Reports & findings
Published work, or nothing at all.
Every completed engagement whose client permits publication appears here with the full report. We do not list logos we cannot link to a report, and we do not count private engagements in public numbers.
SENTRYX is a new brand. This portfolio is being built in public.
The only entry below today is a clearly-labelled illustrative sample — a constructed report that shows our format, not a client engagement. As real audits complete and clients approve publication, they are added to data/reports.js and appear here with a link to the report and, where available, the repository. Until then this page stays honest and mostly empty. That is the point.
Evaluating us without a portfolio? Read the methodology, open the sample report to judge the depth of the analysis, and read what we say we are not. Then ask us for a paid trial on a single contract before committing to a full engagement — we would rather earn it that way.
No reports match those filters yet.
What gets published
Our disclosure policy.
Publication is the client's decision, always. These are the rules we hold ourselves to regardless.
Nothing without consent
No report, client name, finding or statistic is published without the client's written approval. An engagement can stay entirely private and still be complete.
No live unfixed Criticals
We do not publish a Critical or High that is still exploitable on a live system, regardless of who wants it out. Disclosure follows remediation, or a coordinated timeline agreed with the team.
Findings, not just conclusions
A published report includes the findings we raised and their final status — including the ones the team chose to acknowledge rather than fix, with their reasoning. A report showing only fixed issues is a marketing document.
Illustrative material is labelled
Anything on this site that is a constructed example carries a visible label and an HTML comment in the source. You should never have to guess whether a number is real.
No invented metrics
“Value secured” and “protocols protected” figures are trivially inflatable and we do not publish them. Where a counter exists on this site it is either linkable or shown as an explicit placeholder.
Incidents, honestly
If a protocol we audited is exploited through something we should have caught, we say so publicly and publish the analysis. That is the only way an audit report means anything.
Judge the work
Read the sample report before you read our pitch.
The Aurora Vault sample is illustrative, but the depth of analysis, the PoCs and the remediation guidance are exactly what a real engagement delivers.