Two sides of
one record.

Pentest companies work in the Team Console. Their clients work in the Client Portal. Both work from the same record, so nothing is lost between a test and its fix.

Team Console

Where every engagement is run.

The Team Console is the pentest company's workspace. It holds the scope, the checklists, every finding and its evidence, and the checks that stand between the work and the client.

  • Projects & scopePentests, continuous projects, segmentation tests and red team engagements, each with its own scope and team.
  • Methodology checklistsFrom OWASP, ASVS, MASVS, PTES, NIST and OSSTMM templates, completed before a pentest moves to reporting.
  • Finding editorCVSS 3.1 scoring, steps to reproduce and a recommended fix, with evidence marked internal or shared.
  • Quality checksAn automated check on each finding before it leaves draft, and sign-off rules for closing it.
  • ReportsGenerated from the record on your own HTML or Word templates, and delivered as protected PDFs.
CONSOLETester logs a finding
CONSOLEQuality checked
PORTALClient fixes it
PORTALClient requests a retest
CONSOLE → PORTALVerified fixed
Client Portal

Where clients close the loop.

Findings arrive with evidence and a recommended fix. Clients track them against SLA due dates, accept or dispute them, and request a retest when a fix is ready.

  • Live findingsEvery published finding, with evidence and a recommended fix.
  • SLA due datesDue dates and overdue counts on a dashboard, by severity.
  • Accept, dispute, commentRespond to each finding, with evidence where it matters.
  • Retest requestsAsk for a retest when a fix is ready, and see the result.
  • Reports & evidenceDownload reports, evidence and PCI ASV deliverables at any time.
Platform security

Built for sensitive findings.

Single sign-on for staff

Staff sign in through Microsoft Entra ID.

Multi-factor authentication

Required on every account, in both portals.

Roles and permissions

Staff and project roles decide who does what. Clients see only what is published to them.

Append-only audit log

Changes are recorded in an append-only, hash-chained log.

Encryption

TLS on every connection, with encrypted secrets and encrypted backups.

Export any time

Export findings to CSV or Excel whenever you need them.

Ready when
your auditor is.

See your engagements, findings and retests come together in one record, on a workflow like yours.