Free client-ready template
A website security report your client can follow
Document a specific website security check, who fixed it, and what the retest showed. Read the fictional completed example, then copy the blank template or print it for your own authorized work. This template records security remediation; it is not a general SEO or performance audit.
Example: documenting a security header fix
Fictional example for illustration. These values are not a live scan or a customer report.
- Client and scope
- Example Studio · example.com · authorization recorded for this hostname.
- Before the fix
- 14 Sep 2026, 09:00 UTC: the HTTPS response did not include X-Content-Type-Options.
- Remediation and owner
- The hosting engineer added X-Content-Type-Options: nosniff to the response configuration.
- Same check, after the fix
- 14 Sep 2026, 09:15 UTC: the response included X-Content-Type-Options: nosniff.
- Evidence to retain
- The hostname, rule, timestamps and before-and-after header observations, alongside the configuration change record.
- Client-ready conclusion
- The expected header was observed on the retest. This example does not assess other headers, subdomains, application vulnerabilities or overall website security.
Client and authorized scope
- Client
- Add the reviewed value.
- Authorized hostname
- Add the reviewed value.
- Scope and authorization reference
- Add the reviewed value.
- Report prepared on
- Add the reviewed value.
Baseline observation
- Finding or rule
- Add the reviewed value.
- Observation timestamp (UTC)
- Add the reviewed value.
- Observed value
- Add the reviewed value.
- Expected or reviewed baseline
- Add the reviewed value.
Remediation
- Owner
- Add the reviewed value.
- Action taken
- Add the reviewed value.
- Provider or interface
- Add the reviewed value.
- Change timestamp (UTC)
- Add the reviewed value.
Same-rule retest
- Retest timestamp (UTC)
- Add the reviewed value.
- Retest result
- Add the reviewed value.
- Observed value
- Add the reviewed value.
Before and after comparison
- Rule
- Add the reviewed value.
- Baseline
- Add the reviewed value.
- Retest
- Add the reviewed value.
- Change observed
- Add the reviewed value.
Evidence reference
- Evidence or content-hash reference
- Add the reviewed value.
- Related provider evidence
- Add the reviewed value.
- Immutable record or export reference
- Add the reviewed value.
Residual limits
- What was not checked
- Add the reviewed value.
- Point-in-time or environmental limitations
- Add the reviewed value.
- Follow-up owner
- Add the reviewed value.
Bounded conclusion
State only what the authorized, deterministic observation showed. This report is evidence of the reviewed scope and rules; it is not a security certification, compliance assessment, or penetration test.