Visibility from scope to certificate

Finally, a pentest you can see.

Live progress, honest timelines, and a certificate anyone can verify — your whole security assessment in one secure workspace. No more going dark between kickoff and a PDF in your inbox.

Publicly verifiable certificates AES-256 encryption everywhere Reviewed to OWASP ASVS Level 2
Acme Mfg · Web App VAPT
Engagement #ACM-P1 · Northwind Security
On track
Testing in progressStage 6 of 12
◆
VuMaS2d ago
Assessment started — testing against the agreed scope.
DL
Delivery Lead4h ago
Web tier underway. We'll need staging access for the authenticated flows.
Blocked — waiting on you. Upload staging credentials to continue. The clock is paused; your due date won't be counted against this wait.
Why VuMaS

A pentest shouldn't be a waiting game.

You approve a scope, then… silence. Weeks later a PDF lands over email, findings live in a spreadsheet, and the retest you were promised quietly never happens. VuMaS replaces all of that with one workspace you can see into the whole way through.

 
The usual way
With VuMaS
Visibility
✕Silence between kickoff and the final report. You chase email to find out where things stand.
✓A live progress view and a running status feed. You always know the stage, the health and what happens next.
Findings
✕Scattered across spreadsheets, re-typed for every report, with IDs that collide.
✓One structured record per finding, a permanent unique ID, and CVSS computed for you — not typed by hand.
Reports
✕Hand-assembled in Word, formatted differently each time, emailed unprotected.
✓Generated to a consistent template, AES-256 encrypted, and read in-app so they never leave the platform.
Retests
✕Promised at sign-off, then quietly forgotten.
✓Scheduled automatically and gated — a retest can't begin until every fix is confirmed in place.
Never in the dark

See exactly where your engagement stands — always.

Every project has a live progress view and a running status feed both teams post to. VuMaS even posts on its own — on every milestone — so you stay informed with nothing to chase. And when something is waiting on your side, it says so, fairly.

app.vumas.in / acme-web-vapt
Testing in progressOn track
Stage 6 of 12Due 24 Sep
◆
VuMaS2d ago
Assessment started — testing against the agreed scope.
DL
Delivery Lead4h ago
Web tier underway. We'll need staging access for the authenticated flows.
Blocked — waiting on you. Upload staging credentials. Clock paused; the due date auto-extends, so you're never marked late for our wait.

A live view of the whole engagement

Twelve clear stages from kickoff to certificate, each with a planned date. Open the project any time and see exactly where things stand.

Progress you can trust

Ahead, on track, delayed or blocked — one honest signal, calculated the same way everywhere. No optimistic spin, no surprises the week before the deadline.

Updates that arrive on their own

The moment testing starts, a report ships, or a blocker clears, everyone sees it — without waiting for a status call or chasing an email thread.

When you're the hold-up, you'll know

If the engagement is waiting on something from your side, VuMaS says so plainly — and pauses the clock, so your team is never marked late for time it didn't cost.

The engagement lifecycle

Six phases. One timeline. No surprises.

Every engagement follows the same clear arc — so you always know what just happened, and what comes next.

Assessment Security Auditor

Auditors test against the agreed scope and capture every finding with evidence as they go. Nothing sits in a personal spreadsheet waiting to be written up.

Findings & CVSS

Every finding, structured and scored — not a spreadsheet row.

A permanent, unique ID

Every finding carries an ID like ACM-P1-WP-001 — unique across all your engagements, and never reused.

CVSS, computed not typed

Scored by the official v3.1 and v4.0 library, so severity always follows the vector and can't be fudged.

Evidence built in

Up to ten verified screenshots per finding, encrypted at rest and embedded directly in the report.

Nothing gets lost

Structured records, not spreadsheet rows — frozen exactly as they were the moment the report is published.

IDFindingSeverityCVSSScore
ACM-P1-WP-001Unauthenticated file read via path traversalCriticalCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H9.1
ACM-P1-WP-004Session fixation on the account login flowHighCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N7.5
ACM-P1-AP-002Stored XSS in the remediation comment fieldMediumCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N6.1
ACM-P1-AP-007Verbose error discloses framework versionLowCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N3.7
ACM-P1-NW-001TLS 1.1 offered on the legacy load balancerInfoCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N0.0
How a report is made

From findings to a sealed, delivered report.

A clear, consistent report generated from your findings, encrypted, and delivered so it never travels in the clear.

01 · STRUCTURE

Sorted and scored

Findings ordered by severity, each with its CVSS score and permanent ID.

critical → high → medium → low → info
02 · ASSEMBLE

A consistent report

Cover, executive summary, findings, evidence and conclusion — the same clear structure every time.

13 sections
03 · SEAL

AES-256 protected

Rendered to PDF and encrypted with a unique, single-use password.

AES-256 · R=6
04 · DELIVER

Revealed once, recorded

The password is shown exactly once, and that reveal is written to the audit trail.

reveal logged · password burned
05 · READ IN-APP

It never leaves

Opened in a secure viewer with copy, print and download suppressed. Your findings stay on the platform.

view-only
06 · CERTIFY

Provable to anyone

A signed certificate that any third party can verify — no account required.

/verify/{serial}
Track every fix

Watch every finding go from open to verified.

You don't just receive a list of problems — you work them to closed inside VuMaS. Update remediation as you fix, see progress at a glance, and know a retest can't even start until every finding is resolved.

One clear status per finding

Open, in progress or remediated — your team updates each finding as the fix lands, right beside the evidence.

Progress everyone can see

A live count of what's fixed and what's outstanding, so a status update never needs a meeting.

The retest is gated

A retest can't be scheduled while any finding is still open. "We'll get to the retest" becomes something the platform enforces.

Re-verified in place

Auditors retest against your original findings, so every fix is confirmed on the record — not just assumed done.

Remediation · Acme Web App VAPT1 of 5 resolved
ACM-P1-WP-001
Unauthenticated file read via path traversal
Open
ACM-P1-WP-004
Session fixation on the account login flow
In progress
ACM-P1-AP-002
Stored XSS in the remediation comment field
Remediated
ACM-P1-AP-007
Verbose error discloses framework version
Open
ACM-P1-NW-001
TLS 1.1 on the legacy load balancer
Open
Retest locked. 4 findings still open — resolve every finding to unlock the retest.

Try it — mark findings as fixed and watch the retest gate unlock.

Certificates & public verification

A certificate anyone can verify. No login, no phone call.

Signed under two-person control

A certificate is prepared, then signed by an authorized signatory before it can go live. Until then it doesn't exist to anyone outside the team.

Tamper-evident by design

It freezes a snapshot — legal names, scope, engagement dates and report hashes — and seals it. Verification recomputes that seal, so any edit is caught.

Lives at a permanent link

Share one verification URL instead of an attachment that gets lost, forwarded and mistaken for the latest version.

Always current

The public page needs no login, is rate-limited, and is never cached — so if a certificate is ever revoked, that shows the instant someone checks.

Certificate valid
VMS-CERT-6EC7FE6A46314F76
Issued toAcme Manufacturing Pvt Ltd
ScopeWeb Application VAPT
Engagement12 Aug – 24 Sep 2026
IssuerNorthwind Security
Report SHA-256a3f1…9c7e
Survive the audit

Every report and certificate for an audit window — in one place.

Group related engagements into a cluster. When an auditor asks for “all your assessments this year,” you open one folder instead of digging through a year of email.

Web Application VAPT — reportACM-P1 · 24 Sep
Web Application VAPT — certificateVMS-CERT-6EC7 · verified
Network VAPT — reportACM-P2 · 30 Aug
Network VAPT — certificateVMS-CERT-3B8D · verified
Your side stays your side

A hard wall between your data and everyone else's.

Each side works in its own space. Your vendor's internal notes and back-channel are structurally invisible to you — and your data is walled off from their other clients. Not a setting someone can flip, but a boundary built into the platform. Your evidence, reports and chat are encrypted and never leave.

What you see Client
Your milestones, deliverables and certificate
Shared chat and status updates
Reports and evidence for your project
Your vendor's private workspace — never
The vendor's private side Vendor only
Walled off from you
Internal notes · draft findings not yet shared · team back-channel · checklist working copy · reviewer comments…
Internal notes and channels live behind one fail-closed boundary. Neither side can reach across it.
Security & trust

Built for security teams — and reviewed like one would.

Everything a security buyer needs to clear procurement, in one place. Proof, not claims.

Independently reviewed

Assessed against the OWASP Top 10 and ASVS Level 2, with a documented go-live checklist you can hand to your own auditors.

OWASP · ASVS L2

SSO with MFA always on

Sign in with Microsoft or Google Workspace. Domain-bound and MFA-enforced — your identity provider decides who gets in.

DPDPA & GDPR consent

Explicit, versioned consent captured at onboarding with a full audit trail, and re-consent whenever a policy changes.

Envelope encryption

Per-file keys, AES-256-GCM, KMS-backed. Reports, evidence, chat and notes are all encrypted, and plaintext never touches disk.

View-in-app only

Reports, certificates and documents open in a secure viewer with copy, print and download suppressed. Data doesn't leave.

A complete audit trail

Every sign-off, password reveal, download and status change is recorded — an exportable history of exactly what happened, and when.

Clear roles, clean handoffs

Everyone gets exactly the access their job needs.

A security assessment has two sides. VuMaS gives each person the access their role calls for — and nothing beyond it — so work moves quickly without ever blurring the line between your team and your vendor's.

Your vendor — runs the assessment
The security team you've engaged
Delivery LeadRuns scheduling, assigns the team, approves the report and issues the certificate.
Security AuditorDoes the testing — findings, evidence, CVSS scoring, checklist and report drafts.
Authorized SignatoryHolds the sole authority to sign and publish a certificate.
Your team — the client
The organisation being assessed
Project ManagerScopes and authorizes the engagement and acknowledges each sign-off.
Project MemberOwns remediation on assigned projects and marks fixes as they land.
ExecutiveRead-only oversight — progress, findings and certificates at a glance, nothing to manage.
See it yourself

Walk through a real engagement in five minutes.

A guided sample project takes you through the actual screens with sample data — role by role, showing each handoff. No signup, no sales call, nothing to install.

Explore the sandbox →
Proof

Specs are table stakes. Here's the outcome.

0+
Assessments run
0+
Certificates issued and verifiable
0%
Retests verified in place
0
Findings lost between test and report

“For the first time we could actually see our pentest happening — and when we were the hold-up, the tool told us plainly. It finished two weeks faster than our last one.”

— Head of Security, mid-market fintech
Get started

See exactly where your next pentest stands.

Book a 30-minute walkthrough with our team, or jump straight into the sandbox. We'll show you the whole engagement — visibility, findings, report and certificate — on your terms.