Penetration tests, continuous projects, vulnerability assessments, PCI ASV scanning, segmentation tests and red team engagements. Pentest companies run each one in the Team Console; their clients follow it in the Client Portal.
Team ConsoleThe full working record, for the pentest company.
Client PortalWhat has been published, for the client.
01 · PentestOne-time
Penetration tests
A scoped project for web apps, APIs, networks, cloud, mobile and more. It runs from planning through testing, reporting and remediation to delivery, and the methodology checklist must be complete before it moves to reporting.
For the pentest company
Scope, milestones and the team, on a timeline
Methodology checklists from OWASP, PTES and NIST templates
Findings scored with CVSS 3.1, with evidence and scanner imports
Reports on your own templates, delivered as protected PDFs
For the clientPublished findings with SLA due dates, and the reports; comments, disputes and retest requests
Closes withA delivered report that carries the retest history
PlanScope, milestones and the people on the project.
02
TestChecklist items worked through, findings logged with evidence.
03
CheckAn automated quality check on each finding before it leaves draft.
04
ReportThe report built from the record, on your own template.
05
RemediateThe client works to SLA due dates, with comments and disputes.
06
RetestThe client requests a retest and the team records the result.
Kept in the record
ScopeChecklistsFindingsEvidenceReportsRetest history
02 · ContinuousRecurring
Continuous projects
Recurring vulnerability assessment and PCI ASV work, run as cycles on a set cadence instead of one-off projects. Scope is decided for each cycle, findings are tracked across every scan, and overdue cycles are flagged.
For the pentest company
VA or PCI ASV projects, monthly to annual
Scope decided for each cycle
Primary, verification and ad hoc scans
Scheduled scans that start on their own
For the clientCycle status, scans and findings, with disputes; and, when you allow it, their own scope and scans
Closes withA completed cycle with its reports, and for ASV an attestation
ScopeAssets in or out of scope, decided for each cycle.
02
ScanScheduled or launched scans, or imports from your scanners.
03
TrackEach finding followed across hosts and repeat scans.
04
ShareFindings and published reports in the Client Portal.
05
DisputeThe client raises disputes with evidence; reviewers decide.
06
VerifyVerification scans flag what looks fixed, for an analyst to confirm.
Kept in the record
CyclesScope decisionsScansFindingsDisputesReports
03 · VAScan-based
Vulnerability assessments
Scanner output turned into findings a client can act on. Scans are launched from the platform or imported, each issue is tracked across hosts and repeat scans, and verification scans show what looks fixed.
For the pentest company
Scans launched in Nessus, Nexpose or Burp Pro
Imports from Nessus, Nexpose, Burp, Acunetix and CSV
Findings tracked across hosts and repeat scans
Verification scans that flag likely fixes
For the clientFindings by host and severity, the cycle's status and any disputes
ReportExecutive and remediation reports for the cycle.
05
DisputeThe client disputes findings with evidence.
06
VerifyA verification scan flags what looks fixed.
Kept in the record
Hosts in scopeScansFindingsDisputesReports
04 · PCI ASVQuarterly
PCI ASV scanning
Quarterly external scanning with the ASV rules built in. A quarter passes only when its scan covers the whole scope with no failing findings, and only a passing, QA-approved quarter can be attested.
For the pentest company
Quarterly cycles with the pass and fail rules built in
Disputes for false positives, compensating controls and scope
Independent QA sign-off, cleared if the quarter changes
Attestation by someone other than the QA reviewer
For the clientEach quarter's status and scans, with disputes and the justifications they write
Closes withThe three ASV deliverables, with the Attestation of Scan Compliance
Proof that networks are isolated the way the policy says. Zones and the allowed, prohibited or conditional paths between them are defined once, and every test run checks what is actually reachable against them.
For the pentest company
Zones with their address ranges
A zone-to-zone policy: allowed, prohibited or conditional
Results from nmap, Nessus, CSV or manual entry
Pass or fail per path, each reachable service triaged
For the clientResults path by path, with each reachable service to accept or dispute
Closes withA segmentation report, published to the client
PolicyWhich zones may reach which, and on what terms.
03
CollectScan results from nmap, Nessus, CSV or by hand.
04
AnalyseEvery reachable path checked against the policy.
05
TriageEach reachable service marked required, accepted or false positive.
06
ReportA report from your template, published to the client.
Kept in the record
ZonesPolicyScan resultsFindingsReports
06 · Red teamObjective-led
Red team engagements
An objective-led engagement with its authorisation, rules of engagement and attack plan in one record. Activity is mapped to MITRE ATT&CK, and findings are published only after review, by someone other than their author.
For the pentest company
Objectives, starting scenario and rules of engagement
Authorisation letters and NDAs on file
Attack maps from playbooks, with step approvals
Findings reviewed, then published by a second person
For the clientPublished findings to accept or dispute, and the reports
Closes withReports with the attack narrative, timeline and objective scorecard