# Bastion — Bank-Readiness Summary **Asset:** audioprism.pro (saas) · **Depth:** Adversarial · **Mode:** public-verified · **Assessed:** 2026-09-13 18:08 UTC > One-page synthesis for a CISO / vendor-risk / audit reviewer. Every figure below comes from a **read-only, authorized-only** assessment and is reproducible from the signed artifacts in this bundle. "Passed / exercised" means a mapped check **actually ran to completion this scan** (runtime-proven via the execution ledger), never inferred from eligibility. ## Verdict | | | |---|---| | **Security posture** | **STRONG — 85/100** | | **Release gate** | ✅ PASS | | Findings | 0 critical · 0 high · 1 medium · 3 low · 3 info | | Catastrophic / immediate-action | 0 / 0 | | Indicative peak risk | CVSS 5.6 (Medium) — _indicative, derived from observed signals; not a measured CVSS vector_ | | Assessment coverage | 28/28 checks ran to completion · 4/4 external modules executed | ## Per-framework readiness (runtime-proven) _**Readiness**: a control counts as passed only if its mapped check ran to completion in this scan. The Executive Summary reports control **coverage** over the same frameworks — a broader measure that also counts items resolved to "review", so its numbers are higher by design._ | Framework | Verdict | Pass rate | Passed | Failed | Manual | |---|---|---|---|---|---| | OWASP Top 10 (2021) | ❌ NOT READY | 60% | 3 | 2 | 0 | | CWE | ❌ NOT READY | 82% | 14 | 3 | 0 | | PCI-DSS v4.0 | ❌ NOT READY | 70% | 7 | 3 | 0 | | OWASP ASVS | ❌ NOT READY | 77% | 10 | 3 | 0 | | CIS Controls v8 | ❌ NOT READY | 63% | 5 | 3 | 0 | | SOC 2 TSC | ❌ NOT READY | 40% | 2 | 3 | 0 | | NIST CSF | ❌ NOT READY | 67% | 6 | 3 | 0 | | ISO 27001:2022 | ❌ NOT READY | 71% | 5 | 2 | 0 | _Scores the subset of each framework a read-only external scan reaches; the remainder requires manual / authenticated assessment (see the OWASP Top-10 matrix for explicit not-exercised status). Indicative for audit prep, not a formal certification._ ## External posture modules Additional read-only modules executed in this full scan, beyond the 28 surface checks: | Module | Status | Result | |---|---|---| | TLS / crypto grade | ✅ ran | grade A+ | | DNS / email authentication | ✅ ran | grade B | | Exposed network services | ✅ ran | 4 open port(s) | | Vulnerable dependencies | ✅ ran | no issues found | ## Assurance & verification - **Methodology:** external, read-only (GET / HEAD / OPTIONS only); no exploitation. Findings that require active or authenticated testing are flagged for manual validation, never asserted as proven. - **Tamper-evident bundle:** every artifact in this report set is hashed in the accompanying `*.manifest.json`; the posture attestation is SHA-256 stamped — verify with `node cli.js verify-attestation .attestation.json`. - **Reproducible:** re-running the same authorized scan reproduces these findings; the full request log is retained in the JSON report.