PROOF LIBRARY

See the proof behind evidence-driven validation .

Sanitized, representative examples of the outputs generated by the Hayrok platform. Explore sample findings, reports, evidence packages, attack paths, detection gaps, control failures, and revalidation outcomes before speaking with sales.

WHAT THIS LIBRARY ANSWERS

Understand what you receive — before the conversation.

The Proof Library is designed to make evaluation transparent. Everything is sanitized, non-customer-identifiable, and clearly labeled as representative content.

ANSWERED
  • ?What does a Hayrok finding look like?
  • ?What evidence supports a confirmed result?
  • ?How are control and detection responses presented?
  • ?How does Hayrok explain attack paths?
  • ?What does remediation revalidation prove?
  • ?What can be shared with leadership, auditors, or customers?
SAMPLES

Eight sanitized artifacts to review.

REPORTSAMPLE
Sample Validation Report
See the complete outcome of a governed validation: objective, scope, scenarios, findings, controls, detections, evidence, paths, impact, and priorities.
Open sample
EVIDENCESAMPLE
Sample Evidence Pack
Requests, execution metadata, runtime observations, control responses, detection events, reachability, identity decisions, and integrity metadata.
Open sample
FINDINGSAMPLE
Sample Finding Drawer
Overview · Technical Evidence · Attack Path · Validation · Risk · Remediation · Activity — for a real credential-abuse-to-payment-db finding.
Open sample
PATHSAMPLE
Sample Attack Path
Internet API → authorization weakness → exposed credential → privileged cloud role → payment database — with evidence at every hop.
Open sample
DETECTIONSAMPLE
Sample Detection Gap
Expected telemetry vs. observed, latency, missing data, ATT&CK mapping, and detection improvement recommendations.
Open sample
CONTROLSAMPLE
Sample Control Failure
Expected behavior, validation action, observed response, allow/block result, compensating controls, and control improvement plan.
Open sample
REVALSAMPLE
Sample Revalidation Result
Compare original condition, remediation action, new outcome, updated control & detection response, residual risk, and disposition.
Open sample
AUDITSAMPLE
Sample Audit Package
Objective, scope, authorization, policy decisions, approvals, execution timeline, evidence chain, and integrity metadata.
Open sample
TRUST REQUIREMENTS

Everything you see is sanitized and clearly labeled.

Sanitized
No real credentials, secrets, or exploitable customer details.
Non-customer-identifiable
No logos, tenant IDs, or environment fingerprints.
Non-weaponized
No destructive commands or working payloads.
Labeled
Every sample is clearly marked as representative content.
Realistic
Based on real platform outputs and current capabilities.
Watermarked
Where appropriate, samples carry visible watermarks.
SAMPLE DOCUMENT PREVIEWS

Real formats. Sanitized data.

Every artifact ships in the same layout customers, auditors, and executives see in production.

PDF · 48 PAGES
Validation Report Q3-2026
Fortune 500 Retailer · 47 scenarios · 12 crown-jewel paths
PDF · 48 PAGES Preview →
PDF · 26 PAGES
Ransomware Readiness Findings
Regional bank · 9 initial-access paths blocked · 3 gaps
PDF · 26 PAGES Preview →
PDF · 34 PAGES
Detection Coverage Assessment
SOC assessment · SIEM+EDR · 214 ATT&CK techniques
PDF · 34 PAGES Preview →
PDF · 22 PAGES
API Authorization Evidence
B2B SaaS · Tenant isolation · Object & function authz
PDF · 22 PAGES Preview →
PDF · 41 PAGES
Cloud Reachability Findings
Multi-cloud · AWS · GCP · Azure · 61 exploitable paths
PDF · 41 PAGES Preview →
ZIP · 320 MB
Audit-Ready Evidence Package
PCI DSS · SOC 2 · ISO 27001 mapped controls
ZIP · 320 MB Preview →
INSIDE A HAYROK FINDING

A representative finding drawer — the same UI customers work in daily.

app.hayrok.io / findings / hyk-024891
CRITICAL
FINDING
Credential abuse path reaches payment database
SeverityCritical
StatusValidated · Exploitable
Assetsext-api-01 · role-payments
Evidence count24 artifacts
Business impactDirect revenue system
CONTROL RESPONSE
WAFBypassed
IAMAllowed
SegmentationBroken
Data loss preventionNot triggered
CSPM alertSilent
DETECTION RESPONSE
SIEM · SplunkMissed
EDR · endpointAlert · low
Identity providerMissed
Cloud audit logLogged
ATT&CK T1078Uncovered
ATTACK PATH · 5 HOPS
ext-api-01
svc-account
role-deploy
role-payments
db-payments
WHAT AUDITORS & CUSTOMERS SAY

About the Hayrok evidence contract.

The first vendor whose evidence I did not have to reshape before submitting to the audit committee.
MC
Marcus Chen
IT Audit Partner · Big 4 Firm
When we saw the sample report and the evidence pack, we cancelled the RFP. Nothing else compared.
SB
Sonia Blake
CISO · Global Insurance
Being able to hand the board an evidence trail — not a spreadsheet of severities — changed how our program is funded.
AV
Andre Vasquez
VP Security · Public FinTech
MAPS TO WHAT AUDITORS ASK

Evidence packages align with the frameworks your program is measured against.

SOC 2
Mapped
ISO 27001
Mapped
PCI DSS
Mapped
HIPAA
Mapped
NIST CSF
Mapped
NIST 800-53
Mapped
FFIEC
Mapped
NYDFS
Mapped
DORA
Mapped
GDPR
Mapped
MITRE ATT&CK
Mapped
CIS Controls
Mapped
SOC 2
Type II · roadmap
ISO 27001
In progress
GDPR
Ready
CCPA
Ready
NIST CSF
Aligned
ATT&CK
v15 mapped

Ready to see the real thing in your environment?

A live demo walks through evidence, findings, attack paths, and revalidation tailored to your objectives.