An evidence report for security review, built from your staging traces.
The customer report separates scope, scenario verdicts, trace evidence, limitations, fixes, and retest. The public PDF shows the format only; it is not customer execution evidence.
If your gate already holds, that is still useful. The output becomes a buyer-readable PASS evidence pack, not a bug report: actor, target, authorization source, tool result, and side-effect outcome.
✓Executive summary for founders and security reviewers
✓Scenario matrix with benign controls and strict verdicts
✓Runtime trace evidence, tool calls, and observed vs. required authorization source
✓Severity, OWASP/NIST mapping, and concrete application-layer fixes