Solutions / Providers

Dozens of clients.
One operation.

Testers move between clients every week, the schedule lives in a spreadsheet, and every client expects their evidence to stay theirs. Neuron gives the practice one operating picture without mixing anyone's data.

01 / The work

A month across
many clients.

How a provider runs parallel engagements in one Neuron deployment, using features that ship in Neuron today.

Step by step
  1. Monday

    See the month

    The Gantt schedule shows every engagement, assessment, phase and retest across the practice. Filter by client or person, drag work between testers, and let the overload view catch double bookings.

  2. Monday

    Spin up from templates

    Each recurring client has an engagement template holding its assessments, team, QA reviewers and access, so this month's engagement starts where last month's was set up.

  3. Midweek

    Same words, any tester

    Whoever is staffed writes from the same approved library and the same playbooks, so the fortieth report of the month reads like the first.

  4. Midweek

    Review at capacity

    Findings flow into review queues with amber and red aging. Overdue items go out in a daily digest, so review keeps pace as headcount grows.

  5. Friday

    Deliver per client

    Each client sees only their own engagements in the Delivery Portal. Their engineers see only the engagements assigned to them.

  6. Month end

    Show the client what happened

    Every sign-in, view and download is logged per client, with an all-clients view for the practice and a CSV export.

Timings are examples.

02 / In depth

Scale without
mixing clients.

Scheduling

One schedule for the practice.

Engagements, assessments, phases and retests share one Gantt view, with allocations that cascade from an engagement down to its assessments and phases. Drop work on a tester to reassign it, and resolve conflicts in place.

  • Lead, member and observer allocation roles
  • Filters that persist as you move between views
  • Retests scheduled alongside new work, not in a separate tracker
Client separation

Each client sees their own, and only that.

Portal accounts belong to one client organization. Admin, Manager and Read only roles see that client's engagement history. The Engineer role sees only what you assign, for clients with contractors or large teams.

Findings stay invisible until you release them. Partial release shows the number, title, severity and status; full release adds the write-up.

House wording

Consistency that does not depend on who was staffed.

An approved library variant per assessment type and language, briefs with a version per language, and playbooks with coverage built from step states. A tester's improvement only flows back to the library after it clears QA.

Custom Branding

Your name on the portal.

The Custom Branding module puts your practice's name and look on the Delivery Portal and its sign-in pages. Watermarks on delivered PDFs carry the recipient's identity and, if you choose, their IP address.

03 / Recommended setup

What to deploy.
And where.

Setup
Deployment
One Neuron deployment for the whole practice, on infrastructure you operate, with the Delivery Portal in your DMZ. See how we handle data.
Modules
Neuron Core, the Delivery Portal and Custom Branding. Add Workflow Integrations if clients want findings in ServiceNow, and Neuron AI for drafting.
Assessment templates
Network (External and Internal), Web Application, API, Cloud and Configuration / Hardening Review, from a catalogue of 22.
Portal roles
Admin, Manager, Engineer and Read only, per client organization, with MFA and backup codes.
Server
Over 50 users: 8 vCPU, 32 GB of RAM and 200 GB of disk. Linux (Ubuntu 22.04 or later recommended), x64 or arm64, with PostgreSQL 14 or later.
04 / Boundaries

What Neuron
is not.

Out of scope

Not multi-tenant SaaS

Neuron is one deployment you run. Clients are separated inside it by access and release controls, not by separate hosted tenants.

Not a billing system

Neuron schedules and delivers the work. Contracts, invoicing and time sheets stay where they are.

Not a client CRM

Client records hold contacts, locations and portal access for the engagement. Sales pipelines belong elsewhere.

05 / Questions

Asked by
managed security service providers.

FAQ
How are clients kept apart?

Each portal account belongs to one client organization and sees only that client's released work. Staff access is set per engagement team, and unreleased findings are invisible in the portal.

Can a client's contractors get limited access?

Yes. The Engineer portal role sees only the engagements explicitly assigned to it, unlike Admin, Manager and Read only, which see the client's whole history.

Can clients use their own SSO for the portal?

Yes. Portal sign-in supports OIDC and SAML per client, alongside MFA with backup codes for password accounts.

Can we show a client who accessed their report?

Yes. Each client has a portal activity log of sign-ins, views, downloads and status changes, exportable to CSV, and deliverables under Controlled Release carry a signed acknowledgement receipt.

Does any engagement data reach PenTest.WS?

No. Neuron runs on infrastructure you control, and we never receive your findings, evidence or credentials.

Do we have to use the AI?

No. Neuron AI is a separate, optional module. When you use it, the models run on your hardware and no prompt is sent to a third-party provider.

Show us a month of your practice.

We will walk you through scheduling, delivery and client separation in Neuron, on a deployment you would operate.