| customer_slug | Stable identifier; matches the /audits/<slug> page. |
| customer_name | Canonical organisation name. |
| customer_website | The organisation's own site, where known. |
| project_name | The engagement as recorded in our tracker. |
| month | YYYY-MM. Month precision by policy; we do not publish exact dates. |
| retest_month | Present when the engagement included a remediation re-test. |
| kind | Audit, Pentest, Risk Assessment, Dev or Research. |
| team_size | Auditors plus technical lead. 0 means not recorded, not zero people. |
| critical / high / medium / low / info | Findings by severity from our issue tracker. |
| findings_total | Sum of the severity columns. |
| tags | Protocol and technology labels from the public audits index. |
| report_urls | Published PDF reports, semicolon-separated. |
| client_confirmation_urls | Evidence hosted on domains we do not control. |
Every row is generated from our internal engagement tracker and the public audits index at github.com/Decurity/audits. It is regenerated when the record changes, and the generated file is committed so its history is auditable.
What it deliberately excludes: individual researcher names, remediation status, reviewed commits, audited repository URLs, and any engagement whose client has not agreed to be named. A significant share of our work is under NDA and is not represented here at all, so treat 146 as a floor rather than a total.
Licensed CC BY 4.0. Use it, cite it, check our arithmetic against it. Per-organisation pages are at /audits.
Join the 62 organisations in this dataset.