Audit Reports
An audit report organizes detected risks into findings that can be reviewed by users, developers, and third-party services.
A finding can contain a title, severity, affected code location, description, evidence, impact, proof-of-concept or triggering conditions, remediation, and unresolved assumptions.
Reports produced from verified source can reference original files and lines. Reports based on a reconstruction depend on evidence recovered from deployed bytecode. SUMUN identifies the source origin so readers can interpret confidence and limitations correctly.
No detected finding means that the analysis did not identify a reportable issue within its available evidence and coverage. It does not prove that no vulnerability exists.