Solutions / Enterprise

Same estate.
Every quarter, on the record.

The same applications and networks come back every cycle, but last quarter's context lives in someone's folder, and fixed means a ticket was closed. Neuron keeps the testing, the hand-off and the retest in one record, inside your perimeter.

01 / The work

One cycle,
start to verified fix.

A recurring internal assessment from planning to signed-off retest, using features that ship in Neuron today.

Step by step
  1. Week 1

    Schedule the cycle

    Plan engagements, assessments, phases and retests on the Gantt schedule. Assign testers by dragging work onto them, and resolve double bookings before kickoff.

  2. Week 1

    Import the scanners

    Pull in Nessus, Qualys or Nexpose results, plus Prowler and ScoutSuite for cloud. Every issue lands in a triage queue where it can be assigned, grouped by service, dismissed or promoted to a finding.

  3. Week 2

    Test to a method

    Run a playbook such as NIST SP 800-115 or the OWASP API Security Top 10. Coverage comes from the state of each step, and a step marked not applicable needs a reason.

  4. Week 3

    Hand off on approval

    When a finding is approved, a routing rule pushes it to ServiceNow with its evidence images. Pushes queue in the background and retry if ServiceNow does not respond.

  5. Week 8

    Retest

    Open a retest round against the original findings. Each one gets a recorded outcome: resolved, partially resolved, not resolved, risk accepted, or no retest performed.

  6. Week 8

    Sign off

    Verdicts can require a second person to co-sign. Once the round is ready for approval, its results are locked, and the round keeps its own approver, timeline and audit trail.

Timings are examples.

02 / In depth

What holds up
at audit time.

Retests

Fixes you can prove.

A finding closes on a recorded retest outcome, not because a ticket changed state. Each retest round has its own approver, timeline and audit trail.

Sign-off is a deliberate attestation step, designed with PCI DSS v4.0 requirement 11.4.4 in mind. You choose whether critical, critical and high, or all verdicts need a second person.

Scan triage

Scanner output, triaged once.

Scan issues move through New, In Review, Confirmed, Promoted, False Positive, Risk Accepted and Fixed.

  • Unconfirmed detections are badged Possible and sorted below firm ones
  • A check already dismissed as a false positive elsewhere in the engagement is deprioritized
  • Library matches are suggested from the scanner check code, and matching issues promote in bulk
  • Any import can be rolled back, removing every issue it created
Hand-off

Findings reach the people who fix them.

Routing rules push approved findings to ServiceNow based on a condition tree over finding and engagement fields, using your own severity names. Connections authenticate with OAuth2 client credentials, Basic or Bearer.

Every push is queued, retried on failure and recorded in a push history you can export. ServiceNow is the only ticketing connector today. Anything else connects through the REST API, which has OpenAPI documentation and tokens that can be limited to specific engagements.

Identity

Behind your identity provider.

Single sign-on with OIDC (with PKCE) or SAML 2.0, working with Okta, Microsoft Entra ID, Google Workspace, ADFS and Ping. Accounts are never auto-provisioned: an administrator creates each one before its first sign-in.

  • Five staff roles, from superadmin to user
  • A local break-glass superadmin that cannot use SSO or reach day-to-day work
  • Force a password change or MFA enrollment at next sign-in
Coverage

Every assessment type in one place.

The assessment catalogue has 22 templates across applications, infrastructure, adversary simulation and devices. Cloud, Containers and Identity & Access Management map to CIS Benchmarks and MITRE ATT&CK. AI / LLM Application Testing maps to the OWASP Top 10 for LLM Applications and MITRE ATLAS, and records the prompt transcript.

03 / Recommended setup

What to deploy.
And where.

Setup
Deployment
On-premises or in your private cloud, behind your identity provider and your network controls. See how we handle data.
Modules
Neuron Core and Workflow Integrations for ServiceNow. Add Directory for Active Directory and Entra ID testing, and Neuron AI for drafting on your own hardware.
Assessment templates
Web Application, API, Network, Cloud, Containers, Identity & Access Management, Configuration / Hardening Review, and AI / LLM Application Testing.
Integrations
ServiceNow, the REST API, and scanner imports including Nessus, Qualys, Nexpose, OpenVAS, Prowler and ScoutSuite. See the platform page.
Server
10 to 50 users: 4 vCPU, 16 GB of RAM and 100 GB of disk. Linux (Ubuntu 22.04 or later recommended), x64 or arm64, with PostgreSQL 14 or later.
04 / Boundaries

What Neuron
is not.

Out of scope

Not vulnerability management

Neuron triages scanner output for the test in hand. It does not replace the system that tracks every vulnerability across the estate.

Not a ticketing system

Remediation work lives in ServiceNow or your own tooling. Neuron hands findings over and records the retest.

One connector today

ServiceNow is the only ticketing connector that ships today. Other systems connect through the REST API.

05 / Questions

Asked by
enterprise security teams.

FAQ
Which ticketing systems are supported?

ServiceNow, through the Workflow Integrations module, with routing rules that push approved findings automatically. Other systems connect through the REST API.

How do we prove a fix was verified?

Each retest round records an outcome per finding, who signed it off and when, and an optional co-signature. The round has its own audit trail and its results lock once it is ready for approval.

Does it work with our SSO?

Yes. OIDC and SAML 2.0 work with Okta, Microsoft Entra ID, Google Workspace, ADFS, Ping and other standard identity providers.

Can we test cloud, containers and AI applications too?

Yes. The assessment catalogue includes Cloud, Containers, Identity & Access Management and AI / LLM Application Testing, each with its own fields and methodology mapping, and Prowler and ScoutSuite results import into the triage queue.

Who can see what?

Staff have one of five roles, and people are added to each engagement's team. API tokens can be limited to specific engagements, and the Delivery Portal has its own client roles if results go to business units.

Does any engagement data reach PenTest.WS?

No. Neuron runs on infrastructure you control, and we never receive your findings, evidence or credentials.

Do we have to use the AI?

No. Neuron AI is a separate, optional module. When you use it, the models run on your hardware and no prompt is sent to a third-party provider.

Bring your next test cycle.

We will walk your team through a cycle in Neuron, from scanner import to a signed-off retest, behind your own identity provider.