Cyver Core transitions your team from delivering static, point-in-time PDF reports to a continuous, collaborative, and cloud-based Pentest-As-A-Service model.
Follow this onboarding flow to set up your PTaaS operations: Portal & Templates > Client Enablement > Findings-as-Tickets > Insights > Reporting > Project Retest.
1. Preparing Your Templates & Portal
A. Brand Your Portal
Upload your company logo, customize portal colors, and name your portal to match your brand identity. For a completely white-labeled experience, you can contact us to request a full custom domain.
For a complete walkthrough on styling and branding, read our detailed guide on Customize Portal Appearance.
B. Configure Workflows & Methodologies
- Workflows: The platform includes pre-built workflow templates designed for collaboration. You can use these default options or create your own. (Note: Creating custom workflows requires the Professional/Enterprise plan or an Add-on). To learn more about setting up and assigning workflows, read our article on Workflow Templates.
- Checklists & Compliance Norms: The platform includes pre-built checklists and compliance norms like PCI-DSS and OWASP Top 10. You can utilize these defaults or create your own custom frameworks. Check out our comprehensive guide on Checklists & Tasks for step-by-step instructions on managing your methodologies.
C. Create Your Report Template
Define the visual and structural output by using Cyver Core’s pre-built report templates or by building your own from scratch.
For a complete walkthrough on styling, Markdown, and using tokens, read our detailed guide on Customizing Report Templates.
D. Create Your Pentest Template
Link your chosen Workflows, Checklists, Compliance Norms, and Report Template together to build standardized, repeatable service offerings. If desired, these templates can be made available for your clients to use with the "Request Pentest" feature.
(Note: Enabling the "Request Pentest" workflow requires the Professional plan, or the "Advanced Client Portal" Add-on for Starter plans).
To learn more about customizing pentest templates read our article on Customizing Pentest Templates.
2. Client Portal Enablement
- Onboard the Client: Navigate to Clients and click + New Client.
- Assign Roles: Add client users and assign specific roles (like Manager or Finding Only) to restrict their views based on their responsibilities. (Note: Advanced Client User Roles require the Enterprise plan, or the "Advanced Client Portal" Add-on for Starter/Professional plans).
- Configure Portal Settings: Customize the client's view by toggling specific project tabs on or off. You can apply Client Portal Settings Templates to standardize which features are available to different clients. (Note: Client Portal Settings Templates require the Enterprise plan, or the "Advanced Client Portal" Add-on for Starter/Professional plans).
- Enable Asset Management: Train your clients to navigate to their Assets tab to upload and manage their own assets. When they request a pentest later, they can easily attach these pre-defined assets to the scope.
3. Client Collaboration
A. Deliver Findings-as-Tickets (Live Publishing)
- Navigate to the Findings tab inside the active pentest.
- Import your scanner results or manually add findings from your Finding Library.
- Publish Live: Instead of holding all vulnerabilities until the final PDF is ready, change the status of critical findings to Pending Fix immediately. This pushes the vulnerability to the client's dashboard as an actionable ticket while the pentest is still ongoing.
- Ticketing Integrations: Push vulnerabilities directly to your work management platforms, ensuring developers can track and fix issues without leaving their native workflows. Cyver Core supports seamless workflows, including status and comment syncing, with major platforms. Explore our guides on ServiceNow Integration, Jira Integration, and Azure DevOps Integration to learn more.
B. Request Finding Retest (Finding Level)
When a client applies a patch, they can initiate a retest directly from their portal. By clicking Request Retest on a specific finding ticket, your team is automatically pinged to verify the fix and update the status accordingly. To learn how clients trigger these specific checks, read our guide on Request Findings to be retested.
C. Centralize Communication
- Replace Email Chains: When a client's developer has a question about a specific vulnerability, they can comment directly on the finding ticket.
- Use the Messages and Activity logs on the finding to securely chat, share screenshots, and provide remediation advice in context.
4. Vulnerability Management & Insights
Filter & Prioritize: Easily sort and filter findings by Severity, Status, or associated Asset.
Track Vulnerability Lifecycle: Manage the ongoing remediation process by updating finding statuses. Move vulnerabilities through their lifecycle (e.g., from Pending Fix to Fixed) to ensure everyone is aligned on the current progress.
Export Finding Data: For offline tracking, internal audits, or sharing with external development teams, export the finding lists directly to a CSV, XML or Excel file.
- Leverage Finding Fields: Customize your finding fields to match your specific needs, and ensure every ticket contains the exact data your clients need. (Note: Customizing finding fields requires the Professional plan or the "Advanced Findings Management" Add-on for Starter plans). To learn more about custom finding fields read our guide on Finding Fields: Custom Finding Fields.
- The Insights Dashboard: Instruct your clients to check their Insights tab. Here, Cyver Core automatically generates visual metrics based on their live findings.
- Track Metrics: Clients can track SLA aging (Time-to-Fix), monitor open vulnerabilities per asset, and view their overall Risk Summary directly in the platform, without needing to parse a technical PDF document.
5. Report Generation & Delivery
- Generate the Draft: When the engagement cycle ends, navigate to the Report tab and click Generate Draft Report. The platform automatically pulls in all the live tickets, and scope details into a cohesive report.
- Review & Publish: Use the in-app Report Comments feature to review the report internally with your team before finalizing. Once approved, click Publish to make the final version available in the client portal. (Note: The Report Comments feature requires the Professional plan or the "Advanced Reporting" Add-on for Starter plans).
- Versioning: Generate new report versions easily to reflect changes or retests. For advanced reporting features and token management, explore our article on Generating, Changing, and Duplicating Report Templates.
6. Project Requests & Retesting
When a client requests a brand-new pentest or a full project retest directly from their portal, your team will receive a notification. Review and approve the request to automatically initiate the project scope and workflow. (Note: Both the "Request Pentest" and "Project Retest" workflows require the Professional plan, or the "Advanced Client Portal" Add-on for Starter plans).
To learn how to configure intake forms for new client requests, read our guide on Request Forms.
For a complete walkthrough on setting up entire projects for retesting, check out Retest Project setup.