Transilience AI — Threat Intelligence Report Design System
Version: 4.0
Format: PDF (A4), ReportLab
Last Updated: February 24, 2026
1. Page & Document Configuration
| Property |
Value |
| Page Size |
A4 (595.28 × 841.89 pt) |
| Margins |
20mm all sides |
| Content Width (CW) |
555.28 pt (A4 width − 2 × 20mm) |
| Top Margin Offset |
+8 pt (28mm effective top) |
| Bottom Margin Offset |
+10 pt (30mm effective bottom) |
| Background Color |
#07040B (BG) — near-black with purple undertone |
| Output |
Embedded fonts, single PDF file |
2. Typography
2.1 Font Stack
| Alias |
Font |
Weight |
Role |
FH |
Poppins-Bold |
700 |
Headlines, metric values, section numbers, score values |
FM |
Poppins-Medium |
500 |
Subheads, section labels, card section headers, sidebar labels |
FR |
Poppins (Regular) |
400 |
Footer text, metadata labels, TOC sub-items |
FL |
Poppins-Light |
300 |
Reserved (registered, not actively used) |
FI |
Poppins-Italic |
400i |
Reserved (registered, not actively used) |
FB |
Carlito (Regular) |
400 |
Body text, card summaries, table cells, bullet content |
FBB |
Carlito-Bold |
700 |
Bold inline emphasis within body paragraphs |
FBI |
Carlito-Italic |
400i |
Confidentiality notices, closing statement |
FBBI |
Carlito-BoldItalic |
700i |
Registered for <b><i> combinations within Carlito |
FMONO |
Courier |
— |
MITRE technique IDs, CVE identifiers, subdomain names |
Family Registration: Carlito is registered as a full family (normal, bold, italic, boldItalic) enabling automatic style switching via ReportLab's <b> and <i> XML tags.
2.2 Type Scale
| Style Key |
Font |
Size |
Leading |
Color |
Alignment |
Usage |
ct |
Poppins-Bold |
36 pt |
44 pt |
#FFFFFF |
Left |
Cover title ("THREAT INTELLIGENCE", "REPORT") |
cc |
Poppins-Medium |
18 pt |
24 pt |
#8B5CF6 |
Left |
Cover client name |
h1 |
Poppins-Bold |
20 pt |
26 pt |
#FFFFFF |
Left |
Section titles |
h2 |
Poppins-Medium |
16 pt |
21 pt |
#FFFFFF |
Left |
Subsection titles |
h3 |
Poppins-Medium |
13 pt |
17 pt |
#8B5CF6 |
Left |
Sub-headers within sections |
tt |
Poppins-Medium |
13 pt |
18 pt |
#FFFFFF |
Left |
Card titles, posture item titles |
body |
Carlito |
12 pt |
17 pt |
#F0F2F5 |
Justify |
Body paragraphs |
bs |
Carlito |
11 pt |
15 pt |
#F0F2F5 |
Left |
Small body (table cells, metadata values) |
ts |
Carlito |
11 pt |
16 pt |
#F0F2F5 |
Justify |
Card description text |
label |
Poppins |
10 pt |
13 pt |
#E0E3E8 |
Left |
Cover metadata labels |
sl |
Poppins-Medium |
10 pt |
13 pt |
#8B5CF6 |
Left |
Table column headers |
bullet |
Carlito |
12 pt |
17 pt |
#F0F2F5 |
Left |
Bullet items (14pt leftIndent, 0 bulletIndent) |
notice |
Carlito-Italic |
10 pt |
14 pt |
#E0E3E8 |
Left |
Confidentiality footer |
2.3 Advisory Card Typography
| Element |
Font |
Size |
Color |
Notes |
| Serial + Severity Tag |
Poppins-Bold |
14 pt |
Severity color |
Format: #1 [CRITICAL] |
| Card Title |
Poppins-Bold |
14 pt |
#FFFFFF |
Same line as serial, leading 20pt |
| Metadata Row |
Carlito |
10 pt |
#F0F2F5 |
Labels in #8B5CF6, pipe-separated |
| Score Labels |
Poppins-Medium |
10 pt |
#F0F2F5 |
"SEVERITY", "RELEVANCE", "PRIORITY" |
| Score Values |
Poppins-Bold |
12 pt |
Dynamic color |
0.85 format |
| Score Band Label |
Poppins-Bold |
10 pt |
Dynamic color |
"HIGH", "MEDIUM", "LOW" (priority row only) |
| Section Headers |
Poppins-Medium |
10 pt |
#8B5CF6 |
"TECHNICAL DETAILS", "IMPACT CONTEXT", etc. |
| Detection Evidence Header |
Poppins-Medium |
10 pt |
#10B981 |
Green to distinguish from purple headers |
| Section Body |
Carlito |
11 pt |
#F0F2F5 |
leading 15pt |
| MITRE Label |
Carlito |
11 pt |
#F59E0B |
Amber for "MITRE Tactics:", "Techniques:" |
| CVE Label |
Carlito |
11 pt |
#3B82F6 |
Blue for "CVEs:" |
| CVE/Technique Values |
Courier |
10–11 pt |
#F0F2F5 |
Monospace for IDs |
| Relevance Bullets |
Carlito |
11 pt |
#F0F2F5 |
• symbol, 16pt leftIndent, leading 16pt |
| Source Link |
Carlito |
10 pt |
#3B82F6 |
Underlined |
3. Color Palette
3.1 Backgrounds
| Token |
Hex |
RGB |
Usage |
BG |
#07040B |
(7, 4, 11) |
Page background — deepest layer |
BG2 |
#0D0A14 |
(13, 10, 20) |
Reserved secondary background |
BGC |
#13101C |
(19, 16, 28) |
Card backgrounds, table header rows, metric boxes |
BGCA |
#1A1625 |
(26, 22, 37) |
Alternating table rows, progress bar track |
BGEL |
#18181B |
(24, 24, 27) |
Reserved elevated surface |
GL |
#1E1A2E |
(30, 26, 46) |
Table gridlines, footer bar background |
BS |
#2A2535 |
(42, 37, 53) |
Card/box border stroke (0.4pt width) |
3.2 Brand Colors
| Token |
Hex |
RGB |
Usage |
BP |
#6941C6 |
(105, 65, 198) |
Primary brand — TOC numbers, metric accents, section number ghost |
BPL |
#8B5CF6 |
(139, 92, 246) |
Primary light — h3 headers, card section headers, metadata labels, page numbers |
BM |
#C9317C |
(201, 49, 124) |
Magenta accent — third-party tech stack category |
3.3 Text Colors
| Token |
Hex |
Usage |
T1 |
#FFFFFF |
Brightest — headlines, card titles, tech names in evidence |
T2 |
#F0F2F5 |
Primary body — paragraphs, table cells, card content |
T3 |
#E0E3E8 |
Muted — labels, impact context field names, no-match text |
TM |
#CDD1D8 |
Most muted — fallback severity color |
3.4 Severity Colors
| Token |
Hex |
Severity |
Usage |
SC |
#EF4444 |
Critical |
Accent bars, score coloring, badges, immediate recommendations |
SH |
#FB923C |
High |
Accent bars, score coloring, badges, short-term recommendations |
SM |
#EAB308 |
Medium |
Accent bars, score coloring, badges, medium-term recommendations |
SL |
#22C55E |
Low |
Accent bars, score coloring, badges, security posture "STRONG" |
3.5 Accent Colors
| Token |
Hex |
Usage |
AB |
#3B82F6 |
Info blue — CVE labels, source links, "ASSETS" metric box |
AE |
#10B981 |
Emerald green — "Implemented" status, detection evidence header |
AA |
#F59E0B |
Amber — MITRE labels, analytics tech category |
3.6 Gradient Specification
The brand gradient is a linear interpolation between two endpoints used across multiple components:
| Property |
Start (left) |
End (right) |
| Red |
0.412 (105/255) |
0.788 (201/255) |
| Green |
0.255 (65/255) |
0.192 (49/255) |
| Blue |
0.776 (198/255) |
0.486 (124/255) |
| Hex equivalent |
#6941C6 (BP) |
#C9317C (BM) |
Rendered as: 80 discrete steps, left-to-right. Used in: page top rule (3.5pt), section dividers (2pt), cover separators (3pt), progress bars, card bottom dividers.
4. Component Library
4.1 GradientLine
A full-width or partial-width horizontal rule using the brand gradient.
| Property |
Value |
| Default height |
2 pt |
| Steps |
80 |
| Corner radius |
None (rectangular) |
| Usage |
Section dividers (full CW, 2pt), cover (full CW, 3pt), cover sub-separator (CW×0.35, 2pt), card bottom (CW×0.5, 1pt) |
4.2 GradientBar
A proportional progress bar with gradient fill and rounded track.
| Property |
Value |
| Track height |
12 pt |
| Track background |
BGCA (#1A1625) |
| Track corner radius |
3 pt |
| Fill |
Brand gradient, clipped to fraction width |
| Min fraction |
0.06 (floor) |
| Max width |
160 pt (default) |
4.3 CardBox
A bordered container with optional accent sidebar. Used for posture items, recommendations, methodology phases.
| Property |
Value |
| Background |
BGC (#13101C) |
| Corner radius |
6 pt |
| Border |
BS (#2A2535), 0.4 pt stroke |
| Accent bar |
4 pt wide, full height, left side, 2pt corner radius |
| Default padding |
11 pt |
| Content offset |
padding + 6pt (when accent present) |
4.4 MetricBox
A compact KPI display used in the executive summary row.
| Property |
Value |
| Height |
58 pt |
| Width |
(CW − 30) / 5 per box |
| Background |
BGC (#13101C) |
| Border |
BS 0.4pt stroke, 6pt corner radius |
| Top accent |
3pt colored bar across full width, 1pt corner radius |
| Value |
Poppins-Bold 22pt, centered, severity-colored |
| Label |
Poppins 9pt, centered, T2, 7pt from bottom |
4.5 SeverityBadge
A colored pill showing severity level.
| Property |
Value |
| Width |
60 pt |
| Height |
16 pt |
| Corner radius |
3 pt |
| Background |
Severity color fill |
| Text |
Poppins-Medium 9pt, centered |
| Text color |
White (critical/high/low), Black (medium) |
4.6 SectionNumber
A large decorative section number with ghost double-strike effect.
| Property |
Value |
| Width |
Full CW |
| Height |
38 pt |
| Front layer |
Poppins-Bold 42pt, rgba(105, 65, 198, 0.7) at (0, 0) |
| Ghost layer |
Poppins-Bold 42pt, rgba(140, 92, 230, 0.5) at (1, 1) — offset 1pt right and up |
4.7 ScoreRow
Three horizontal inline score bars stacked vertically.
| Property |
Value |
| Total height |
60 pt |
| Row height |
16 pt |
| Row padding |
4 pt |
| Bar max width |
CW × 0.48 |
| Bar height |
8 pt |
| Bar track |
BGCA, 3pt radius |
| Bar fill |
Severity color at 0.85 alpha, min 4pt width |
| Glow dot |
Circle at fill endpoint, severity color at 0.3 alpha, 5pt radius |
| Layout x-positions |
Label: 0, Value: CW×0.12 + 10, Bar: CW×0.22, Band: CW×0.72 + 10 |
Dynamic color rules:
| Score Type |
Thresholds |
| Severity |
≥0.75 → SC (red), ≥0.5 → SH (orange), else → SM (yellow) |
| Relevance |
≥0.6 → AE (green), ≥0.3 → AA (amber), else → T3 (muted) |
| Priority |
≥0.7 → SC (red), ≥0.5 → SH (orange), ≥0.3 → SM (yellow), else → T3 |
4.8 AccentBar (Card Top)
A thin colored bar at the top of each advisory card.
| Property |
Value |
| Width |
Full CW |
| Height |
4 pt |
| Corner radius |
2 pt |
| Color |
Severity color of the advisory |
4.9 TechStackBlock
A category block displaying technology items as a bulleted list.
| Property |
Value |
| Width |
CW × 0.48 |
| Background |
BGC, 5pt radius |
| Border |
BS 0.3pt stroke |
| Header bar |
22pt height, category color fill, 5pt radius |
| Header text |
Poppins-Medium 10pt, white, 10pt left offset |
| Item bullet |
2pt radius circle, category color, at (14, y+3) |
| Item text |
Carlito 10pt, T2, at (22, y) |
| Item spacing |
16pt vertical |
5. Page Template (dark_bg)
Applied to every page via onFirstPage and onLaterPages.
5.1 Background Fill
- Full page
BG (#07040B) rectangle
5.2 Top Gradient Rule
- Brand gradient (80 steps, BP → BM), 3.5pt height, full page width, positioned at page top
5.3 Footer Bar
| Property |
Value |
| Height |
26 pt |
| Background |
GL (#1E1A2E) |
| Left text |
Poppins 7pt, T3: TRANSILIENCE AI · Threat Intelligence Report · CONFIDENTIAL |
| Left offset |
20mm margin |
| Page number |
Poppins-Bold 9pt, BP — right-aligned |
| Page label |
Poppins 8pt, T2: Page — immediately left of number |
5.4 Left Accent Strip
- 2.5pt wide vertical bar, full page height minus footer,
rgba(105, 65, 198, 0.12), positioned at x=0
6. Radar Visualization
A custom Flowable rendering a polar threat radar.
6.1 Dimensions
| Property |
Value |
| Canvas size |
300pt + 100pt width, 300pt + 60pt height |
| Center |
(200, 180) |
| Max radius |
300 × 0.38 = 114 pt |
6.2 Background Glow
Concentric filled circles from max_r + 20 down to 0 (step −2), each with increasing alpha (0.03 → 0.05), color rgba(10, 5, 20, alpha).
6.3 Ring Grid
4 dashed concentric rings at 25%, 50%, 75%, 100% of max radius.
| Ring |
Fraction |
Label |
Label Color |
| Inner |
0.25 |
CRITICAL |
SC (#EF4444) |
| Mid-inner |
0.50 |
HIGH |
SH (#FB923C) |
| Mid-outer |
0.75 |
MEDIUM |
SM (#EAB308) |
| Outer |
1.00 |
LOW |
SL (#22C55E) |
- Ring stroke:
rgba(105, 65, 198, 0.3), 0.5pt, dash pattern (3, 3)
- Labels positioned along 15° angle from center at each ring's radius, Poppins-Medium 7pt
6.4 Sector Spokes
12 spokes at 30° intervals, representing attack surfaces:
Web Apps/API, Cloud/Infra, Network, Endpoints, Email, Mobile, IoT/OT, Data Storage, Identity, Third-Party, Physical, Social Eng.
- Spoke stroke:
rgba(105, 65, 198, 0.25), 0.3pt
- Labels: Poppins-Medium 9pt, white, at
max_r + 32 from center
- Alignment: centered if near vertical, left-aligned if right half, right-aligned if left half
6.5 Center Crosshair
- 16pt arms, color
rgba(140, 92, 230, 0.4), 0.4pt
- Center glow: 16 concentric circles,
rgba(105, 65, 198, 0.04 × (16−r))
6.6 Threat Points
Each threat plotted using theta_deg and radius_norm from data.
| Severity |
RGB |
Point radius |
| Critical |
(0.937, 0.267, 0.267) |
7 pt |
| High |
(0.984, 0.573, 0.235) |
5.5 pt |
| Medium |
(0.918, 0.702, 0.031) |
4.5 pt |
| Low |
(0.133, 0.773, 0.369) |
3.5 pt |
Three-layer rendering per point:
- Outer glow: severity color at 0.12 alpha, radius + 7pt
- Mid glow: severity color at 0.25 alpha, radius + 3pt
- Core dot: severity color at 0.9 alpha, exact radius
- Specular highlight: white at 0.3 alpha, offset (−0.15r, +0.15r), radius 0.35r
7. Advisory Card Structure
Cards are returned as flat lists of Flowables (not wrapped in CardBox), enabling ReportLab page-split. Between cards: CondPageBreak(220) — only breaks if <220pt space remains.
7.1 Card Layout (top to bottom)
| # |
Section |
Spacing After |
| 1 |
AccentBar (4pt, severity color) |
8pt |
| 2 |
Title — #{serial} [{SEVERITY}] {title} |
2pt (spaceAfter) |
| 3 |
Metadata Row — pipe-separated: Source │ Surface │ Status │ First Seen |
2pt + 10pt gap |
| 4 |
ScoreRow — 3 inline progress bars (60pt) |
12pt gap |
| 5 |
Summary — justified body text |
4pt + 6pt gap |
| 6 |
TECHNICAL DETAILS (conditional) — Tactics, Techniques, CVEs |
4pt per item + 6pt gap |
| 7 |
IMPACT CONTEXT (always shown) — Industries, Regions, Assets |
4pt per item + 6pt gap |
| 7b |
DETECTION EVIDENCE (conditional) — Techstack fingerprint matches |
3pt per item + 6pt gap |
| 8 |
RELEVANCE ANALYSIS (conditional) — Bullet-point reasoning |
4pt per item + 4pt gap |
| 9 |
Source Link — blue underlined URL |
0pt |
| 10 |
Bottom Divider — GradientLine at CW×0.5, 1pt height |
8pt before |
7.2 Metadata Row Format
Source: THREAT INTEL │ Surface: Endpoint / Email │ Status: NEW │ First Seen: 2026-02-24
Labels in BPL (#8B5CF6), values in T2, separator: unicode │ (U+2502) with 4-space padding.
Source label mapping: threat → THREAT INTEL, product → PRODUCT VULN, breach → BREACH INTEL.
7.3 Detection Evidence Format
• {TechName} — {evidence_string}
Tech name in T1 (white, bold), em-dash separator, evidence string in T2. Max 6 items per card.
7.4 Section Header Coloring
| Header |
Color |
| TECHNICAL DETAILS |
BPL (#8B5CF6) |
| IMPACT CONTEXT |
BPL (#8B5CF6) |
| DETECTION EVIDENCE |
AE (#10B981) — green to visually distinguish |
| RELEVANCE ANALYSIS |
BPL (#8B5CF6) |
8. Cover Page Layout
8.1 Structure (top to bottom)
| Element |
Configuration |
| Logo row |
3-column table: [Transilience logo (55×22mm), spacer, Client logo (38×27mm)], row height 28mm |
| Gap |
26mm |
| Gradient separator |
Full CW, 3pt height |
| Gap |
12mm |
| Title line 1 |
"THREAT INTELLIGENCE" — ct style (Poppins-Bold 36pt, white) |
| Title line 2 |
"REPORT" — ct style |
| Gap |
6mm |
| Client name |
cc style (Poppins-Medium 18pt, BPL) |
| Gap |
4mm |
| Sub-separator |
GradientLine CW×0.35, 2pt |
| Gap |
8mm |
| Metadata table |
6 rows, 2 columns (CW×0.3 label, CW×0.7 value) |
| Gap |
15mm |
| Confidentiality notice |
Carlito-Italic 10pt, T3 |
8.2 Metadata Fields
| Label |
Style |
| REPORT DATE |
Poppins 10pt T3 → value Carlito 11pt T2 |
| CLASSIFICATION |
Same |
| SECTOR |
Same |
| REGION |
Same |
| GENERATED BY |
Same |
| REPORT ID |
Same — format: TI-{CLIENT}-{YYYYMMDD} |
9. Table of Contents Layout
| Element |
Style |
| Title |
"TABLE OF CONTENTS" — h1 style |
| Divider |
GradientLine full CW, 2pt |
| Gap |
8mm |
| Main entry |
3-column table: section number (Poppins-Bold 13pt BP, 35pt col), title (Poppins-Medium 10.5pt T1), page (Poppins-Bold 11pt T1, right-aligned, 40pt col) |
| Entry separator |
0.3pt GL line below |
| Sub-entry |
Indented 15pt, Poppins 10pt, sub-number in T3, title in T2 |
10. Report Section Blueprint
10.1 Standard Section Header Pattern
Every numbered section follows this sequence:
SectionNumber(num) — decorative ghost number (38pt height)
- Section title in
h1 style (Poppins-Bold 20pt)
GradientLine(CW, 2) — full-width separator
Spacer(1, 4*mm) — breathing room
10.2 Section Inventory (12 sections)
| # |
Section |
Content Type |
| 01 |
Executive Summary |
MetricBox row + narrative + bulleted key findings |
| 02 |
Threat Landscape Overview |
Source distribution table + attack surface table |
| 03 |
Threat Radar Visualization |
RadarVisualization flowable + legend |
| 04 |
Critical Severity Advisories |
Advisory cards (PageBreak before section) |
| 05 |
High Severity Advisories |
Advisory cards (PageBreak before section) |
| 06 |
Medium Severity Advisories |
Advisory cards (PageBreak before section) |
| 07 |
Attack Surface Analysis |
Digital footprint table + subdomain inventory |
| 08 |
Asset Inventory & Crown Jewels |
Crown jewel CardBoxes + full inventory table |
| 09 |
Technology Stack Intelligence |
TechStackBlocks + security headers table |
| 10 |
Security Posture Assessment |
Status CardBoxes (6 items) |
| 11 |
Strategic Recommendations |
Tiered CardBoxes (Immediate/Short/Medium-term) |
| 12 |
Methodology & Data Sources |
Pipeline CardBoxes + scoring methodology + evidence table |
11. Spacing System
11.1 Vertical Rhythm
| Context |
Spacing |
| After section title |
8pt (h1 spaceAfter) |
| After gradient divider |
4mm (≈11.3pt) |
| Between card sections (within) |
4pt |
| Between card section groups |
6pt |
| After metadata row → scores |
10pt |
| After scores → summary |
12pt |
| After summary → tech details |
6pt |
| Between advisory cards |
CondPageBreak(220) |
| Between severity sections |
PageBreak() |
| Before Evidence Collection |
PageBreak() |
11.2 Table Padding
| Property |
Value |
| Top padding |
4–5 pt |
| Bottom padding |
4–5 pt |
| Left padding |
6–8 pt |
| Row separator |
0.5pt GL line |
12. Data-Driven Components
12.1 Evidence Map Architecture
Technology evidence is extracted from techstack_report.json and indexed by keyword. The extraction traverses:
technologies.frontend[] — name, evidence[].finding, evidence[].details
technologies.backend[] — web servers, frameworks, CMS, languages
technologies.infrastructure[] — DNS, CDN providers
technologies.security[] — WAF, certificates, headers, email security
technologies.third_party[] — analytics, collaboration tools
Each evidence item is indexed under multiple keywords derived from the technology name fragments. Alias mappings expand coverage (e.g., email → proofpoint, microsoft, dmarc).
12.2 Threat-Evidence Matching
get_threat_evidence(threat) scans the threat's title, summary, and threat_name against the keyword index. Returns up to 6 (tech_name, evidence_string) tuples. Deduplication by {tech_name}:{evidence} key.
12.3 Severity Sorting
All threats sorted by: severity rank descending (critical=4, high=3, medium=2, low=1), then prioritization_score descending. Split into four lists for section rendering.
13. Unicode Characters
| Character |
Code |
Usage |
│ |
U+2502 |
Pipe separator in metadata rows |
• |
U+2022 |
Bullet point in relevance analysis, detection evidence |
— |
U+2014 |
Em-dash in section headers, posture items, evidence items |
· |
U+00B7 |
Middle dot in footer text |
✔ |
U+2714 |
Reserved (previously used in evidence, now removed) |
• |
HTML entity |
Bullet in executive summary key findings |
14. Adaptive Behaviors
14.1 Page Break Strategy
| Transition |
Method |
| Between advisories (same severity) |
CondPageBreak(220) — break only if <220pt remains |
| Between severity sections |
PageBreak() — always new page |
| Before Evidence Collection |
PageBreak() — separate last page |
14.2 Card Splittability
Advisory cards return flat list[Flowable] instead of monolithic CardBox. This allows ReportLab's frame to split cards across page boundaries at any Paragraph/Spacer seam, eliminating blank pages.
14.3 Client Adaptation
The design system is client-agnostic. Customized per client:
- Cover: client logo, name, sector, region, report ID
- Executive summary: narrative and key findings
- Attack surface: domain/subdomain inventory
- Evidence map: keyword aliases tuned to client's tech stack
- Security posture: assessments specific to client's infrastructure
- Recommendations: actionable items specific to client's vulnerabilities
All visual elements (colors, typography, spacing, components) remain identical across clients.
1---2name: transilience-report-style3description: Transilience AI — Threat Intelligence Report Design System4---5# Transilience AI — Threat Intelligence Report Design System67**Version:** 4.0 8**Format:** PDF (A4), ReportLab 9**Last Updated:** February 24, 20261011---1213## 1. Page & Document Configuration1415| Property | Value |16|---|---|17| Page Size | A4 (595.28 × 841.89 pt) |18| Margins | 20mm all sides |19| Content Width (CW) | 555.28 pt (A4 width − 2 × 20mm) |20| Top Margin Offset | +8 pt (28mm effective top) |21| Bottom Margin Offset | +10 pt (30mm effective bottom) |22| Background Color | `#07040B` (BG) — near-black with purple undertone |23| Output | Embedded fonts, single PDF file |2425---2627## 2. Typography2829### 2.1 Font Stack3031| Alias | Font | Weight | Role |32|---|---|---|---|33| `FH` | Poppins-Bold | 700 | Headlines, metric values, section numbers, score values |34| `FM` | Poppins-Medium | 500 | Subheads, section labels, card section headers, sidebar labels |35| `FR` | Poppins (Regular) | 400 | Footer text, metadata labels, TOC sub-items |36| `FL` | Poppins-Light | 300 | Reserved (registered, not actively used) |37| `FI` | Poppins-Italic | 400i | Reserved (registered, not actively used) |38| `FB` | Carlito (Regular) | 400 | Body text, card summaries, table cells, bullet content |39| `FBB` | Carlito-Bold | 700 | Bold inline emphasis within body paragraphs |40| `FBI` | Carlito-Italic | 400i | Confidentiality notices, closing statement |41| `FBBI` | Carlito-BoldItalic | 700i | Registered for `<b><i>` combinations within Carlito |42| `FMONO` | Courier | — | MITRE technique IDs, CVE identifiers, subdomain names |4344**Family Registration:** Carlito is registered as a full family (`normal`, `bold`, `italic`, `boldItalic`) enabling automatic style switching via ReportLab's `<b>` and `<i>` XML tags.4546### 2.2 Type Scale4748| Style Key | Font | Size | Leading | Color | Alignment | Usage |49|---|---|---|---|---|---|---|50| `ct` | Poppins-Bold | 36 pt | 44 pt | `#FFFFFF` | Left | Cover title ("THREAT INTELLIGENCE", "REPORT") |51| `cc` | Poppins-Medium | 18 pt | 24 pt | `#8B5CF6` | Left | Cover client name |52| `h1` | Poppins-Bold | 20 pt | 26 pt | `#FFFFFF` | Left | Section titles |53| `h2` | Poppins-Medium | 16 pt | 21 pt | `#FFFFFF` | Left | Subsection titles |54| `h3` | Poppins-Medium | 13 pt | 17 pt | `#8B5CF6` | Left | Sub-headers within sections |55| `tt` | Poppins-Medium | 13 pt | 18 pt | `#FFFFFF` | Left | Card titles, posture item titles |56| `body` | Carlito | 12 pt | 17 pt | `#F0F2F5` | Justify | Body paragraphs |57| `bs` | Carlito | 11 pt | 15 pt | `#F0F2F5` | Left | Small body (table cells, metadata values) |58| `ts` | Carlito | 11 pt | 16 pt | `#F0F2F5` | Justify | Card description text |59| `label` | Poppins | 10 pt | 13 pt | `#E0E3E8` | Left | Cover metadata labels |60| `sl` | Poppins-Medium | 10 pt | 13 pt | `#8B5CF6` | Left | Table column headers |61| `bullet` | Carlito | 12 pt | 17 pt | `#F0F2F5` | Left | Bullet items (14pt leftIndent, 0 bulletIndent) |62| `notice` | Carlito-Italic | 10 pt | 14 pt | `#E0E3E8` | Left | Confidentiality footer |6364### 2.3 Advisory Card Typography6566| Element | Font | Size | Color | Notes |67|---|---|---|---|---|68| Serial + Severity Tag | Poppins-Bold | 14 pt | Severity color | Format: `#1 [CRITICAL]` |69| Card Title | Poppins-Bold | 14 pt | `#FFFFFF` | Same line as serial, leading 20pt |70| Metadata Row | Carlito | 10 pt | `#F0F2F5` | Labels in `#8B5CF6`, pipe-separated |71| Score Labels | Poppins-Medium | 10 pt | `#F0F2F5` | "SEVERITY", "RELEVANCE", "PRIORITY" |72| Score Values | Poppins-Bold | 12 pt | Dynamic color | `0.85` format |73| Score Band Label | Poppins-Bold | 10 pt | Dynamic color | "HIGH", "MEDIUM", "LOW" (priority row only) |74| Section Headers | Poppins-Medium | 10 pt | `#8B5CF6` | "TECHNICAL DETAILS", "IMPACT CONTEXT", etc. |75| Detection Evidence Header | Poppins-Medium | 10 pt | `#10B981` | Green to distinguish from purple headers |76| Section Body | Carlito | 11 pt | `#F0F2F5` | leading 15pt |77| MITRE Label | Carlito | 11 pt | `#F59E0B` | Amber for "MITRE Tactics:", "Techniques:" |78| CVE Label | Carlito | 11 pt | `#3B82F6` | Blue for "CVEs:" |79| CVE/Technique Values | Courier | 10–11 pt | `#F0F2F5` | Monospace for IDs |80| Relevance Bullets | Carlito | 11 pt | `#F0F2F5` | • symbol, 16pt leftIndent, leading 16pt |81| Source Link | Carlito | 10 pt | `#3B82F6` | Underlined |8283---8485## 3. Color Palette8687### 3.1 Backgrounds8889| Token | Hex | RGB | Usage |90|---|---|---|---|91| `BG` | `#07040B` | (7, 4, 11) | Page background — deepest layer |92| `BG2` | `#0D0A14` | (13, 10, 20) | Reserved secondary background |93| `BGC` | `#13101C` | (19, 16, 28) | Card backgrounds, table header rows, metric boxes |94| `BGCA` | `#1A1625` | (26, 22, 37) | Alternating table rows, progress bar track |95| `BGEL` | `#18181B` | (24, 24, 27) | Reserved elevated surface |96| `GL` | `#1E1A2E` | (30, 26, 46) | Table gridlines, footer bar background |97| `BS` | `#2A2535` | (42, 37, 53) | Card/box border stroke (0.4pt width) |9899### 3.2 Brand Colors100101| Token | Hex | RGB | Usage |102|---|---|---|---|103| `BP` | `#6941C6` | (105, 65, 198) | Primary brand — TOC numbers, metric accents, section number ghost |104| `BPL` | `#8B5CF6` | (139, 92, 246) | Primary light — h3 headers, card section headers, metadata labels, page numbers |105| `BM` | `#C9317C` | (201, 49, 124) | Magenta accent — third-party tech stack category |106107### 3.3 Text Colors108109| Token | Hex | Usage |110|---|---|---|111| `T1` | `#FFFFFF` | Brightest — headlines, card titles, tech names in evidence |112| `T2` | `#F0F2F5` | Primary body — paragraphs, table cells, card content |113| `T3` | `#E0E3E8` | Muted — labels, impact context field names, no-match text |114| `TM` | `#CDD1D8` | Most muted — fallback severity color |115116### 3.4 Severity Colors117118| Token | Hex | Severity | Usage |119|---|---|---|---|120| `SC` | `#EF4444` | Critical | Accent bars, score coloring, badges, immediate recommendations |121| `SH` | `#FB923C` | High | Accent bars, score coloring, badges, short-term recommendations |122| `SM` | `#EAB308` | Medium | Accent bars, score coloring, badges, medium-term recommendations |123| `SL` | `#22C55E` | Low | Accent bars, score coloring, badges, security posture "STRONG" |124125### 3.5 Accent Colors126127| Token | Hex | Usage |128|---|---|---|129| `AB` | `#3B82F6` | Info blue — CVE labels, source links, "ASSETS" metric box |130| `AE` | `#10B981` | Emerald green — "Implemented" status, detection evidence header |131| `AA` | `#F59E0B` | Amber — MITRE labels, analytics tech category |132133### 3.6 Gradient Specification134135The brand gradient is a linear interpolation between two endpoints used across multiple components:136137| Property | Start (left) | End (right) |138|---|---|---|139| Red | 0.412 (105/255) | 0.788 (201/255) |140| Green | 0.255 (65/255) | 0.192 (49/255) |141| Blue | 0.776 (198/255) | 0.486 (124/255) |142| Hex equivalent | `#6941C6` (BP) | `#C9317C` (BM) |143144**Rendered as:** 80 discrete steps, left-to-right. Used in: page top rule (3.5pt), section dividers (2pt), cover separators (3pt), progress bars, card bottom dividers.145146---147148## 4. Component Library149150### 4.1 GradientLine151152A full-width or partial-width horizontal rule using the brand gradient.153154| Property | Value |155|---|---|156| Default height | 2 pt |157| Steps | 80 |158| Corner radius | None (rectangular) |159| Usage | Section dividers (full CW, 2pt), cover (full CW, 3pt), cover sub-separator (CW×0.35, 2pt), card bottom (CW×0.5, 1pt) |160161### 4.2 GradientBar162163A proportional progress bar with gradient fill and rounded track.164165| Property | Value |166|---|---|167| Track height | 12 pt |168| Track background | `BGCA` (`#1A1625`) |169| Track corner radius | 3 pt |170| Fill | Brand gradient, clipped to fraction width |171| Min fraction | 0.06 (floor) |172| Max width | 160 pt (default) |173174### 4.3 CardBox175176A bordered container with optional accent sidebar. Used for posture items, recommendations, methodology phases.177178| Property | Value |179|---|---|180| Background | `BGC` (`#13101C`) |181| Corner radius | 6 pt |182| Border | `BS` (`#2A2535`), 0.4 pt stroke |183| Accent bar | 4 pt wide, full height, left side, 2pt corner radius |184| Default padding | 11 pt |185| Content offset | padding + 6pt (when accent present) |186187### 4.4 MetricBox188189A compact KPI display used in the executive summary row.190191| Property | Value |192|---|---|193| Height | 58 pt |194| Width | (CW − 30) / 5 per box |195| Background | `BGC` (`#13101C`) |196| Border | `BS` 0.4pt stroke, 6pt corner radius |197| Top accent | 3pt colored bar across full width, 1pt corner radius |198| Value | Poppins-Bold 22pt, centered, severity-colored |199| Label | Poppins 9pt, centered, `T2`, 7pt from bottom |200201### 4.5 SeverityBadge202203A colored pill showing severity level.204205| Property | Value |206|---|---|207| Width | 60 pt |208| Height | 16 pt |209| Corner radius | 3 pt |210| Background | Severity color fill |211| Text | Poppins-Medium 9pt, centered |212| Text color | White (critical/high/low), Black (medium) |213214### 4.6 SectionNumber215216A large decorative section number with ghost double-strike effect.217218| Property | Value |219|---|---|220| Width | Full CW |221| Height | 38 pt |222| Front layer | Poppins-Bold 42pt, `rgba(105, 65, 198, 0.7)` at (0, 0) |223| Ghost layer | Poppins-Bold 42pt, `rgba(140, 92, 230, 0.5)` at (1, 1) — offset 1pt right and up |224225### 4.7 ScoreRow226227Three horizontal inline score bars stacked vertically.228229| Property | Value |230|---|---|231| Total height | 60 pt |232| Row height | 16 pt |233| Row padding | 4 pt |234| Bar max width | CW × 0.48 |235| Bar height | 8 pt |236| Bar track | `BGCA`, 3pt radius |237| Bar fill | Severity color at 0.85 alpha, min 4pt width |238| Glow dot | Circle at fill endpoint, severity color at 0.3 alpha, 5pt radius |239| Layout x-positions | Label: 0, Value: CW×0.12 + 10, Bar: CW×0.22, Band: CW×0.72 + 10 |240241**Dynamic color rules:**242243| Score Type | Thresholds |244|---|---|245| Severity | ≥0.75 → `SC` (red), ≥0.5 → `SH` (orange), else → `SM` (yellow) |246| Relevance | ≥0.6 → `AE` (green), ≥0.3 → `AA` (amber), else → `T3` (muted) |247| Priority | ≥0.7 → `SC` (red), ≥0.5 → `SH` (orange), ≥0.3 → `SM` (yellow), else → `T3` |248249### 4.8 AccentBar (Card Top)250251A thin colored bar at the top of each advisory card.252253| Property | Value |254|---|---|255| Width | Full CW |256| Height | 4 pt |257| Corner radius | 2 pt |258| Color | Severity color of the advisory |259260### 4.9 TechStackBlock261262A category block displaying technology items as a bulleted list.263264| Property | Value |265|---|---|266| Width | CW × 0.48 |267| Background | `BGC`, 5pt radius |268| Border | `BS` 0.3pt stroke |269| Header bar | 22pt height, category color fill, 5pt radius |270| Header text | Poppins-Medium 10pt, white, 10pt left offset |271| Item bullet | 2pt radius circle, category color, at (14, y+3) |272| Item text | Carlito 10pt, `T2`, at (22, y) |273| Item spacing | 16pt vertical |274275---276277## 5. Page Template (dark_bg)278279Applied to every page via `onFirstPage` and `onLaterPages`.280281### 5.1 Background Fill282- Full page `BG` (`#07040B`) rectangle283284### 5.2 Top Gradient Rule285- Brand gradient (80 steps, BP → BM), 3.5pt height, full page width, positioned at page top286287### 5.3 Footer Bar288| Property | Value |289|---|---|290| Height | 26 pt |291| Background | `GL` (`#1E1A2E`) |292| Left text | Poppins 7pt, `T3`: `TRANSILIENCE AI · Threat Intelligence Report · CONFIDENTIAL` |293| Left offset | 20mm margin |294| Page number | Poppins-Bold 9pt, `BP` — right-aligned |295| Page label | Poppins 8pt, `T2`: `Page ` — immediately left of number |296297### 5.4 Left Accent Strip298- 2.5pt wide vertical bar, full page height minus footer, `rgba(105, 65, 198, 0.12)`, positioned at x=0299300---301302## 6. Radar Visualization303304A custom Flowable rendering a polar threat radar.305306### 6.1 Dimensions307308| Property | Value |309|---|---|310| Canvas size | 300pt + 100pt width, 300pt + 60pt height |311| Center | (200, 180) |312| Max radius | 300 × 0.38 = 114 pt |313314### 6.2 Background Glow315316Concentric filled circles from `max_r + 20` down to 0 (step −2), each with increasing alpha (0.03 → 0.05), color `rgba(10, 5, 20, alpha)`.317318### 6.3 Ring Grid3193204 dashed concentric rings at 25%, 50%, 75%, 100% of max radius.321322| Ring | Fraction | Label | Label Color |323|---|---|---|---|324| Inner | 0.25 | CRITICAL | `SC` (#EF4444) |325| Mid-inner | 0.50 | HIGH | `SH` (#FB923C) |326| Mid-outer | 0.75 | MEDIUM | `SM` (#EAB308) |327| Outer | 1.00 | LOW | `SL` (#22C55E) |328329- Ring stroke: `rgba(105, 65, 198, 0.3)`, 0.5pt, dash pattern (3, 3)330- Labels positioned along 15° angle from center at each ring's radius, Poppins-Medium 7pt331332### 6.4 Sector Spokes33333412 spokes at 30° intervals, representing attack surfaces:335336`Web Apps/API, Cloud/Infra, Network, Endpoints, Email, Mobile, IoT/OT, Data Storage, Identity, Third-Party, Physical, Social Eng.`337338- Spoke stroke: `rgba(105, 65, 198, 0.25)`, 0.3pt339- Labels: Poppins-Medium 9pt, white, at `max_r + 32` from center340- Alignment: centered if near vertical, left-aligned if right half, right-aligned if left half341342### 6.5 Center Crosshair343344- 16pt arms, color `rgba(140, 92, 230, 0.4)`, 0.4pt345- Center glow: 16 concentric circles, `rgba(105, 65, 198, 0.04 × (16−r))`346347### 6.6 Threat Points348349Each threat plotted using `theta_deg` and `radius_norm` from data.350351| Severity | RGB | Point radius |352|---|---|---|353| Critical | (0.937, 0.267, 0.267) | 7 pt |354| High | (0.984, 0.573, 0.235) | 5.5 pt |355| Medium | (0.918, 0.702, 0.031) | 4.5 pt |356| Low | (0.133, 0.773, 0.369) | 3.5 pt |357358**Three-layer rendering per point:**3591. **Outer glow:** severity color at 0.12 alpha, radius + 7pt3602. **Mid glow:** severity color at 0.25 alpha, radius + 3pt3613. **Core dot:** severity color at 0.9 alpha, exact radius3624. **Specular highlight:** white at 0.3 alpha, offset (−0.15r, +0.15r), radius 0.35r363364---365366## 7. Advisory Card Structure367368Cards are returned as flat lists of Flowables (not wrapped in CardBox), enabling ReportLab page-split. Between cards: `CondPageBreak(220)` — only breaks if <220pt space remains.369370### 7.1 Card Layout (top to bottom)371372| # | Section | Spacing After |373|---|---|---|374| 1 | **AccentBar** (4pt, severity color) | 8pt |375| 2 | **Title** — `#{serial} [{SEVERITY}] {title}` | 2pt (spaceAfter) |376| 3 | **Metadata Row** — pipe-separated: Source │ Surface │ Status │ First Seen | 2pt + 10pt gap |377| 4 | **ScoreRow** — 3 inline progress bars (60pt) | 12pt gap |378| 5 | **Summary** — justified body text | 4pt + 6pt gap |379| 6 | **TECHNICAL DETAILS** (conditional) — Tactics, Techniques, CVEs | 4pt per item + 6pt gap |380| 7 | **IMPACT CONTEXT** (always shown) — Industries, Regions, Assets | 4pt per item + 6pt gap |381| 7b | **DETECTION EVIDENCE** (conditional) — Techstack fingerprint matches | 3pt per item + 6pt gap |382| 8 | **RELEVANCE ANALYSIS** (conditional) — Bullet-point reasoning | 4pt per item + 4pt gap |383| 9 | **Source Link** — blue underlined URL | 0pt |384| 10 | **Bottom Divider** — GradientLine at CW×0.5, 1pt height | 8pt before |385386### 7.2 Metadata Row Format387388```389Source: THREAT INTEL │ Surface: Endpoint / Email │ Status: NEW │ First Seen: 2026-02-24390```391392Labels in `BPL` (`#8B5CF6`), values in `T2`, separator: unicode `│` (U+2502) with 4-space padding.393394Source label mapping: `threat` → `THREAT INTEL`, `product` → `PRODUCT VULN`, `breach` → `BREACH INTEL`.395396### 7.3 Detection Evidence Format397398```399• {TechName} — {evidence_string}400```401402Tech name in `T1` (white, bold), em-dash separator, evidence string in `T2`. Max 6 items per card.403404### 7.4 Section Header Coloring405406| Header | Color |407|---|---|408| TECHNICAL DETAILS | `BPL` (#8B5CF6) |409| IMPACT CONTEXT | `BPL` (#8B5CF6) |410| DETECTION EVIDENCE | `AE` (#10B981) — green to visually distinguish |411| RELEVANCE ANALYSIS | `BPL` (#8B5CF6) |412413---414415## 8. Cover Page Layout416417### 8.1 Structure (top to bottom)418419| Element | Configuration |420|---|---|421| Logo row | 3-column table: [Transilience logo (55×22mm), spacer, Client logo (38×27mm)], row height 28mm |422| Gap | 26mm |423| Gradient separator | Full CW, 3pt height |424| Gap | 12mm |425| Title line 1 | "THREAT INTELLIGENCE" — `ct` style (Poppins-Bold 36pt, white) |426| Title line 2 | "REPORT" — `ct` style |427| Gap | 6mm |428| Client name | `cc` style (Poppins-Medium 18pt, `BPL`) |429| Gap | 4mm |430| Sub-separator | GradientLine CW×0.35, 2pt |431| Gap | 8mm |432| Metadata table | 6 rows, 2 columns (CW×0.3 label, CW×0.7 value) |433| Gap | 15mm |434| Confidentiality notice | Carlito-Italic 10pt, `T3` |435436### 8.2 Metadata Fields437438| Label | Style |439|---|---|440| REPORT DATE | Poppins 10pt `T3` → value Carlito 11pt `T2` |441| CLASSIFICATION | Same |442| SECTOR | Same |443| REGION | Same |444| GENERATED BY | Same |445| REPORT ID | Same — format: `TI-{CLIENT}-{YYYYMMDD}` |446447---448449## 9. Table of Contents Layout450451| Element | Style |452|---|---|453| Title | "TABLE OF CONTENTS" — `h1` style |454| Divider | GradientLine full CW, 2pt |455| Gap | 8mm |456| Main entry | 3-column table: section number (Poppins-Bold 13pt `BP`, 35pt col), title (Poppins-Medium 10.5pt `T1`), page (Poppins-Bold 11pt `T1`, right-aligned, 40pt col) |457| Entry separator | 0.3pt `GL` line below |458| Sub-entry | Indented 15pt, Poppins 10pt, sub-number in `T3`, title in `T2` |459460---461462## 10. Report Section Blueprint463464### 10.1 Standard Section Header Pattern465466Every numbered section follows this sequence:4671. `SectionNumber(num)` — decorative ghost number (38pt height)4682. Section title in `h1` style (Poppins-Bold 20pt)4693. `GradientLine(CW, 2)` — full-width separator4704. `Spacer(1, 4*mm)` — breathing room471472### 10.2 Section Inventory (12 sections)473474| # | Section | Content Type |475|---|---|---|476| 01 | Executive Summary | MetricBox row + narrative + bulleted key findings |477| 02 | Threat Landscape Overview | Source distribution table + attack surface table |478| 03 | Threat Radar Visualization | RadarVisualization flowable + legend |479| 04 | Critical Severity Advisories | Advisory cards (PageBreak before section) |480| 05 | High Severity Advisories | Advisory cards (PageBreak before section) |481| 06 | Medium Severity Advisories | Advisory cards (PageBreak before section) |482| 07 | Attack Surface Analysis | Digital footprint table + subdomain inventory |483| 08 | Asset Inventory & Crown Jewels | Crown jewel CardBoxes + full inventory table |484| 09 | Technology Stack Intelligence | TechStackBlocks + security headers table |485| 10 | Security Posture Assessment | Status CardBoxes (6 items) |486| 11 | Strategic Recommendations | Tiered CardBoxes (Immediate/Short/Medium-term) |487| 12 | Methodology & Data Sources | Pipeline CardBoxes + scoring methodology + evidence table |488489---490491## 11. Spacing System492493### 11.1 Vertical Rhythm494495| Context | Spacing |496|---|---|497| After section title | 8pt (h1 spaceAfter) |498| After gradient divider | 4mm (≈11.3pt) |499| Between card sections (within) | 4pt |500| Between card section groups | 6pt |501| After metadata row → scores | 10pt |502| After scores → summary | 12pt |503| After summary → tech details | 6pt |504| Between advisory cards | CondPageBreak(220) |505| Between severity sections | PageBreak() |506| Before Evidence Collection | PageBreak() |507508### 11.2 Table Padding509510| Property | Value |511|---|---|512| Top padding | 4–5 pt |513| Bottom padding | 4–5 pt |514| Left padding | 6–8 pt |515| Row separator | 0.5pt `GL` line |516517---518519## 12. Data-Driven Components520521### 12.1 Evidence Map Architecture522523Technology evidence is extracted from `techstack_report.json` and indexed by keyword. The extraction traverses:524- `technologies.frontend[]` — name, evidence[].finding, evidence[].details525- `technologies.backend[]` — web servers, frameworks, CMS, languages526- `technologies.infrastructure[]` — DNS, CDN providers527- `technologies.security[]` — WAF, certificates, headers, email security528- `technologies.third_party[]` — analytics, collaboration tools529530Each evidence item is indexed under multiple keywords derived from the technology name fragments. Alias mappings expand coverage (e.g., `email` → `proofpoint`, `microsoft`, `dmarc`).531532### 12.2 Threat-Evidence Matching533534`get_threat_evidence(threat)` scans the threat's title, summary, and threat_name against the keyword index. Returns up to 6 `(tech_name, evidence_string)` tuples. Deduplication by `{tech_name}:{evidence}` key.535536### 12.3 Severity Sorting537538All threats sorted by: severity rank descending (critical=4, high=3, medium=2, low=1), then prioritization_score descending. Split into four lists for section rendering.539540---541542## 13. Unicode Characters543544| Character | Code | Usage |545|---|---|---|546| `│` | U+2502 | Pipe separator in metadata rows |547| `•` | U+2022 | Bullet point in relevance analysis, detection evidence |548| `—` | U+2014 | Em-dash in section headers, posture items, evidence items |549| `·` | U+00B7 | Middle dot in footer text |550| `✔` | U+2714 | Reserved (previously used in evidence, now removed) |551| `•` | HTML entity | Bullet in executive summary key findings |552553---554555## 14. Adaptive Behaviors556557### 14.1 Page Break Strategy558559| Transition | Method |560|---|---|561| Between advisories (same severity) | `CondPageBreak(220)` — break only if <220pt remains |562| Between severity sections | `PageBreak()` — always new page |563| Before Evidence Collection | `PageBreak()` — separate last page |564565### 14.2 Card Splittability566567Advisory cards return flat `list[Flowable]` instead of monolithic `CardBox`. This allows ReportLab's frame to split cards across page boundaries at any Paragraph/Spacer seam, eliminating blank pages.568569### 14.3 Client Adaptation570571The design system is client-agnostic. Customized per client:572- Cover: client logo, name, sector, region, report ID573- Executive summary: narrative and key findings574- Attack surface: domain/subdomain inventory575- Evidence map: keyword aliases tuned to client's tech stack576- Security posture: assessments specific to client's infrastructure577- Recommendations: actionable items specific to client's vulnerabilities578579All visual elements (colors, typography, spacing, components) remain identical across clients.