Finally, a pentest you can see.
Live progress, honest timelines, and a certificate anyone can verify — your whole security assessment in one secure workspace. No more going dark between kickoff and a PDF in your inbox.
A pentest shouldn't be a waiting game.
You approve a scope, then… silence. Weeks later a PDF lands over email, findings live in a spreadsheet, and the retest you were promised quietly never happens. VuMaS replaces all of that with one workspace you can see into the whole way through.
See exactly where your engagement stands — always.
Every project has a live progress view and a running status feed both teams post to. VuMaS even posts on its own — on every milestone — so you stay informed with nothing to chase. And when something is waiting on your side, it says so, fairly.
A live view of the whole engagement
Twelve clear stages from kickoff to certificate, each with a planned date. Open the project any time and see exactly where things stand.
Progress you can trust
Ahead, on track, delayed or blocked — one honest signal, calculated the same way everywhere. No optimistic spin, no surprises the week before the deadline.
Updates that arrive on their own
The moment testing starts, a report ships, or a blocker clears, everyone sees it — without waiting for a status call or chasing an email thread.
When you're the hold-up, you'll know
If the engagement is waiting on something from your side, VuMaS says so plainly — and pauses the clock, so your team is never marked late for time it didn't cost.
Six phases. One timeline. No surprises.
Every engagement follows the same clear arc — so you always know what just happened, and what comes next.
Assessment Security Auditor
Auditors test against the agreed scope and capture every finding with evidence as they go. Nothing sits in a personal spreadsheet waiting to be written up.
Every finding, structured and scored — not a spreadsheet row.
A permanent, unique ID
Every finding carries an ID like ACM-P1-WP-001 — unique across all your engagements, and never reused.
CVSS, computed not typed
Scored by the official v3.1 and v4.0 library, so severity always follows the vector and can't be fudged.
Evidence built in
Up to ten verified screenshots per finding, encrypted at rest and embedded directly in the report.
Nothing gets lost
Structured records, not spreadsheet rows — frozen exactly as they were the moment the report is published.
| ID | Finding | Severity | CVSS | Score |
|---|---|---|---|---|
| ACM-P1-WP-001 | Unauthenticated file read via path traversal | Critical | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H | 9.1 |
| ACM-P1-WP-004 | Session fixation on the account login flow | High | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N | 7.5 |
| ACM-P1-AP-002 | Stored XSS in the remediation comment field | Medium | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N | 6.1 |
| ACM-P1-AP-007 | Verbose error discloses framework version | Low | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N | 3.7 |
| ACM-P1-NW-001 | TLS 1.1 offered on the legacy load balancer | Info | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N | 0.0 |
From findings to a sealed, delivered report.
A clear, consistent report generated from your findings, encrypted, and delivered so it never travels in the clear.
Sorted and scored
Findings ordered by severity, each with its CVSS score and permanent ID.
A consistent report
Cover, executive summary, findings, evidence and conclusion — the same clear structure every time.
AES-256 protected
Rendered to PDF and encrypted with a unique, single-use password.
Revealed once, recorded
The password is shown exactly once, and that reveal is written to the audit trail.
It never leaves
Opened in a secure viewer with copy, print and download suppressed. Your findings stay on the platform.
Provable to anyone
A signed certificate that any third party can verify — no account required.
Watch every finding go from open to verified.
You don't just receive a list of problems — you work them to closed inside VuMaS. Update remediation as you fix, see progress at a glance, and know a retest can't even start until every finding is resolved.
One clear status per finding
Open, in progress or remediated — your team updates each finding as the fix lands, right beside the evidence.
Progress everyone can see
A live count of what's fixed and what's outstanding, so a status update never needs a meeting.
The retest is gated
A retest can't be scheduled while any finding is still open. "We'll get to the retest" becomes something the platform enforces.
Re-verified in place
Auditors retest against your original findings, so every fix is confirmed on the record — not just assumed done.
Try it — mark findings as fixed and watch the retest gate unlock.
A certificate anyone can verify. No login, no phone call.
Signed under two-person control
A certificate is prepared, then signed by an authorized signatory before it can go live. Until then it doesn't exist to anyone outside the team.
Tamper-evident by design
It freezes a snapshot — legal names, scope, engagement dates and report hashes — and seals it. Verification recomputes that seal, so any edit is caught.
Lives at a permanent link
Share one verification URL instead of an attachment that gets lost, forwarded and mistaken for the latest version.
Always current
The public page needs no login, is rate-limited, and is never cached — so if a certificate is ever revoked, that shows the instant someone checks.
Every report and certificate for an audit window — in one place.
Group related engagements into a cluster. When an auditor asks for “all your assessments this year,” you open one folder instead of digging through a year of email.
A hard wall between your data and everyone else's.
Each side works in its own space. Your vendor's internal notes and back-channel are structurally invisible to you — and your data is walled off from their other clients. Not a setting someone can flip, but a boundary built into the platform. Your evidence, reports and chat are encrypted and never leave.
Built for security teams — and reviewed like one would.
Everything a security buyer needs to clear procurement, in one place. Proof, not claims.
Independently reviewed
Assessed against the OWASP Top 10 and ASVS Level 2, with a documented go-live checklist you can hand to your own auditors.
SSO with MFA always on
Sign in with Microsoft or Google Workspace. Domain-bound and MFA-enforced — your identity provider decides who gets in.
DPDPA & GDPR consent
Explicit, versioned consent captured at onboarding with a full audit trail, and re-consent whenever a policy changes.
Envelope encryption
Per-file keys, AES-256-GCM, KMS-backed. Reports, evidence, chat and notes are all encrypted, and plaintext never touches disk.
View-in-app only
Reports, certificates and documents open in a secure viewer with copy, print and download suppressed. Data doesn't leave.
A complete audit trail
Every sign-off, password reveal, download and status change is recorded — an exportable history of exactly what happened, and when.
Everyone gets exactly the access their job needs.
A security assessment has two sides. VuMaS gives each person the access their role calls for — and nothing beyond it — so work moves quickly without ever blurring the line between your team and your vendor's.
Walk through a real engagement in five minutes.
A guided sample project takes you through the actual screens with sample data — role by role, showing each handoff. No signup, no sales call, nothing to install.
Specs are table stakes. Here's the outcome.
“For the first time we could actually see our pentest happening — and when we were the hold-up, the tool told us plainly. It finished two weeks faster than our last one.”
See exactly where your next pentest stands.
Book a 30-minute walkthrough with our team, or jump straight into the sandbox. We'll show you the whole engagement — visibility, findings, report and certificate — on your terms.