What a client sees
Your workspace:
the engagement, while it is happening.
Most testing is invisible until a PDF arrives. Everything we find lands in a workspace you can open at any point in the engagement — the finding, the evidence behind it, the thread where you asked us about it, and whether the retest passed.
The shape of it
A list on the left, one finding opened on the right
Two panes, and the reason for the split is the question each answers. The left asks where does this engagement stand? The right asks what exactly is this one thing, and how do I close it? Most security reporting forces you to choose — a dashboard that cannot show you the evidence, or a PDF that cannot show you the state.
The left: what is outstanding
- Every finding in the engagement, one row each, ordered by how much trouble it can actually cause rather than by when we found it.
- Its severity as we authored it — the rating does not change because a finding got old or inconvenient.
- Its retest state, which is the column people actually live in: awaiting your fix, retest passed, or retest failed. That last one exists because it happens, and hiding it would make the other two meaningless.
- New rows appear during the engagement, as each one is confirmed. You are not waiting for a document.
The right: one finding, completely
- Click a row and everything known about it opens beside the list — you never lose your place in the engagement to read one item.
- Reproduction and evidence: the request we sent, the response it returned, captured at the moment of the test.
- Impact in terms of your system, and remediation written for the engineer who has to write the fix.
- Retest history: every attempt, its date and its verdict. This is the audit trail when somebody asks, months later, when a thing was closed and on what basis.
A schematic of the workspace, not a screenshot. The real thing carries your findings, so we show it in a walkthrough rather than inventing a picture of somebody else’s engagement.
What you can do in it
Six things that are ordinarily an email thread
See findings the day they are confirmed
Not at the end. A critical issue reaches your team while there is still time to do something about it, with the evidence already attached.
Ask the person who found it
A thread per finding, answered by the engineer who wrote it rather than by an account manager relaying a question.
Request a retest when you have fixed it
From the finding itself. Our median turnaround on a submitted retest is 0.2 days, and the verdict lands back on the same page.
Export what your auditor is asking for
The report, the evidence, the current state of every finding. Assembled once, downloaded whenever the question comes round again.
See what is genuinely still open
Status is derived from retest verdicts, not from anybody’s recollection, so the dashboard and the truth are the same thing.
Keep the history when the engagement ends
Next year’s test starts against this year’s record rather than against a blank page, which is how a second engagement gets to go deeper than the first.
How it is built
A viewer, not a second copy of the truth
Worth stating because it is a security property, not a limitation: the public application has no path that rewrites your findings.
Read-only, by design
- The portal cannot alter a finding, a severity or a report. It reads.
- Anything you ask for — a retest, a question, a document — is a request that our side acts on, not a write into the record.
- That boundary exists so the internet-facing application is never the thing that can change the evidence.
Access
- Single sign-on through your own identity provider. We never hold a password for you.
- Access follows your organisation. When someone leaves your company, they leave the workspace, without anyone having to remember to tell us.
- Findings are a map of how to attack you and are treated that way — under NDA as standard, and never used as a reference without your written permission.
See it against your own system.
A walkthrough takes twenty minutes and uses a real engagement structure rather than a slide deck.