Managing Multilingual Security Reporting Templates with AI and MCP

Security Reporter Team

Maintaining finding templates becomes increasingly time-consuming when organizations use custom reporting structures, custom fields, and multiple languages.

Watch the demo to see how we customize the finding structure, then use AI through MCP to adapt existing finding templates, add Dutch translations, and set up a multilingual assessment workflow.

Video file
Read the transcript

Many organizations have their own reporting structure and terminology, while assessments may also need to be delivered in different languages. Security Reporter can be adapted to these requirements without having to manually maintain separate templates for every structure and language. In this demo, we'll show how to customize Reporter for reporting in multiple languages and how we can use AI for quick translations and template management.

Let's start by adding Dutch as a new language for this demo.

We can add additional report languages by importing a ready-made translation file. This translation file contains the translations for the standard text used throughout the generated report. This means that once the file is imported, virtually all of the standard report content is immediately available in Dutch.

We don't have to translate headings, labels, and other recurring report elements individually for every assessment. This gives us the foundation for producing reports in Dutch. Of course, the actual assessment content, such as findings and management summaries, still needs to be available in the selected language. We'll address that later in the demo.

Next, we'll customize the finding layout.

Security Reporter comes with a standard finding structure, but in practice, organizations often have their own way of documenting vulnerabilities. They may use different terminology, require additional information, or divide technical details differently.

For this example, we'll add two custom fields to the standard finding layout: a Summary field and a Steps to Reproduce field.

The Summary gives us a concise description of the vulnerability, while Steps to Reproduce provides a dedicated place for the technical steps needed to verify the issue.

Now that the fields have been created, we can define a new finding layout and add both of our custom fields.

We set this finding layout as the new default and then simply drag the new fields into place.

Our finding structure is now customized, but this also means that our existing finding templates no longer fully match the structure we want to use.

If we open one of the existing templates, we can see that our new fields are still empty. The template content needs to be adapted to the new structure, and there is no Dutch translation yet either.

Doing this manually for every existing template would take a lot of time.

Rather than updating every template manually, we'll use the Security Reporter MCP server to adapt them to the new layout and also add the missing Dutch translations.

We'll connect Claude to Security Reporter. To do this, we first create an API token.

The MCP configuration will be automatically generated for us. We can copy it, paste it into the terminal, and ask Claude to configure it for us.

Instead of manually copying finding templates into an AI tool, requesting changes, and then copying the results back into Security Reporter, Claude can work with the relevant data directly through the MCP interface.

The MCP server gives Claude access to dedicated Security Reporter functionality, including languages, templates, and their underlying structure. This becomes especially useful when updating a larger number of templates or maintaining the same content across multiple languages.

One note: for this demo, we disabled Claude's permission checks, which we wouldn't recommend for regular use.

Once the MCP server is configured, we restart the Claude session to activate it. We can then use the MCP command to verify that the connection is working correctly.

Now we can ask Claude to retrieve the existing finding templates, understand the available fields, and reorganize the content to match our new structure.

The goal is to preserve the information we already have and map it to the most appropriate fields in our custom finding layout.

At the same time, we asked Claude to add the missing Dutch translations.

For this demo, we limit Claude to just three templates so we can review the results before continuing with the rest of the template library.

As you can see, using AI to manage a large template library can save a significant amount of time.

And because the templates remain stored in Security Reporter, the security team can still review and adjust them before they are used in an assessment.

Our two custom fields are correctly populated, and the Dutch translation has been added.

One final step before we can start reporting in Dutch is to translate the assessment structure itself.

For this demo, we'll only translate the OWASP Top 10 template.

Instead of doing this manually, we can once again simply ask Claude to do it for us, saving us even more time.

Done. After refreshing the Assessment Template page, we can see that Claude did exactly as instructed.

Now that everything is in place, we can easily create security assessments in both English and Dutch.

Let's look at the result by creating a Dutch security assessment using the translated OWASP Top 10 structure and our custom finding layout. Then we'll add a finding using one of the finding templates we just adapted.

If we preview the report, we can see that the finding has been created in Dutch and follows our custom structure.

And that's the end result.

Obviously, in a real setup, you would use a custom theme with your own company branding, which also includes additional translation options that we haven't covered in this video.

Reporter adapts to the way your organization works, while AI and the MCP server help take care of the repetitive work.

You keep control over your reporting structure and content while making it much easier to maintain templates and assessments across multiple languages.

How it works

In this demo, we first customize the finding structure in Security Reporter, then connect Claude, our AI assistant, via MCP. MCP provides a standardized way for AI tools to interact directly with Security Reporter data and functionality.

This allows Claude to work with the available finding fields and templates, reorganize existing content to match the new structure, create translations, and write the results back to Security Reporter.

There is no need to copy templates back and forth between Security Reporter and an AI tool. Claude works directly with the relevant structure and data, while the security team retains control and can review the results before proceeding.