Skip to content
Vaptiq logo mark — V orientationVAPTIQ

[ Platform ]

The report is not a deliverable. It is a view.

Penetration testing has spent twenty years shipping its output as a PDF that arrives weeks after the work finished. We publish findings as they are confirmed, keep them in one place, and let the documents render from that, so remediation can start on day two.

[ 01 / Live view ]

This is what your team sees while an engagement is running. Findings, severity, status and the asset each one sits on, filterable, exportable, and updated by the tester working your scope rather than by a project manager at the end.

EngagementACME · Grey box · Q3
Testing in progress · day 4 of 8
4 of 4 findings
Example findings as they appear in the Vaptiq reporting platform
IDSeverityFinding
VPQ-0142Critical
VPQ-0139High
VPQ-0131High
VPQ-0128Medium

Illustrative data · select a row to see what your team sees

[ 02 / What it does ]

Six things it changes about a pentest.

None of these are novel ideas. They are the obvious consequences of storing findings as data instead of as paragraphs in a document.

  1. 01

    Findings arrive live

    The moment a tester confirms and writes up a finding, it appears in your tenant with evidence, reproduction steps and a CVSS v4.0 score. Critical findings also trigger an immediate notification. You should not learn about remote code execution from a PDF in week six.

  2. 02

    A thread on every finding

    Ask the tester who wrote it what they meant, or push back on a severity rating. The conversation stays attached to the finding, so the context is still there when somebody picks it up three months later.

  3. 03

    Retest without a new project

    Mark a fix as ready and it enters the retest queue. The same tester verifies it, the status changes in place, and the report regenerates with the finding closed and dated.

  4. 04

    Export to where the work happens

    Push findings into Jira, Linear or GitHub Issues with the severity and reproduction steps intact, or pull everything through the API. Your developers never need to open our platform if they would rather not.

  5. 05

    Reports that generate themselves

    Technical report, executive summary and attestation letter all render from the same findings. Re-run them after a retest and every document reflects the current state, correctly versioned.

  6. 06

    History that means something

    Engagement over engagement, you can see which finding classes keep coming back. That trend is usually a more useful input to your roadmap than any single report.

[ 03 / Our own security ]

We are holding a map of how to break into your company.

That is worth saying plainly. A penetration testing platform is a high-value target by definition, and it is treated like one, including being tested by people who do not work here.

  • Isolated tenants

    Each client's data sits in its own logical tenant. No shared indexes, no cross-tenant queries.

  • Encrypted throughout

    AES-256 at rest, TLS 1.3 in transit, with evidence files encrypted separately from metadata.

  • SSO and MFA

    SAML and OIDC, enforced MFA, and role-based access so contractors see only their scope.

  • Audit logging

    Every view, download and export recorded and available to your team, not just ours.

  • Least privilege internally

    Testers are granted access to an engagement for its duration, and lose it on close.

  • Your retention rules

    Set how long evidence lives. Export everything, or have it destroyed, on request.

Found something in our platform? Send it to [email protected]. We answer within one working day, and we do not send lawyers to people who report bugs.

See the platform with your own scope in it.

Book a walkthrough and we will load a redacted engagement so you can judge the workflow rather than a slide about it.