For MSSPs & security consultancies

Standardise and Scale Security Assessment Delivery

More assessments mean more findings to review, different deliverables for each client, and retest requests arriving while the next engagement is already underway. Security Reporter is a self-hosted assessment and reporting platform that keeps delivery consistent, while your testers retain the methods and professional judgement each engagement requires.

Toreon Telenor European Central Bank Orange Cyberdefense ABN AMRO ASML Capgemini Sogeti EY Schneider Downs NFIR Toreon Telenor European Central Bank Orange Cyberdefense ABN AMRO ASML Capgemini Sogeti EY Schneider Downs NFIR

Move Beyond Document-Based Delivery

For many security providers, the report is still at the centre of the assessment. Testers document findings, reviewers exchange comments, and remediation and retesting follow afterwards through separate emails, documents or tickets.

Security Reporter keeps the assessment itself at the centre. Findings, evidence, review, client communication, remediation and retesting stay connected, and reports are generated from the work already documented.

  1. Prepare

    Define scope, methodology, requirements and assessment structure.

  2. Test

    Document findings and evidence as testing progresses.

  3. Review and report

    Review findings in context and generate technical and management deliverables.

  4. Collaborate and remediate

    Questions, remediation updates and new evidence stay with the finding.

  5. Retest

    Verify fixes using the original finding and assessment context.

Collaboration at every stage Testers, reviewers and clients work around the same assessment information.

The report should be the outcome of the assessment, not the workflow itself.

Scale the Delivery Around the Testing

Every extra assessment adds specialist time around the testing itself: reporting, review, client coordination and follow-up. Security Reporter structures that work around the assessment.

Team knowledge

Start from Established Team Knowledge

A new tester joins an engagement for a long-standing client. They need your team’s reporting standard and approved remediation guidance, without searching old reports or asking a senior colleague to reconstruct it.

With the shared library of approved findings, remediation guidance and assessment structures, they start from what the team already knows and write to the same standard as everyone else, without being forced into one technical approach.

Templates and efficient workflows

A finding built from the library and your own evidence On the left, a finding library with four approved findings above a terminal window with tool output. On the right, a finding editor titled NTLM relay to SMB. One arrow runs from a highlighted library finding to the Description section, another from the terminal to the Evidence section. Finding library Approved Approved Approved Approved NTLM relay to SMB Approved Description Remediation Evidence

Review and oversight

Review in Context, Keep Delivery in View

Two reports are due this week, one finding still needs stronger evidence, and retest requests are arriving from earlier engagements.

Reviewers check whether the evidence supports the impact and whether the remediation advice is actionable, discuss it where the finding is written and compare every revision line by line. Team leads see what is ready, what is waiting for review and which retests are outstanding.

Collaborate with team members

Review in context, delivery in view On the left, the review of the finding NTLM relay to SMB: revision 2 of its impact section, with removed lines struck through and added lines highlighted, a reviewer comment, and Approve and Request changes buttons. On the right, this week's delivery overview listing three assessments by status: awaiting review, due Friday and retest requested. FINDING REVIEW NTLM relay to SMB Revision 2 Impact − − + + + Reviewer Approve Request changes Delivery overview This week Awaiting review Due Friday Retest requested

Let Clients Act Before the Final Report

A high-severity finding is ready while testing continues. Once it is reviewed, your team can publish it to the client, discuss the evidence and let remediation begin before the final report is delivered.

Client portal

One Place for Every Client Conversation

Clients reply with context, questions and scope changes in the portal, connected to the assessment and its findings instead of spread across email threads.

Your team controls publication and assessment access, so each client contact sees the information intended for them.

Work with clients in one place

A client supplies network context and an attachment, requests a scope change, and receives a reply from the researcher in Security Reporter.

Generate Reports From the Work Already Done

The final report remains an important client deliverable. The client’s engineers need evidence and remediation guidance; its management needs priorities and progress. Producing both should not require testers to reconstruct information that already exists.

Security Reporter generates technical and management reports from structured assessment data, while you keep control of your own templates, branding and reporting standards. Each client receives the deliverables it requires, without anyone reformatting the same information.

Illustrated management report Illustrative data, not customer results: 12 findings, 8 resolved and 4 open. The open findings comprise one High, two Medium and one Low. Charts show remediation progress and remaining findings; placeholder prose represents priorities and next steps. Management summary Assessment overview Remediation status 12 findings Resolved 8 Open 4 8 of 12 resolved Open findings by severity High 1 Medium 2 Low 1 Priorities and next steps

Management report

Remediation progress, open findings and priorities.

Illustrated technical report Illustration based on an example Security Reporter report. An injection finding shows its original High severity and an OK retest outcome. Description, risk and recommendation sections use placeholder bars for detailed prose. 3.3. A03:2021 — Injection Reflected cross-site scripting (XSS) Retested: OK Original severity High Description Risk Recommendation

Technical report

Findings, risk, recommendations and retest outcomes.

Keep Remediation and Retesting Connected

Weeks after delivery, a client requests a retest while the original tester is on another engagement. A colleague needs to understand the original evidence and what the client changed before verifying the fix.

In Security Reporter, the colleague returns to the evidence, remediation updates and earlier discussion on the finding before verifying the fix. Where a client tracks remediation in its own ticketing system, a configured integration can create or update a linked ticket from the finding.

From reviewed finding to verified fix Illustrative High finding: NTLM relay to SMB gives administrative access to a file server. A reviewer checks the evidence. The researcher publishes to the client during the assessment. The client starts remediation and requests a retest. The researcher verifies the fix. FILE-SRV-02 Service: SMB / TCP 445 Signing required: No Relayed session: Accepted Administrative access: Confirmed FINDING NTLM relay to SMB High Medium Low Info EVIDENCE Administrative access to FILE-SRV-02 FINDING REVIEW Original Reviewed Impact needs context Privileged access confirmed 1 Reviewed Reviewer Evidence checked. 2 Published to client Researcher During the assessment. 3 Remediation started Client Require SMB signing. 4 Ready for retest Client Fix applied. Verified Researcher Relay no longer succeeds.
From reviewed finding to verified fix Illustrated example. Evidence from FILE-SRV-02 shows administrative access over SMB. The published High finding NTLM relay to SMB is checked by a reviewer, the client reports the fix is ready for retest, and the researcher verifies that the relay no longer succeeds. FILE-SRV-02SMB / TCP 445Admin access confirmedPublished findingNTLM relay to SMBHighReviewerEvidence checkedClientFix ready for retestResearcherRelay no longer succeeds

Keep Sensitive Client Data Under Your Control

Before an engagement begins, a client asks where their findings and evidence will be stored and who can access them. Security providers handle some of their clients’ most sensitive security information: vulnerabilities, evidence, screenshots, infrastructure details and remediation discussions.

  • Where client data lives

    Security Reporter is self-hosted, so findings and evidence stay on infrastructure you control.

  • Who can see it

    Assessment-level roles and permissions decide what each client contact sees.

  • How the supplier is assessed

    DongIT, the company behind Security Reporter, is ISO/IEC 27001:2022 certified and carries the Cybersecurity Made in Europe label.

    • ISO 27001:2022 certified company
    • Cybersecurity Made in Europe label

Why Security Reporter is self-hosted

Line illustration: a tall server cabinet with one drawer pulled out, holding finding cards, a screenshot and a report page. A thin line runs from the drawer to a small browser window beside the cabinet, where the client sees the same finding while the files stay in the cabinet.

A Tested Platform, Maintained by the People Who Build It

Building an internal reporting tool is only the beginning. Once your team depends on it for client delivery, security testing, updates and support become ongoing responsibilities alongside your assessment work.

A security provider is judged by how it handles client data. The platform that holds it deserves the same care as the rest of your service.

  • Independently tested

    Security Reporter undergoes independent security testing, and qualified prospective customers can review the latest penetration test report on request.

  • Maintained and updated

    Security Reporter follows a monthly release schedule. Releases bring product improvements and, when needed, security fixes, and you are notified when an update is available. When a customer request adds value for Security Reporter and its other customers, we build it into the standard product at no charge.

  • Support from the people who build it

    No intermediaries. Your questions go straight to the developers of Security Reporter, who respond quickly and understand assessment delivery.

On our standard licence, pricing is based primarily on team size, so increasing assessment volume alone does not increase its cost.

Request the penetration test report

Meet the team behind Security Reporter

Recent releases

All release notes
73 published release notes since April 2021
FAQ

Questions Before the Demo

Can we keep our reporting standards and client-specific deliverables?

Your branding and report structure are configurable, and we review your requirements during the evaluation. Security Reporter generates PDF reports from the assessment data, with your branding and your choice of sections per assessment type, template or assessment, and separate technical and management reports. Security Reporter supports multilingual reporting. Changes are made in the findings, templates or report configuration, and the report is generated again. We help you set up your initial report theme as part of onboarding. Security Reporter does not generate Word reports. If editable Word output is required, a separate document-generation workflow can be built using data retrieved through the API.

Professional PDF reporting

Can each client see only the information intended for them?

Yes. Assessment-level roles and fine-grained permissions control who can see published findings, reports, discussions and retest requests. Client access is configured for each assessment.

Role-based user management

Can we keep using our existing testing tools and client ticketing systems?

Yes, through imports and configured integrations. Output from supported tools, including Nessus, Qualys, Nmap and Burp Suite, is imported directly into the assessment. Other systems, such as a client's Jira or Azure DevOps, connect through the REST API and webhooks, or through Zapier and n8n, for example to create or update a ticket from a finding. Supported file imports use Security Reporter's import functionality; connections to other systems are configured around the data and actions you want to exchange.

API, webhooks and integrations

What happens to our existing findings and assessment history when we move?

You decide what to keep as reference and what to migrate. Earlier reports can be kept as attachments on assessment records, so they stay available as reference; their findings are not converted into structured records automatically. Supported tool output can be imported, and an existing finding library, from Word or an in-house tool, can be migrated into Security Reporter as structured data through the API. We agree the field mapping before the migration starts.

Template library and researcher guidance

Is Security Reporter priced per assessment or per report?

No. Security Reporter is licensed as one product. Our standard licence has no per-assessment or per-report charges, no feature tiers and no usage-based API charges. Pricing is based primarily on team size, so increasing assessment volume alone does not increase its cost. Team size is the number of administrators and researchers; client accounts and external testers do not count towards it.

View Security Reporter pricing

How is Security Reporter deployed and maintained?

Security Reporter is self-hosted and deployed with Docker on infrastructure you control, on-premises or in a private cloud, so client findings, evidence and reports stay within your environment. Your team runs the installation and decides when to update; we develop and maintain the software on a monthly release schedule, with support from the developers.

Why Security Reporter is self-hosted

Can we export our data if we decide to move away?

Yes. Generated PDF reports, attachments and other evidence are stored on storage you control, such as your own file share, and can be copied without our help. Findings, assessment templates, finding templates and other structured records can be retrieved through the API as JSON. If active work stops but the installation must stay accessible, for example to answer a client's question about an earlier assessment, a dormant licence keeps the data available and includes security updates.

How do we evaluate a move from Word or an internal tool?

Start with a representative engagement. Bring a representative report and engagement workflow. Together we walk through your reporting requirements, finding review, client access and retesting, and identify what needs configuration or migration before a wider rollout. You can run production assessments in Security Reporter during an agreed proof-of-concept period while your current way of working remains available.

Does Your Assessment Workflow Look Familiar?

If your team delivers assessments across separate documents, emails and tools, see how Security Reporter could fit into your existing delivery process.