Solutions / Firms

Run more engagements.
Ship the same quality every time.

Report week. Ten testers, ten writing styles, and a reviewer reading the whole thing the night before it ships. Neuron moves the writing and the review into the engagement, so the report reads like one firm wrote it.

01 / The work

Signed contract
to signed deliverable.

A web application and external network engagement from start to finish, using features that ship in Neuron today.

Step by step
  1. Kickoff

    Start from a template

    Create the engagement from a saved engagement template that already holds the assessments, team, QA reviewers and access. Each assessment brings its own fields, methodology mapping and finding ID prefix.

  2. Day 1

    Import and triage

    Import Nmap, Nessus and Burp Suite results. Scanner issues land in a triage queue, and the ones that already match an approved library finding can be promoted in bulk.

  3. Day 2

    Write from the library

    Testers add findings from the firm's approved library, choosing the variant written for this assessment type and the client's language, with its own severity. They adapt it to what they found rather than starting from a blank page.

  4. Day 3

    Review while testing

    Findings go to review as they are written, not at the end. Track changes is on during review, and approval stays blocked while any tracked change or comment is unresolved.

  5. Day 3

    Tell the client early

    Partially release a critical to the Delivery Portal the day it is found: its number, title, severity and status, without the write-up. The full write-up follows once it is approved.

  6. Day 5

    Generate the report

    Render the report from the firm's own Word template, with the executive summary and methodology briefs drawn from the library in the engagement's language. Reviewer and approver names and dates are part of the report data.

  7. Delivery

    Release under control

    Publish the deliverable under Controlled Release. The client signs an acknowledgement before downloading, recorded as a verifiable receipt, and the PDF is watermarked with the recipient's identity.

Timings are examples.

02 / In depth

Where the consistency
comes from.

Findings library

One approved version of every finding.

Each library finding holds a variant per assessment type and language, each with its own severity and its own review. An approved variant keeps serving engagements while a new draft is edited, and its version history can be restored.

When a tester improves a finding on an engagement, they can push the change back to the library section by section, once the engagement finding has cleared QA.

  • A Stale badge on variants written against an older field configuration
  • Scanner check codes and CVEs mapped to library findings, so imports suggest the right one
  • The whole library exports and re-imports as JSON, with a preview and a rollback
Quality assurance

Review that cannot be skipped.

Findings and briefs move from draft to in review to pending approval to approved. The reviewer and the approver must be different people, and nobody can approve their own work.

The review queue ages. Items turn amber, then red, at thresholds you set, and each reviewer gets a daily digest of what is overdue.

  • Track changes attributes every insertion, deletion, formatting change and caption edit
  • Approval is blocked while any tracked change or comment is unresolved
  • Approved findings and briefs become read-only
Reporting

Your template. Your languages.

Reports render from your own Word templates, including charts fed by engagement data. When you upload a template, Neuron checks its fonts and lists what will be substituted in the PDF. The same data also exports to Excel and Markdown.

Set a default output language and enable more. Each brief is one section with a version per language, so one template serves every language you deliver in.

Scoring

Scored the way your clients ask.

CVSS v4.0 with Threat, Environmental and Supplemental metrics, the full sixteen-factor OWASP Risk Rating, and MITRE ATT&CK mapping. Twelve custom field types cover whatever else your reports need.

Delivery Portal

Delivery that leaves a record.

The Delivery Portal runs as a separate service that can sit in your DMZ, with no database and no encryption keys of its own. Client users sign in with MFA or their own SSO and see only what has been released to them.

Every sign-in, view and download is logged per client, and the log exports to CSV. Clients request retests from the portal, and you accept or decline with a reply they can read.

03 / Recommended setup

What to deploy.
And where.

Setup
Deployment
Your own data center or a cloud account you control. Install guides cover AWS, Azure, Google Cloud and Oracle Cloud. See how we handle data.
Modules
Neuron Core and the Delivery Portal. Add Custom Branding to put your firm's name on the portal, and Neuron AI for drafting on your own hardware.
Assessment templates
Web Application, API, Mobile, Thick Client, Network (External and Internal), Cloud and Active Directory, from a catalogue of 22.
Imports
Nmap, Masscan, Nessus, Qualys, OpenVAS, Nexpose, Nuclei, Nikto, Burp Suite, OWASP ZAP, Acunetix, Invicti and more. See the platform page.
Server
10 to 50 users: 4 vCPU, 16 GB of RAM and 100 GB of disk. Linux (Ubuntu 22.04 or later recommended), x64 or arm64, with PostgreSQL 14 or later.
04 / Boundaries

What Neuron
is not.

Out of scope

Not a testing marketplace

Neuron does not supply testers or resell testing. It is the system your own team works in.

Not hosted by us

There is no shared SaaS tenant. You run Neuron, so you also own its backups and updates. Updates install from inside the app.

Not self-serve

There is no credit-card signup. Every deployment starts with a briefing, because it runs on your infrastructure.

05 / Questions

Asked by
penetration testing firms.

FAQ
Can we keep our existing report template?

Yes. Neuron renders reports from your Word templates using Jinja2 placeholders, including charts fed by engagement data. Font substitutions for PDF output are flagged when you upload the template.

Can we bring our existing findings library?

Yes. The library imports from JSON with a preview before anything is written and a rollback afterwards, and it exports in the same format.

Do we deliver in more than one language?

You can. Set a default output language and enable more. Library variants and briefs carry a version per language, and an engagement pulls them in its own language.

Can clients see findings before the report is final?

Only when you choose. Partial release shows a finding's number, title, severity and status. Full release adds the write-up. A finding that has not been released returns not found, so clients cannot discover work still in review.

Can we put our brand on the portal?

Yes, with the Custom Branding module, which puts your firm's name and look on the portal and its sign-in pages.

Does any engagement data reach PenTest.WS?

No. Neuron runs on infrastructure you control, and we never receive your findings, evidence or credentials.

Do we have to use the AI?

No. Neuron AI is a separate, optional module. When you use it, the models run on your hardware and no prompt is sent to a third-party provider.

Bring your report template.

We will show you a finding go from the library to a signed deliverable in your own template, with your review steps, on a deployment like yours.