the reviewed value.

Bounded conclusion

State only what the authorized, deterministic observation showed. This report is evidence of the reviewed scope and rules; it is not a security certification, compliance assessment, or penetration test.