Every feature

194+ features, and every one ships today.

Scope, Report, and the Client Portal are live and delivering engagements now. This is the working feature set, tool by tool, with nothing on the list that isn’t already shipping.

Scope

Pre-sales, scoping, and the deal
59 features

Clients & CRM

  • Client directory with search, filter, sort and pagination
  • Filter by industry, company size, and active status
  • Client CRUD, activate / deactivate, per-client stats
  • Multiple named contacts per client with roles
  • Per-client asset history

Opportunity pipeline

  • Seven-stage pipeline: Lead to Qualified to Won / Lost
  • Opportunities linked to client and generated SoW
  • Activity and notes timeline per opportunity
  • Pipeline forecast on the dashboard
  • Win / loss analysis with competitor tracking

CRM integrations

  • Five real connectors: Salesforce, HubSpot, Pipedrive, ConnectWise, Monday
  • Bidirectional sync: deal push on acceptance and stage change
  • Inbound CRM webhooks with HMAC signature verification
  • Conflict detection for competing updates
  • One-click Sync to CRM from any SoW

Intake & scoping

  • Public intake form builder with nine field types
  • Per-form branding, notification emails, optional NDA gate
  • Shareable public slug, unauthenticated submit
  • Convert intake to client, opportunity and scoping session
  • Guided scoping sessions from five seeded templates
  • Scoping session converts to a pre-filled SoW

Statement-of-Work engine

  • Five-step SoW wizard, start from a proposal template
  • Rich editor: sections, assessments, RoE, milestones, team
  • Embedded Rules of Engagement: scopes, windows, boundaries, contacts
  • 12-stage role-gated approval pipeline with segregation of duties
  • Field-level protection: Sales vs Technical fields lock by stage
  • Full per-field audit log with old-to-new diffs
  • Version tracking, one-click clone, live preview
  • Internal and client change requests

Pricing & billing

  • Five pricing models: day-rate, fixed, T&M, retainer, call-off
  • Org pricing config: day rates, margin, complexity multipliers, currency
  • Historical effort estimator: median / P25 / P75 from your signed SoWs
  • Questionnaire-driven effort and price estimation
  • Service catalog across ten categories with per-service day splits
  • Call-off / day-bank contracts with atomic drawdown tracking

Signatures & NDA

  • Native in-app signing: draw, type, upload, or external
  • DocuSign and HelloSign / Dropbox Sign integrations
  • Magic-link multi-party signing for external signers
  • Wet-signed PDF upload with approve / reject review
  • Signature audit trail across the full lifecycle
  • Dedicated NDA module with a nine-stage lifecycle
  • NDA gating blocks SoW send or intake until signed
  • Automated NDA expiry and reminder jobs

Renewals & handoff

  • Save any SoW as a reusable recurring template (full snapshot)
  • One-click renewal into a fresh opportunity and draft SoW
  • Field-level delta diff versus the source SoW
  • Handoff a signed SoW into delivery as a cross-tool project
  • Configurable handoff checklists with completion tracking
  • Idempotent, lock-serialized handoff (no double projects)

AI assist (bring your own model)

  • Three SoW assistants: draft content, effort estimate, pricing advice
  • Human-in-the-loop review, approve or reject before apply
  • Configurable provider with a connectivity test
  • Editable prompt templates with per-org overrides

Admin, RBAC & notifications

  • Eleven-tab admin console
  • User management, password reset, roles and per-user permissions
  • Granular RBAC across the whole pipeline
  • Org policy toggles: approvals, expiry, required QA, reminders
  • In-app notification bell plus around 45 event types
  • Per-user notification preferences and email notifications

Report

Findings, authoring, and delivery
93 features

Scanner import & parsers

  • Import from 40 scanner and tool formats, auto-detected by content
  • Auto-match imported findings to library entries by tool
  • Enrich matched scan findings with curated library content
  • Import-mapping manager and single or bulk relink
  • Bulk CSV import with validation preview, generic CSV / JSON
  • OPF (Open Pentest Format) import and export
  • Import findings from a previous report
  • AI scan-triage: dedupe and false-positive flagging

Findings library

  • A curated library of ~2,476 findings across 26 test types
  • 215 categories, CWE / CVE / MITRE ATT&CK referenced
  • Global (Cairn-maintained) vs organization-private tiers
  • Search plus severity / test-type / category / CWE / tier filters
  • Named filter presets and saved searches
  • Create, clone, AI-generate, and fork findings (copy-on-write)
  • Import into a report or save a report finding back as a template

Finding authoring

  • Word-style rich-text editor with tables, code blocks and images
  • Font color and a severity-preset highlighter
  • Live spellcheck and autocorrect (en-US / en-GB)
  • @mention teammates, 800ms autosave with status
  • Typed references: CVE, CWE, OWASP, MITRE, vendor, article
  • Affected-assets picker against a report asset pool
  • User-defined custom fields: text, number, dropdown, date, boolean
  • Finding badges: Library, Scan, Unmatched, Disclosed

Evidence

  • Screenshot upload (button or drag into the finding)
  • HTTP request / response replay import from HAR, Burp XML, or raw
  • Replay viewer: color-coded methods, status, multi-step sequences
  • Terminal .cast session recordings
  • Video PoC upload (.webm / .mp4) with thumbnails
  • Annotation canvas: pen, shapes, arrows, text, blur / redaction
  • Evidence diff across retests: side-by-side, overlay, pixel-diff
  • Cross-report evidence gallery with search and filter

Finding DNA & correlation

  • Finding-DNA structural fingerprint with component breakdown
  • Automatic clustering of similar findings across engagements
  • Similar-findings ranking with percent-similarity scores
  • Merge duplicates into a survivor (moves assets, refs, evidence)
  • Interactive correlation map: shared CWE, asset, MITRE, CVE, category
  • Cross-report finding timeline with retest outcomes

Collaboration & review

  • Live presence: who is editing versus viewing
  • Entity-level section and finding locks with read-only banner
  • Optimistic-concurrency conflict resolution
  • Tracked changes with per-author accept / reject
  • Inline, threaded comments with severity
  • Multi-stage review: Tech QA, Ops QA, manager approval
  • QA quality-gate checklist before submission
  • Report access roles: Editor, Tech QA, Ops QA, Viewer

Scoring & compliance

  • CVSS 3.1 score and vector throughout
  • Full inline calculator: Base, Temporal, Environmental
  • Paste-and-parse a CVSS vector with validation
  • CWE (validated), OWASP 2021, MITRE ATT&CK tags, CVE lookup
  • Compliance mapping: Pass / Partial / Fail per control
  • Auto-map via AI plus manual, with per-framework appendix
  • Frameworks: ISO 27001, SOC 2, NIST CSF, PCI-DSS

Templating & export

  • Export to PDF, native Word DOCX, and branded HTML
  • Chromium-rendered PDF via Gotenberg
  • Real Word-template merge with embedded evidence images
  • Custom .docx template upload, rendered per organization
  • AI ingestion: parse a DOCX / PDF into a template draft
  • Custom branding: logos, fonts, covers, per-severity colors, themes
  • DRAFT watermark on draft exports
  • Async background export jobs with retries and progress

Attestation & manifests

  • Attestation letters in DOCX, HTML and PDF
  • DOCX five-by-five risk-matrix table
  • Ed25519-signed artifact manifests with per-file SHA-256
  • Offline, in-browser manifest verifier (no server needed)
  • Vulnerability-disclosure flash documents from selected findings

Retest & remediation

  • Retest cycles: Resolved, Partially, Not Resolved, New
  • Verification checklist: HTTP, terminal, screenshot, or manual
  • Client retest-request queue: approve, reject, schedule, assign
  • Remediation dashboard: overdue, due-this-week, SLA aging
  • Per-finding remediation status, due date, notes
  • Remediation priority scoring

AI drafting (redaction-first)

  • Draft descriptions, impact, remediation and executive summaries
  • Automated report QA and phased remediation roadmaps
  • Attack-chain narratives mapped to MITRE ATT&CK
  • Cross-engagement trend analysis and report-diff narratives
  • Client-name, IP and hostname redaction before the model
  • Bring your own provider and key, encrypted per org
  • Six providers incl. self-hosted Ollama; human-in-the-loop approval
  • A dozen report-focused agents; editable prompt templates

Integrations & delivery

  • Two-way ticketing sync across six connectors
  • Jira Cloud & Server, ServiceNow, GitHub, Azure DevOps, Linear
  • SharePoint Online delivery via Microsoft Graph
  • Outbound webhooks to Slack, Teams, and generic endpoints
  • Client delivery portal with requests and messaging
  • Scoped API keys and operator PATs

Analytics, admin & audit

  • Compare two reports: new, resolved, changed, unchanged
  • Cross-engagement trend analysis and recurring-findings table
  • Quarterly trend reports and a regression banner
  • Auto-generated ~2-minute client video summary
  • RBAC across eight roles with a per-role permission editor
  • Cryptographically chained audit trail with integrity verification
  • Offline mode: IndexedDB write queue with FIFO sync
  • Per-finding changelog and keyboard-shortcut help

Client Portal

Delivery and client requests
42 features

Access & authentication

  • Three sign-in methods: SSO, magic link, password
  • Email-domain SSO discovery auto-routes to the client IdP
  • Passwordless magic link, 15-minute single-use
  • Email-enumeration-safe login responses
  • Invite onboarding with 7-day expiring tokens
  • TOTP multi-factor authentication with recovery codes
  • Account lockout after repeated failed attempts

Tenant & client isolation

  • Client role required on every portal route
  • Every query scoped to the user’s granted client IDs
  • Per-client access grants, revocable by operators
  • Only delivered, published or archived reports are visible
  • Path-traversal-guarded evidence access per finding

White-label branding

  • Custom logo and favicon
  • Separate light-mode and dark-mode themes
  • Custom domain per organization
  • Self-service DNS verification via TXT record
  • CNAME validation and domain availability check

Disclosure & notifications

  • Critical and High findings auto-disclose on report delivery
  • Manual per-finding disclosure for operators
  • Disclosed-findings feed with severity, CVSS, remediation status
  • In-app notifications and styled disclosure emails
  • Deep links straight to the finding

Client requests

  • Submit disputes, amendments, remediation evidence, inquiries
  • File attachments on requests
  • Threaded two-way messaging with your team
  • Status lifecycle: Open, In Review, Resolved, Rejected
  • Remediation evidence auto-verifies the finding when resolved

Retests & remediation

  • Request retests spanning multiple findings
  • Lifecycle: pending, approved, scheduled, in progress, completed
  • Operator approve / reject with reason and scheduling
  • Per-finding outcomes: resolved, partial, not resolved, new
  • Remediation progress, risk-trend and severity-trend over time

Notifications & preferences

  • Notification bell with unread count and mark-all-read
  • Per-category, per-channel (email vs in-app) preferences
  • Immediate or digest email, configurable send hour
  • One-click HMAC-signed unsubscribe, no login required

Integrations & security

  • Outbound webhooks with CRUD, live test and delivery history
  • Scoped portal API keys: create, list, rotate, revoke
  • Per-org SMTP with AES-256-GCM-encrypted credentials
  • OIDC secrets encrypted; SAML replay protection
  • Hashed-at-rest tokens for invites, magic links, API keys
  • Full audit logging and per-socket rate limiting

Want the walkthrough?

See the whole set in a two-minute click-through, or book a live session and we will drive it end to end.

← Back to the platform