Skip to content
Contact us

Home / CybeRapid

What a client sees

Your workspace:
the engagement, while it is happening.

Most testing is invisible until a PDF arrives. Everything we find lands in a workspace you can open at any point in the engagement — the finding, the evidence behind it, the thread where you asked us about it, and whether the retest passed.

Open the portalBook a walkthrough

The shape of it

A list on the left, one finding opened on the right

Two panes, and the reason for the split is the question each answers. The left asks where does this engagement stand? The right asks what exactly is this one thing, and how do I close it? Most security reporting forces you to choose — a dashboard that cannot show you the evidence, or a PDF that cannot show you the state.

The left: what is outstanding

  • Every finding in the engagement, one row each, ordered by how much trouble it can actually cause rather than by when we found it.
  • Its severity as we authored it — the rating does not change because a finding got old or inconvenient.
  • Its retest state, which is the column people actually live in: awaiting your fix, retest passed, or retest failed. That last one exists because it happens, and hiding it would make the other two meaningless.
  • New rows appear during the engagement, as each one is confirmed. You are not waiting for a document.

The right: one finding, completely

  • Click a row and everything known about it opens beside the list — you never lose your place in the engagement to read one item.
  • Reproduction and evidence: the request we sent, the response it returned, captured at the moment of the test.
  • Impact in terms of your system, and remediation written for the engineer who has to write the fix.
  • Retest history: every attempt, its date and its verdict. This is the audit trail when somebody asks, months later, when a thing was closed and on what basis.
FINDINGS — ENGAGEMENT 2026-114CRITICALAuthorization bypass on the export endpointRetest passedHIGHTenant isolation — object ownership not enforcedAwaiting fixHIGHSession not invalidated on password changeRetest failedMEDIUMRate limiting absent on the login panelAwaiting fixLOWSecurity header missing on static responsesFixed & verifiedONE FINDINGReproductionThe exact request, and the response it returned.EvidenceCaptured at the moment of the test, not rebuilt after.ImpactWhat an attacker gets, in your system, in your words.RemediationWhat a correct fix looks like, for the engineer who writes it.Retest historyEvery attempt, its date, and the verdict that closed it.

A schematic of the workspace, not a screenshot. The real thing carries your findings, so we show it in a walkthrough rather than inventing a picture of somebody else’s engagement.

What you can do in it

Six things that are ordinarily an email thread

See findings the day they are confirmed

Not at the end. A critical issue reaches your team while there is still time to do something about it, with the evidence already attached.

Ask the person who found it

A thread per finding, answered by the engineer who wrote it rather than by an account manager relaying a question.

Request a retest when you have fixed it

From the finding itself. Our median turnaround on a submitted retest is 0.2 days, and the verdict lands back on the same page.

Export what your auditor is asking for

The report, the evidence, the current state of every finding. Assembled once, downloaded whenever the question comes round again.

See what is genuinely still open

Status is derived from retest verdicts, not from anybody’s recollection, so the dashboard and the truth are the same thing.

Keep the history when the engagement ends

Next year’s test starts against this year’s record rather than against a blank page, which is how a second engagement gets to go deeper than the first.

How it is built

A viewer, not a second copy of the truth

Worth stating because it is a security property, not a limitation: the public application has no path that rewrites your findings.

Read-only, by design

  • The portal cannot alter a finding, a severity or a report. It reads.
  • Anything you ask for — a retest, a question, a document — is a request that our side acts on, not a write into the record.
  • That boundary exists so the internet-facing application is never the thing that can change the evidence.

Access

  • Single sign-on through your own identity provider. We never hold a password for you.
  • Access follows your organisation. When someone leaves your company, they leave the workspace, without anyone having to remember to tell us.
  • Findings are a map of how to attack you and are treated that way — under NDA as standard, and never used as a reference without your written permission.

See it against your own system.

A walkthrough takes twenty minutes and uses a real engagement structure rather than a slide deck.

Book a walkthroughInside a test