Guide

Markdown to a client-ready PDF

The findings are in a .md file. The client wants a PDF with a cover, a contents page, page numbers and tables that do not break in half. Here is what "client-ready" means, why the usual routes fall short, and how to get there in one export.

What "client-ready" actually requires

  • A cover page with the title, client, date, version and who prepared it
  • A table of contents with page numbers, and page numbers in the footer ("Page 6 of 14")
  • A running header naming the document and version on every page
  • Tables that survive page breaks: header row repeated, rows not split mid-cell
  • Severity that reads in greyscale print: a label and a glyph, not colour alone
  • Embedded fonts and no remote references: it must look the same on the client's machine, offline
  • A confidentiality footer the client's procurement team will look for
  • Nothing leaked: no reviewer comments, no draft notes, no links to internal systems

Why the usual routes fall short

Print from the browser or the editor preview

Browser printing has no real concept of a document. Page numbers and "Page x of y" are not available in a cross-platform way, there is no table of contents with page numbers, table header rows do not repeat reliably, and on a Mac the system font gets embedded in the PDF, which its licence does not allow for redistribution. Good for a draft, not for a deliverable.

Pandoc with LaTeX

Pandoc produces excellent PDFs once a LaTeX toolchain (1 to 4 GB) is installed and a template is written. Tables with long cells overflow the page unless you hand-tune widths; GitHub alerts, task lists and details blocks need filters; emoji and CJK need font configuration. It is a fine tool for people who already run it. It is not a Friday-afternoon handoff.

Online converters

They require uploading the report. For a pentest or a compliance document, that is usually a contract breach on its own.

How AsItIs does it

AsItIs renders the PDF with a typesetting engine bundled inside the app, in a child process with a memory cap, using the same fonts and colour tokens you see on screen. Nothing is uploaded and nothing is fetched.

  1. Fix the source. Correct the findings, update statuses, add the sign-off row. The save is byte-clean, so the git diff shows only your fixes and the report stays reviewable.
  2. Choose a template. Plain (free): the document as it reads on screen, with page numbers. Security findings (Pro): cover page, severity chart, findings by severity as cards, contents, running header, confidentiality footer. Word (Pro): a .docx with real Heading 1 to 3, table and code styles, for clients who redline.
  3. Read the preview. The export sheet shows real pages, not a mock. Warnings are actionable: "2 remote images are blocked and will be left out", "Contains Chinese text, download the CJK font pack for correct output".
  4. Export. A 14-page report renders in under half a second. Fonts are embedded subsets. Links to javascript: or file: are stripped. HTML comments appear as a visible box in the preview so you notice them before the client does.
Export sheet: Security findings template selected, structure options for cover page, table of contents, page numbers and severity summary, and a two-page preview
The export sheet with the Security findings template and a real page preview.
Word export preview showing heading styles and a findings table in a .docx document
Word export with real styles, for clients who redline in Word.

Markdown that exports well

  • One H1 for the title, H2 for sections, H3 for findings. The contents page follows this.
  • Put the client, version and date in YAML frontmatter; the cover page reads them.
  • Keep a findings table with fixed columns (ID, title, severity, CVSS, status). Cards are generated from it.
  • Use a severity label in text (Critical), not only an emoji or a colour word.
  • Use relative image paths inside the report folder. Remote images are blocked by default.
  • Delete reviewer comments before export, or check the preview's comment boxes.
  • Mermaid diagrams render; if one fails, it is exported as its code block and the preview says so.

Which template when

SituationTemplatePlan
Internal copy, quick reviewPlain PDFFree
Pentest, audit or scanner findings for a clientSecurity findings PDFPro
Client's legal or procurement team will redlineWord exportPro
Firm branding on every exportFirm template packFirm (coming later)

Pricing. Pro can be tried for 21 days or 3 exports, whichever ends later, without an account.