PlatformFor pentest companies and their clients

Every test.
One source
of truth.

Cerberos Nexus is where pentest companies run every engagement, from pentests to PCI ASV quarters, and where their clients follow every finding through to a verified fix.

Six engagement typesLive Client PortalRetest-verified fixes
Frameworks built in
OWASPPTESNIST SP 800-115MITRE ATT&CKPCI ASV
Two sides of every test

Built for pentest companies.
Open to their clients.

Pentest companies run the work in the Team Console. The companies they test follow it in the Client Portal. Both work from the same record, so nothing is chased by email or lost in a PDF.

For pentest companies

Run every engagement from one console.

  • Pentests, VA, PCI ASV, segmentation and red team in one console
  • Methodology checklists from OWASP, PTES and NIST templates that gate reporting
  • Findings scored with CVSS 3.1, with evidence and scanner imports
  • Quality checks built in: checklist gates, ASV QA and two-person publishing
  • Reports on your own templates, delivered as password-protected PDFs
  • Milestones, timesheets, leave and a weekly digest for delivery managers
Explore the Team Console →
For their clients

Follow every finding to a verified fix.

  • Findings as they are published, with evidence and a recommended fix
  • SLA due dates and overdue counts on a live dashboard
  • Accept, dispute or comment on findings, with evidence
  • Retests requested from the portal when a fix is ready
  • Reports and evidence to download, including PCI ASV deliverables
  • Client admins invite their own team, with MFA on every account
Explore the Client Portal →
Engagements

Every engagement.
One platform.

Penetration tests, continuous projects, vulnerability assessments, PCI ASV scanning, segmentation tests and red team engagements, each managed from scope to report with the client in the loop.

01 · One-time

Penetration tests

A scoped project for web apps, APIs, networks, cloud, mobile and more. It runs from planning through testing, reporting and remediation to delivery, and the methodology checklist must be complete before it moves to reporting.

Explore penetration tests →
For the pentest company
  • Scope, milestones and the team, on a timeline
  • Methodology checklists from OWASP, PTES and NIST templates
  • Findings scored with CVSS 3.1, with evidence and scanner imports
  • Reports on your own templates, delivered as protected PDFs
For the clientPublished findings with SLA due dates, and the reports; comments, disputes and retest requests
Closes withA delivered report that carries the retest history
Client Portal

No finding left
in a PDF.

Clients see each finding as it is published, with its evidence, SLA due date and every retest, in one place instead of a folder of PDFs.

Live findingsRetest requestsEvidenceReportsSLA trackingExplore the platform →
Lifecycle

Scope to verified,
in six steps.

Every step is timestamped and attributed in an append-only audit trail.

01

Scope

Assets, scope and the team on it.
02

Test

Checklists worked, findings logged.
03

Report

Quality-checked, on your template.
04

Remediate

SLA due dates, comments, disputes.
05

Retest

Requested by the client in the portal.
06

Verified

Closed with the evidence on record.

One-time pentest or continuous project. Same platform.

Run a scoped pentest when a release or an audit needs a point-in-time answer, and continuous VA and PCI ASV projects for the scanning that comes round every month or quarter. Both reach the client in the same portal.

One-time

Scope, test, report and retest, closed with a delivered report.

Continuous

Cycles on a cadence, scheduled scans and verification scans.
Open high & critical findings over four cycles of a continuous project (illustrative)
FAQ

Questions buyers ask.

Straight answers about Cerberos Nexus, for pentest companies and the clients they work with.

Pentest companies and the clients they test. The pentest company runs its engagements in the Team Console, and its clients follow findings, disputes, retests and reports in the Client Portal.

Ready when
your auditor is.

See your engagements, findings and retests come together in one record, on a workflow like yours.