OPEN DATA

The whole record, as data

A machine-readable dataset of every Decurity security engagement: 146 engagements for 62 organisations, 1356 findings by severity, and links to 56 published reports. JSON and CSV, CC BY 4.0.

audits.jsonaudits.csvJSON Schema
WHAT IS IN IT
146
ENGAGEMENTS
62
ORGANISATIONS
1356
FINDINGS
56
PUBLISHED REPORTS
FIELDS
customer_slugStable identifier; matches the /audits/<slug> page.
customer_nameCanonical organisation name.
customer_websiteThe organisation's own site, where known.
project_nameThe engagement as recorded in our tracker.
monthYYYY-MM. Month precision by policy; we do not publish exact dates.
retest_monthPresent when the engagement included a remediation re-test.
kindAudit, Pentest, Risk Assessment, Dev or Research.
team_sizeAuditors plus technical lead. 0 means not recorded, not zero people.
critical / high / medium / low / infoFindings by severity from our issue tracker.
findings_totalSum of the severity columns.
tagsProtocol and technology labels from the public audits index.
report_urlsPublished PDF reports, semicolon-separated.
client_confirmation_urlsEvidence hosted on domains we do not control.
PROVENANCE AND LIMITS

Every row is generated from our internal engagement tracker and the public audits index at github.com/Decurity/audits. It is regenerated when the record changes, and the generated file is committed so its history is auditable.

What it deliberately excludes: individual researcher names, remediation status, reviewed commits, audited repository URLs, and any engagement whose client has not agreed to be named. A significant share of our work is under NDA and is not represented here at all, so treat 146 as a floor rather than a total.

Licensed CC BY 4.0. Use it, cite it, check our arithmetic against it. Per-organisation pages are at /audits.

Request an audit

Join the 62 organisations in this dataset.

REQUEST FORM