Current Doc

Security Attestation Report

Use Browse Docs to switch sections and search the full docs list.

Documentation

Blue Lantern Security Docs

Learn how to use the marketplace, run security tools, and integrate via the API.

Security Attestation Report

A printable, summary-level document of your monitoring posture, the evidence cyber insurers and larger customers increasingly ask for.

The Security Attestation Report is generated on demand from the Monitoring Hub's Security Report view with the Download attestation report button (account admins only). It opens in a new tab with a Print / Save as PDF button, and falls back to downloading an HTML file if your browser blocks the popup. Every figure comes from live data at generation time, over a 7-day reporting window, with each monitored device counted once by its latest report.

What it contains

  • Summary tiles: devices monitored, MFA coverage, mailboxes monitored, mail checks passed, and AI apps with data access.
  • Device Posture: the number of devices reporting in the window, then one table per platform (macOS, Windows) listing every scored check with how many devices are failing it. This section is EDR-vendor-blind: checks from the CrowdStrike Falcon and Microsoft Defender integrations appear alongside the agent's own checks.
  • Identity Posture: the latest daily identity scan, users checked, MFA coverage, and the per-check results (MFA and dormancy).
  • Mail Posture: one block per connected provider (Google Workspace and Microsoft 365 both appear) with its latest scan, checks passed, and each forwarding, inbox-rule, and mail-authentication check with its result.
  • AI Exposure: a PII-free inventory of third-party OAuth grants over org data, one block per provider: how many AI apps hold grants, how many reach mail, files, or calendars, how many users granted AI tools access, and how many unverified apps hold data scopes, plus the per-app check rows.
  • Mailbox Coverage: active members versus monitored mailboxes, and the email integrations with their status and last sync.
  • Monitoring Instrumentation: counts of device monitors, web and mail extensions, org integrations, and alert rules.
  • Monitoring Activity: how many email, website, file, identity, mail posture, and AI exposure scans were scored in the window, as evidence that monitoring is actually running.

What it deliberately leaves out

The document is written to leave your organization, so it is summary-level by design. It contains no per-device roster (hostnames often embed people's names), no per-user rows (per-user findings are rolled up into counts before anything is written), no alert-rule targets or secrets, and no roll-up verdict words; the per-check pass/fail results let a reviewer reach their own determination. Any section whose data could not be loaded at generation time says so rather than showing stale numbers.

Getting a useful report

The report only reflects what you monitor, so coverage drives its value:

  1. Connect an org email integration so Mailbox Coverage and Mail Posture have data, and enable the daily identity, mail posture, and AI exposure scans in the integration's settings.
  2. Install device agents (or connect Falcon or Defender) so Device Posture is populated.
  3. Create at least one alert rule; it counts as monitoring instrumentation.
  4. Generate the report inside the 7-day window after those scans have run.

If you would rather have an assessor produce the evidence for a specific insurance application, the Cyber Security Snapshot is the guided, one-time version of this report.

Need Help?

Can't find what you're looking for? Reach out and we'll get back to you.

Contact Support