Continuous pentesting

Retesting, certification & the client portal

The pentest-platform add-on turns a point-in-time test into a delivery loop: findings land live, customers remediate and one-click retest, a certified human signs the report, and posture is tracked over time — all in a white-labeled portal.

The pentest-platform module is a per-account add-on. When it's enabled for your organization, five surfaces appear in the sidebar: Portal, Retesting, Certified Reports, Tracking, and Coverage. If you don't see them, the add-on isn't enabled — contact your provider.

Retesting — verify a fix on demand

When you've remediated a finding, you don't need a whole new engagement to confirm it's fixed. Open Retesting (or hit Retest directly on a finding) and request a retest. You can run it now or schedule it for a maintenance window so it never disrupts production.

  • The platform re-runs the exact check that produced the finding — a targeted re-verification, not a full re-scan.
  • Findings that no longer reproduce are auto-closed as resolved; anything still present re-opens for the next cycle.
  • Each request becomes a Retest Round you can track (scope, window, how many were re-verified).

Certified reports — a human signs it

A scanner answers "what did the robot find?" A certified report answers "what does a named penetration tester stand behind?" Open Certified Reports and pick an engagement:

  • Draft with AI writes the Executive Summary, Recommendations, and Positive Observations from the engagement's real findings — grounded in the actual counts, never invented.
  • Edit the sections (Markdown), preview the document, and Save.
  • Submit for review, then Certify & seal: the approver enters their name and credentials, which locks the report and stamps the attestation.
  • Every change is captured in Version History, and Re-open starts a new version cycle.

Certification can be delivered as a service — the certifier may be your own staff or a designated cross-organization certified pentester.

Framework coverage — MITRE & OWASP

Coverage maps an engagement's findings to the frameworks buyers and auditors expect: internal / Active Directory findings to MITRE ATT&CK techniques (Kerberoasting, LLMNR/relay, valid accounts, …) and web / API findings to the OWASP Top 10. Anything that can't be confidently mapped lands in an explicit Unmapped bucket — we show what was actually tested, never imply coverage we don't have.

Tracking — posture over time

Tracking is the longitudinal view: a findings-remediated-over-time trend, your current posture (open / in-retest / remediated), a remediation rate, and a per-engagement progress breakdown. It's the record of risk your team has retired — kept as long as the organization is active.

The client portal

Portal is the customer-facing home: security posture at a glance, the remediation trend, and clear next steps — review findings, request a retest, get your certified report, track posture. It's the simple front door for stakeholders who don't live in the full operator dashboard.

Notifications

Members can opt in (under Settings → Email notifications) to emails for the moments that matter: a pentest starting, a critical finding confirmed in real time, a test completing, and deliverables — a certified report ready or a retest complete. Consultants can also enable these for a customer from Team → Members, so clients get updates without any setup.