The Pentest Client Portal.Add More Value To Your Clients

A white-label portal where your clients access their findings, track progress and download deliverables.

add-on
14-day free trialSelf-hosting includedCancel anytime
Vulnotes client portal security dashboard
  1. Open
  2. Fix In Progress
  3. Ready for Retest
  4. Fixed
  5. Accepted Risk

The remediation lifecycle your clients follow

A Remediation Lifecycle Your Clients Can Follow

Every published finding carries one of five statuses, so both sides always know where a fix stands. SLA due dates are computed per severity, and retest requests notify the pentest team automatically.

  1. Open
  2. Fix In Progress
  3. Ready for Retest
  4. Fixed
  5. Accepted Risk
7 days
critical
30 days
high
90 days
medium
180 days
low

default SLA due dates per severity

A Vulnotes finding synced as a ticket in the client's Jira

Two-Way Jira Sync, in the Client's Own Jira

Clients connect their own Jira directly from the portal and turn findings into tickets where their engineers already work. When a linked issue transitions to done, a signed webhook advances the finding and notifies your team. Fix it in Jira and the finding updates itself.

  • Clients connect their own Jira from the portal
  • Signed webhooks advance findings when linked issues reach done
  • Default transition to Ready for Retest, with your team notified
portal logo
primary color
company name

set per client, not per instance

White-Label Branding and Client Teams

Set the portal logo, primary color and company name per client, so the portal reads as your deliverable. A client-admin role lets each client run its own user list, and threaded comments keep client and internal users in the same conversation.

  • Portal logo, primary color and company name per client
  • Client-admin role invites, activates and deactivates portal users
  • Threaded comments between client and internal users
status-triggered publishingreal-time publishing
PDFXLSXCSVDOCX opt-in

client-side exports, straight from the portal

Publishing and Delivery, on Your Terms

Publish findings when a report reaches the status you choose, or in real time as they land. Clients export PDF, XLSX and CSV by default, with DOCX as an opt-in. Your own deliverables keep their five export formats.

  • Status-triggered or real-time publishing as findings land
  • Client-side exports: PDF, XLSX and CSV by default, DOCX opt-in
  • Read-only view of upcoming engagements

Frequently Asked Questions

Your team does. Findings are published either when a report reaches the status you choose or in real time as they land. Clients get exactly the published findings, client-side exports (PDF, XLSX and CSV by default, DOCX opt-in) and a read-only view of upcoming engagements. See how deliverables are built on the report editor and exports page.

Yes. A client-admin role lets each client invite, activate and deactivate their own portal users, and threaded comments connect client and internal users on the same finding. See how your own team works together on the collaboration page.
Start today

Ready to Upgrade
Client Delivery?

Set up in minutes. Write, review and deliver your next pentest report in Vulnotes.

14-day free trialSelf-hosting includedCancel anytime
Vulnotes report editor preview