Six engagement types. One workflow.

Penetration tests, continuous projects, vulnerability assessments, PCI ASV scanning, segmentation tests and red team engagements. Pentest companies run each one in the Team Console; their clients follow it in the Client Portal.

Every engagement includes
ScopeTeam rolesFindingsEvidenceClient PortalDisputesReportsAudit trail
Two views of one record
Team ConsoleThe full working record, for the pentest company.
Client PortalWhat has been published, for the client.
01 · PentestOne-time

Penetration tests

A scoped project for web apps, APIs, networks, cloud, mobile and more. It runs from planning through testing, reporting and remediation to delivery, and the methodology checklist must be complete before it moves to reporting.

For the pentest company
  • Scope, milestones and the team, on a timeline
  • Methodology checklists from OWASP, PTES and NIST templates
  • Findings scored with CVSS 3.1, with evidence and scanner imports
  • Reports on your own templates, delivered as protected PDFs
For the clientPublished findings with SLA due dates, and the reports; comments, disputes and retest requests
Closes withA delivered report that carries the retest history
See it in a demo

How it runs

6 stages
  1. 01
    PlanScope, milestones and the people on the project.
  2. 02
    TestChecklist items worked through, findings logged with evidence.
  3. 03
    CheckAn automated quality check on each finding before it leaves draft.
  4. 04
    ReportThe report built from the record, on your own template.
  5. 05
    RemediateThe client works to SLA due dates, with comments and disputes.
  6. 06
    RetestThe client requests a retest and the team records the result.
Kept in the record
ScopeChecklistsFindingsEvidenceReportsRetest history
The shared workflow

One workflow,
quality built in.

Every engagement type follows the same shape, with quality checks between the work and the client.

01

Scope

Assets, zones or objectives, agreed before work starts.

02

Plan

Checklists, milestones and the people on the job.

03

Test & log

Findings logged with evidence and scored, or imported from scanners.

04Built in

Quality checks

Checklist gates and an automated finding check for pentests, independent QA for ASV, two-person publishing for red team.

05

Publish

Findings and reports published to the Client Portal, with password-protected PDFs.

06

Remediate

The client works through findings in the portal, accepting or disputing each one.

07

Retest & verify

Retests, verification scans and repeat runs show what was fixed.

ResultOne record of what was found, fixed and verified.
Who it serves

Everyone around a test.

01

Testers

Log findings once, with evidence, and see them flow into the report.

02

QA & ASV reviewers

Check findings, decide ASV disputes and sign off quarters before attestation.

03

Delivery managers

Milestones, timesheets and a weekly digest of where the work stands.

04

Client teams

Follow findings and SLA due dates, dispute with evidence and request retests.

Ready when
your auditor is.

See your engagements, findings and retests come together in one record, on a workflow like yours.