Findings reach you while the test is still running
A consultant finds it, a tech lead reviews and approves it, and it publishes to your portal with an alert at the severity you choose. A critical found on day three is yours on day three, not when the report ships.
The portal your findings land in: each one as it is approved, the retest request on the same screen, what was actually tested, and the deliverables when you want them.
- Testing since 2014
- 850+ assessments run through it
- 7,600+ findings documented
- Every finding approved before you see it
Client Experience
Hand a developer something they can fix today
Impact, reproduction steps, CVSS and a specific fix, with your ticket reference on it. Your engineers reproduce the issue without calling us, and you ask for verification once it is done.
Every open issue, one list
Findings across every engagement, filtered by severity and remediation state. The status you see is the approved status, never a tester's work in progress.
The finding, not a summary of it
Impact, reproduction steps, CVSS and fix guidance specific enough for whoever owns the fix. Add your own ticket reference and owner notes, which never appear in our report, then request a retest from the same place.
What was actually tested
In-scope hosts, resolved hostnames, open ports and service fingerprints, plus a scope map that collapses sprawl into the few entry points that are genuinely reachable.
Exposed credentials, with the source
Breach-sourced credentials tied to your domains, with the breach source and date, so your identity team can force resets. Values stay masked until you choose to reveal them.
Deliverables on your schedule
Confirmed findings in writing as each one is approved, ahead of the formal report, then the full report, executive summary, letter of attestation and CSV when you want them.
Whether you are getting better
Severity-weighted impact, remediation progress, and how this engagement compares with a typical test of its type. Year over year, on the same scope, so the comparison means something.
Access & Confidentiality
Built for enterprise security teams
Compartmentalize by team, log in with your own identity provider, and pull your data into your own tools. The controls a large or regulated organization has to ask about, built in rather than promised.
Per-team confidentiality
Grant each team access to only the assessments they own. Your payments team never sees the identity team's findings, with per-assessment access control inside your own organization.
Self-service team management
Your security lead adds colleagues, decides who sees which assessments, and removes people who leave, with no support ticket to us.
SSO with real deprovisioning
Log in with your identity provider (Okta, Entra ID, or any OIDC). Disable someone there and their access is gone. MFA by authenticator app or email, with trusted-device support.
Notification controls
Choose which events you are alerted on and at what severity, by email or in your own Slack channel. Where per-team access is enabled, you are only notified about the assessments you can see.
Read-only client API
Pull your findings, assessments and projects into your own GRC platform, SIEM or dashboards through a scoped, read-only API key that cannot write anything.
Buying for SOC 2 or a customer questionnaire? Thirty minutes against your own scope, and we will say so if a single traditional test is all you need.
Schedule a MeetingHow It Runs
Tools find the surface. People find the way in.
Automation does the breadth: every host, port, service and exposed credential, mapped before anyone starts. The depth is a consultant, and it is most of the engagement.
- Stage 01
Scope it and sign
Review an interactive proposal, adjust the scope yourself, and watch the price move as you do. Sign the statement of work electronically. No three-week email thread to agree what is in scope.
- Stage 02
Map what you actually expose
Nmap, Naabu, Nuclei and httpx run through production pipelines and roll into one attack surface: resolved hostnames, open ports, service fingerprints, subdomains nobody remembered, and credentials of yours already sitting in breach corpora. This is the starting line. It is also the part some vendors sell as the whole test.
- Stage 03
Test it by hand
Then a consultant works it. On an application that means every boundary between user roles, in both directions, plus the business logic a scanner has no model for. On a network it means the issues we report most often: certificate services misconfigured into a domain-admin path, credentials sitting in a share any user can read, name resolution nobody ever turned off.
- Stage 04
Chain it into something that matters
A finding on its own is a severity label. The work is joining them up: a foothold on one workstation into domain-wide access, an information disclosure nobody rated into an account takeover. That is the difference between a list of issues and an answer to what an attacker would actually do to you.
- Stage 05
Findings reach you as they land
Each finding is published to your portal once it is confirmed and approved, with an email or a Slack message at whatever severity floor you set. A critical issue found on day three is yours on day three.
- Stage 06
Two reviews before the report ships
A second consultant peer-reviews the work, requesting changes against a frozen snapshot until it is approved, and a delivery gate stops a report shipping before that happens. An AI pass runs first, catching typos, severity mismatches and gaps so the human review is spent on judgment.
- Stage 07
Remediate, and we verify
Fix something, request a retest from the finding itself, and we verify it against the original evidence. The verification is recorded against the same finding your auditor will read.
New to this delivery model? What PTaaS actually means covers it without the sales gloss.
The Real Difference
Four things a scan vendor cannot tell you
Plenty of vendors now sell a portal. These are the parts that decide whether the portal is worth logging into.
A named person owns every finding
Every finding is written by a consultant and approved by a second one before it reaches you. Automation and AI review sit underneath that, catching mistakes before a reviewer spends attention on them. They do not write your findings, and no report ships without a human approving it.
You see approved state, not work in progress
Client-facing views render the approval snapshot rather than live internal state, so a status never flips under you mid-retest and unpublished work stays unpublished. That is enforced on the server, not hidden in the interface, and it is the part of a portal nobody thinks to ask about until it goes wrong.
Retesting is in the engagement, not the next one
Verification of a fix is not a new statement of work. You request it from the finding, we test it against the original evidence, and the result lands on the same record.
The report is one export of the record
Findings are structured records, not paragraphs in a document. They export to Jira with severity mapped to priority, pull through a read-only API into your own dashboards, and roll up into trends across engagements. A scan report is a dead end by comparison.
The fastest way to check any of this is to read the deliverable. Our sample reports are published without a form, because the report is what you are actually buying.
Capabilities
The tooling behind the testing
What the platform contributes to your engagement. The parts that run our practice rather than your assessment are on the platform page for firms.
Recon & Attack Surface
- Nmap port and service discovery
- Nuclei template-based vulnerability checks
- Subdomain enumeration (Chaos, certificate transparency, certificate names read from every open port)
- HTTP probing and technology fingerprinting
- In-scope versus out-of-scope classification
- Recurring discovery between engagements
- What changed since the last scan, shown in your attack surface
Breach & Credential Exposure
- Automated per-domain breach lookups
- Source database and date per record
- Plaintext masked until you reveal it
- On your Attack Surface tab, and as a masked appendix in the full report
- Deduplicated across breach sources
- Used live in password-spray testing
Quality Gates
- 500+ curated finding templates
- CVSS 3.1 and 4.0 scoring
- AI review with a 0-100 quality score
- Severity mismatch detection
- Multi-round peer review with delivery gating
- Sanitized before any AI review runs
Deliverables
- Full report in PDF, from the portal or by share link
- Finding Notification PDF before formal sign-off
- Executive summary for your board
- Letter of attestation for your customers
- CSV export of approved findings
- Multi-assessment combined reports
- Findings and report sections readable in the portal
Integration & Evidence
- Jira export with severity mapped to priority
- Evidence images attached to tickets
- Read-only API for findings and assessments
- Field-level change history on every finding, available to your auditor on request
- Time-limited, revocable report share links
- Retest history recorded per finding
- SOC 2 and PCI DSS evidence support
Your Shortlist
How we compare
You are probably weighing us against a traditional firm and something scan-led calling itself PTaaS. Here is where each one actually differs.
Swipe sideways to see each column.
| What you get | TrustFoundry | Traditional Firm | Scan-Led Vendor |
|---|---|---|---|
| Expert manual testing, not scan triage | — | ||
| Findings visible during the engagement | — | Partial | |
| Client portal with your own SSO | — | ||
| You see approved state, not live internal state | n/a | — | |
| Retest included, requested from the portal | Varies | Partial | |
| Your ticket reference and owner notes per finding | — | Partial | |
| Per-instance CVSS and affected locations | Manual | Partial | |
| Jira export with severity mapping | — | ||
| Read-only API into your own tooling | — | Partial | |
| Breach and credential exposure included | Extra | — | |
| Attack surface and scope map | Appendix | Partial | |
| Year-over-year comparison on the same scope | — | Partial | |
| AI quality review plus human peer review | — | — | |
| Per-team access control inside your org | — | Partial | |
| Field-level change history, on request for your auditor | — | Partial | |
| Letter of attestation for your customers | Partial |
“Traditional Firm” = expert manual testing delivered as a PDF over email. “Scan-Led Vendor” = an automated scanning service sold with a portal on top. Both are real options, and the honest answer is that the first is often good work packaged badly.
Under the Hood
Integrated tools & services
Security tooling orchestrated through production pipelines, plus the integrations that tie an engagement together.
Security Tools
Platform Integrations
All product names and trademarks are the property of their respective owners. References here describe interoperability and do not imply endorsement or affiliation. Commercial tools such as Nessus and Burp Suite are supported via import and integration, and are licensed separately by their vendors.
See it against your own scope
Book thirty minutes. We will walk the portal with your environment in mind, tell you which assessments actually fit, and scope it honestly. If a single traditional test is all you need, we will say so.
Run a pentest firm yourself rather than buying testing? The same platform is available to other firms as Hexecution.