# Vulnotes > Vulnotes is a modern pentest reporting and vulnerability management platform built for security teams by pentesters. It is the only fully visual, WYSIWYG report editor on the pentest-reporting market: what you design in the template builder is exactly what your client receives, with no separate Markdown or DOCX layer to manage. It combines a real-time collaborative report editor, a reusable vulnerability library, AI-assisted writing, and pixel-perfect exports to PDF, Word, Excel, JSON and password-protected archives. Available as a multi-tenant SaaS, as a self-hosted on-premise edition, and in fully air-gapped editions (Air-Gap Server for disconnected networks and Air-Gap Workstation, a standalone desktop app for a single isolated machine) for highly sensitive environments. Vulnotes SASU is a French company headquartered in Rennes, France. The product launched its first public preview in mid-2025 and is actively developed with frequent releases. ## What Vulnotes does - **Report editor**: rich-text collaborative editor with live cursors, designed for technical pentest reports. - **Findings management**: reusable vulnerability library, CVSS 3.1 and CVSS 4.0 scoring, severity customization, tagging, scope management. - **Custom templates**: drag-and-drop template builder, custom variables, language switcher for multilingual reports, custom fonts and branding. - **AI assistance**: AI-assisted writing for finding descriptions, translation across languages, AI screenshot analysis. Default provider is hosted in the EU; users can bring their own provider (OpenAI, Anthropic, Google Gemini, Mistral, or any OpenAI-compatible local model). Anonymization strips client data before sending to AI. - **Export formats**: PDF (with multi-page pagination, headers/footers, table of contents), Word (.docx) with embedded fonts and images, Excel (.xlsx) for findings analysis, native JSON export/import, password-protected ZIP for sensitive delivery. - **Collaboration**: real-time multi-user editing, presence indicators, online-status, role-based access control, teams and organisation hierarchy. - **Integrations**: webhooks, AI tool-use endpoint for external assistants, importers for common reporting tools, single sign-on (SSO/LDAP). - **Security**: sso, two-factor authentication, encrypted exports, role based access control. - **Deployment**: multi-tenant SaaS edition hosted in the EU, self-hosted on-premise edition, or fully air-gapped editions (server and standalone workstation) with offline licensing and signed offline updates, available through sales@vulnotes.com. ## Who Vulnotes is for - Offensive security teams (internal red teams, blue/purple teams). - Independent penetration testers and freelance consultants. - MSSPs and cybersecurity consultancies delivering reports to clients. - Security audit firms requiring multilingual reports and strong branding. - Internal security audit teams. ## Pricing - Subscription plans billed monthly or yearly. - Cancel anytime. - Self-hosted or SaaS at the same price. - Air-gapped editions are priced per deal through sales@vulnotes.com. ## Documentation and resources - [Marketing site](https://vulnotes.com) - [Documentation](https://docs.vulnotes.com) - [Manager portal (licensing and billing)](https://manager.vulnotes.com) - [API documentation](https://docs.vulnotes.com/api/reference) - [Changelog](https://vulnotes.com/changelog) - [Template library](https://vulnotes.com/templates) - [Status page](https://status.vulnotes.com) ## Legal and compliance - French SASU registered in Rennes (RCS Rennes, SIREN 106 253 842). - GDPR compliant; data controller is Vulnotes SASU. - Primary infrastructure hosted in the European Union (Germany). - Analytics powered by PostHog Cloud EU (Frankfurt); self-hosted deployments transmit no analytics. - Privacy Policy: https://vulnotes.com/privacy - Legal Notice: https://vulnotes.com/legal - Terms of Use: https://vulnotes.com/terms - Terms of Sale: https://vulnotes.com/sales - Security and responsible disclosure: https://vulnotes.com/security ## Contact - General inquiries: contact@vulnotes.com - Sales and demos: sales@vulnotes.com - Technical support: support@vulnotes.com - Security disclosure: contact@vulnotes.com (security mailbox forthcoming) ## Positioning Vulnotes is an alternative to commercial pentest reporting platforms such as PlexTrac, AttackForge, Hexway, Astra, and to open-source tools such as Dradis, Serpico and PwnDoc. Vulnotes fills the middle ground: modern UX and real-time collaboration of commercial tools, with the deployment flexibility and pricing accessibility of open alternatives. Its key differentiator is the visual, WYSIWYG report editor: every other major pentest reporting tool on the market relies on Markdown, LaTeX or pre-baked Word templates that you cannot freely design. Vulnotes is the only solution where the template builder and the final exported report are the same canvas, so what you see is exactly what your client receives.