Features

26 modules. One platform.

Core engagement 6 modules

01

Dashboard & analytics

Real-time operational view, scoped by role

Gives a live overview of the firm’s entire pentest activity from the moment you sign in, filtered automatically according to the user’s role.

  • Global counters Clients, total projects, projects for the current year
  • Vulnerability distribution by severity Critical, High, Medium, Low, Informational: across all projects and for the current year
  • Breakdown by project type Web, infrastructure, mobile, API and so on
  • Breakdown by client sector Overall view and current year
  • Annual chart Number of projects per calendar year since records began
  • Active / completed projects Separate counters
  • Upcoming projects The 5 active projects with the nearest end date, with client, status and dates
  • Recently completed projects The 5 most recent
  • Revenue (administrators only): total and yearly breakdown; calculated automatically from hours, days, hourly rate or fixed price
  • Automatic scoping by role Administrators see everything; auditors and project managers see only their assigned projects
02

Project management

The central workspace for every pentest engagement

Runs the full lifecycle of a pentest engagement, from the initial request to final delivery, with team assignment, scheduling and role-based access control.

  • Full CRUD Create, read, update and delete, with archiving semantics
  • Rich metadata Client, name, type, status, dates, budgeted days, hours worked, hourly rate, total price, language, custom fields
  • Multiple assignees One lead auditor and an unlimited list of additional assignees, with role-scoped visibility
  • Project managers Assigned independently, one or several per project
  • Workflow statuses Request, Scheduled, In progress, In review, Completed, Cancelled
  • Clone as retest Full copy with every unfixed vulnerability marked “To retest”, infrastructure copied, port checkboxes reset
  • Clone as version Full copy with a version suffix
  • Attachments Upload arbitrary files (documents, screenshots, archives) to any project
  • Schedule protection Moving dates is restricted to users holding the calendar.move permission
  • Automatic switch to Completed When an invoice is issued
  • Client portal Project managers with a client account see only their organisation’s projects
  • Team group scoping Managers see only the projects belonging to their groups
03

Audit rounds

Numbered phases within a single project

Splits a project into independent, numbered audit rounds so you can plan and report phased assessments or periodic retests without creating a new project.

  • Unlimited rounds Per project: name, dates, assigned auditor, status, notes
  • Automatic numbering Sequential
  • Retest round Clones every unfixed vulnerability from the previous round, preserves host-to-vulnerability links, resets infrastructure checkboxes
  • Recurring retests Creating a retest round automatically advances the project’s next retest date by the configured interval
  • Deduplication A vulnerability already cloned in an earlier round is not duplicated again when rounds are chained
  • Filtering by round In reports and exports
  • Date protection Same as projects (calendar.move permission)
04

Vulnerability management

Full tracking of every finding, with scoring, classification and evidence

Records, classifies and qualifies every security finding within a project, with CVSS scoring, OWASP/CWE classification and fully multilingual content.

  • CRUD per project With an optional link to a round
  • States Draft, Confirmed, Fixed
  • Retest status To retest, Fixed, Not fixed, Partially fixed
  • CVSS 3.1 and CVSS 4.0 Vector and numeric score both stored; reports prefer CVSS 4.0 when available
  • Auto-calculated severity Derived from the CVSS score: Critical, High, Medium, Low, Informational
  • OWASP Top 10 Web 2021 and API Security Top 10 2023 Classified by category code
  • CWE Common Weakness Enumeration, recorded per finding
  • Multilingual content Title, short description, description, impact, evidence, recommendation, short recommendation and notes: each held as a per-language dictionary (FR, EN, DE, ES, IT)
  • Affected component A specific URL, parameter, host or service
  • Rich formatting Bold, italic, underline, highlight, inline code, lists, image references
  • References Links to CVEs, advisories and vendor documentation
  • Links to infrastructure hosts Every finding can point at the affected hosts in the inventory
  • Independent copy from VulnDB Changes to the master library do not propagate back into existing projects
05

Vulnerability database (VulnDB)

A firm-wide library of reusable templates

A central library of vulnerability templates that auditors browse and import into any project, without retyping boilerplate content.

  • Full CRUD On master entries
  • Same multilingual structure As project vulnerabilities
  • CVSS 3.1, CVSS 4.0, OWASP and CWE Same classification as project vulnerabilities
  • One-click import Into the current project: content deep-copied instantly
  • Institutional knowledge base That grows with every engagement
06

Infrastructure mapping

Host and port inventory with nmap import

Maintains the host-and-port inventory of each project, giving a structured view of the attack surface that feeds reports and links to findings.

  • Manual host creation IP address, hostname optional
  • Port management TCP/UDP, number, state (open/filtered/closed), detected service and version
  • Nmap XML import Merged with deduplication; existing hosts are updated, not duplicated
  • Verification checkbox per port Reset automatically on retest rounds
  • Notes per port Observations that do not warrant a full finding
  • Host-to-vulnerability links Reports state exactly which hosts each finding affects
  • Infrastructure carried over automatically To retest and version projects

Artificial intelligence 3 modules

07

AI assistant

Context-aware chat with full project awareness Paid only

An embedded AI chat that knows the current project in real time: its vulnerabilities, infrastructure, attachments and relevant VulnDB entries: so you can draft, analyse and get advice in plain language.

  • Per-project conversations Full history persisted across sessions
  • Attachments in chat PDF, Word, Excel, plain text, Markdown, CSV, JSON, XML, YAML, images
  • Built-in OCR Images and screenshots processed by Tesseract (EN, FR, DE, ES, IT)
  • Automatic context injection The whole project, every vulnerability with its CVSS/OWASP/CWE, the infrastructure, relevant VulnDB entries and text extracted from files
  • Intent detection Adaptive routing based on the type of question (OWASP, a specific vulnerability, methodology, tool execution)
  • Content translation Translates title, descriptions, impact and recommendation while preserving rich formatting
  • Vulnerability draft generation A complete draft (title, description, severity, OWASP, CWE, recommendation) from a one-line description
  • Audit plan Generates a structured plan from the project scope and description
  • Result analysis Classifies findings from raw tool output and assigns OWASP and CWE
  • OWASP and CWE mandatory The system prompt makes them non-negotiable on every finding
  • Multiple providers Ollama (local) or any OpenAI-compatible endpoint
  • Standalone mode General AI conversations, independent of any project
  • Files validated by magic bytes, not by extension alone, to prevent type-confusion attacks.
08

AI auto-audit

An automated audit engine that runs real tools and imports the findings Paid only

A fully automated audit engine: the AI selects, configures and runs genuine pentest tools against a target, analyses the results, and imports the findings straight into the project.

  • Built-in audit templates Network reconnaissance (nmap), directory enumeration (ffuf), SSL/TLS analysis, HTTP headers, CORS, JWT, SQL injection (sqlmap), OS command injection, path traversal, IDOR, privilege escalation
  • Custom templates Team edition: create, edit and delete playbooks with named variables ({TARGET}, {PORT} and so on) and categories
  • Variable substitution The AI or the user fills in the variables; the runner substitutes them at execution time
  • Isolated container runner Execution inside a dedicated Docker container, cut off from the network, holding only the required tools (nmap, ffuf, sqlmap, curl, openssl, dirb, python3)
  • Session lifecycle Plan_ready (awaiting variables) → running → completed / failed
  • Result import The AI parses the raw output and produces structured vulnerability records, imported into the project
  • Notifications Alerts when the plan is ready for variables, and when a session finishes with results
  • The runner is reachable only from the internal Docker network: unreachable from the host or from the internet.
20

AI configuration

Connecting and tuning the AI provider Paid only

Lets administrators connect and tune the AI provider that powers the assistant and the auto-audit, without restarting the application.

  • Two independent AI profiles General assistant and auto-audit (they can point at different models)
  • Providers Ollama (local models) or any OpenAI-compatible endpoint
  • Full configuration Endpoint, model name, API key, temperature, max tokens
  • Live test Sends a test prompt and returns latency, the model response and any error, without saving
  • Ollama model listing Retrieves the models available locally

Reporting & export 5 modules

09

PDF reports

Professional, branded reports rendered by headless Chromium

Produces professional, fully branded PDF pentest reports from any project, using customisable HTML/Jinja2 templates rendered by a headless Chromium browser.

  • Jinja2 templates Editable without rebuilding the Docker image
  • Firm logo and client logo Embedded as base64
  • Multilingual content Vulnerability text in the project language; captions (figures, tables, appendices) translated automatically
  • Rich formatting Internal markup converted to styled HTML for rendering
  • CVSS 3.1 and 4.0 scores With their vectors, available in the template
  • Infrastructure section Hosts and open ports as a table
  • Filtering by round Report scoped to a specific round
  • Data available in the template The whole project, client, contacts, every vulnerability, infrastructure, company, internal contact and executive summary
  • Playwright/Chromium Full CSS rendering, severity-coloured tables, charts
10

Word reports (DOCX)

Editable documents for clients who annotate

Produces editable Word documents from the same project data, for clients who need to annotate or reformat the report.

  • .docx templates Using docxtpl syntax: the same library as PDF
  • Native Word formatting Bold, italic, underline, highlight and inline code converted into Word XML runs
  • Hyperlinks URLs converted into genuine Word hyperlinks
  • Multilingual figure numbering Correct in every language
  • Embedded logos As Word images
  • Same data As the PDF rendering
11

Export formats

Six formats for ingestion by other tools

Exports project data in six structured formats, for integration with other tools, tracking spreadsheets, SIEMs or archiving.

  • Excel (XLSX) Multi-sheet workbook (project, vulnerabilities, infrastructure, invoicing); auto-sized columns; supports custom Excel templates
  • JSON Complete project data serialised, optionally pretty-printed; ideal for programmatic integrations
  • XML Same content as JSON; compatible with SIEM, GRC and custom processors
  • SQLite A portable database with one table per entity type (project, vulnerabilities, hosts, ports); queryable offline with any SQL client
  • Markdown Project and vulnerabilities as Markdown, for wikis, issue trackers and Git documentation
  • HTML Self-contained rendering for web delivery or archiving without a PDF reader
  • Every format shares the same context-building layer as PDF and Word.
12

Invoicing & quotes

Multi-format invoice generation from project data

Generates invoices for completed engagements and keeps the billing history inside the platform, in six formats from a single action.

  • Six invoice formats Word, Excel, HTML, PDF, JSON, XML
  • Automatic sequential numbering Reset each year
  • VAT calculation Configurable rate, amounts shown excluding and including tax
  • Stored in the database Invoice number, date, total, link to the project
  • Project switches to Completed automatically When the invoice is issued
  • Customisable templates (.docx and .xlsx) in the same directory as the reports
  • Financial data Taken from the project; the hourly rate defaults to the client’s when not specified
21

Template management

Fully customisable reports and invoices

Manages the Word and Excel templates used to generate reports and invoices: editable on the fly, with no image rebuild.

  • Upload .docx and .xlsx templates Your own
  • Download Existing templates, for offline editing
  • Deletion Of templates
  • Sample catalogue A library of downloadable starter templates
  • Volume-mounted Updates without rebuilding any Docker image

Administration 9 modules

13

Clients & contacts

A CRM directory of every pentest client

Maintains a CRM directory of every client, with contacts, billing rates and logos: used across reports and invoices.

  • Client CRUD Name, address, sector, VAT number, hourly rate, company registration number, custom fields
  • Client logo Upload and management; appears in generated reports
  • Multiple contacts per client Name, email, phone, role; used as recipients for invoices and reports
  • Default contact and default project manager Per client
  • Autonomous auditors option A setting that lets auditors create and edit clients without admin rights
  • Cascading deletion Of contacts; projects are not deleted
14

User management

Full account administration with roles and groups Paid only

Full administration of every user account on the platform, with role assignment, group membership and company affiliation.

  • Creating, editing, deactivating Accounts
  • Role assignment One named role per user, governing every permission
  • Complete profile First name, last name, email, phone, daily hours (used for revenue calculation)
  • Company and group affiliation
  • Client portal users Project_manager role with managed_customer_id for restricted client access
  • Last-admin protection The last admin account can be neither deleted nor demoted
  • Password reset By admins; self-service change by the user (8 characters minimum)
  • Preferred language Per user: controls the interface language
15

User profile

Self-service account management and a personal API key

Every user manages their own profile, generates their API key and reviews their permissions without going through an admin.

  • Profile editing Name, email, phone, daily hours
  • Password change With verification of the current password
  • Personal API key Generation and rotation for programmatic access; creation date and last-used timestamp
  • Terms acceptance Timestamp recorded on the account
  • Resolved permissions The profile response includes the role name, the complete permission set, and the logo and name of the associated organisation
16

Roles & permissions (RBAC)

Granular, fully customisable access control Paid only

A fully customisable RBAC system in which every feature of the application can be protected by named permissions.

  • Named roles with permission sets A key → boolean dictionary
  • Granular permissions Customers, projects, vulnerabilities, calendar, reports, billing, groups, users, settings, license: each with a read/write distinction
  • Reader/writer distinction For every entity type
  • System role protection Built-in roles cannot be deleted
  • Permission audit Lists every role with its complete permission set
  • Enforced on every API endpoint On every API call
17

Team groups

Scoped visibility for managers, without admin rights Paid only

Organises users into named groups so managers get scoped visibility over projects and users without admin access.

  • Groups with a name, description and machine key
  • Assigning and removing members
  • Scoped visibility Managers only see the groups they belong to
  • Protection A manager cannot add admins or other managers to their groups
  • Projects tagged by group For manager visibility
  • Round assignment Restricted to auditors in the same group
  • Requires a multi-user licence: unavailable in single-user free mode.
18

Company management

Firm branding and affiliated entities

Manages internal company entities (the pentest firm and its affiliates) whose branding and details appear on reports and invoices.

  • Company CRUD Name, address, legal identifiers, phone, email, website, custom fields
  • Company logo Upload with secure storage; visible in report headers
  • Multiple entities Several internal entities (sub-brands, partners), each with its own branding
  • User affiliation The user profile automatically shows the right logo and the right name
19

Application settings

A central admin console for adapting the platform

An admin console that adapts the platform to the firm’s specific workflows and languages, with no code changes.

  • Report languages Enable or disable EN, FR, DE, ES, IT; set the default language
  • Vulnerability types A customisable list (web, network, mobile, API, and so on)
  • Business sectors The list of sectors used for clients and analytics
  • OWASP categories OWASP Top 10 Web and API Security: enablement and labels per language
  • Custom fields Extra fields on project, client or vulnerability forms, with no code changes
  • Behavioural options Whether auditors may manage clients, the “In Review” alert delay, and more
  • Session TTL How long a session may stay idle before re-authentication
22

Project chat & notifications

Internal messaging and a unified notification centre

A per-project message thread for team coordination, plus a notification centre aggregating every project event in real time.

  • Per-project message thread Visible to everyone assigned; admins see every project
  • Persistent history Sorted chronologically, with the author’s name and email
  • Read tracking Unread message counters per project
  • Notification bell Aggregates every unread alert
  • Unread messages from other users
  • New project requests with no auditor assigned
  • Active projects with no auditor
  • Projects starting within 3 days
  • Projects left “In review” for too long
  • Auto-audit sessions ready for variables
  • Auto-audit sessions finished with results
  • Mark all as read And marking by project or by type
26

Reader accounts

Read-only access scoped by group and project Paid only

Read-only accounts access projects based on their assigned groups and consult the results, with no edit rights whatsoever.

  • Read-only role No writes: no creation, editing or deletion
  • Group-scoped access A reader only sees the projects of the groups assigned to them
  • Results consultation Vulnerabilities, infrastructure, reports and dashboards of the authorised projects
  • Ideal for stakeholders Clients, managers or external auditors who follow progress without intervening
  • Enterprise edition Reader accounts are available from the Enterprise edition

Platform 3 modules

23

Authentication & security

Secure sessions, brute-force protection, API keys

Handles authentication and protects against common attacks: secure cookies, session rotation and brute-force blocking.

  • Secure session cookies Hardened against session theft
  • Session rotation Each sign-in ends the sessions open on other devices
  • Inactivity timeout Configurable, with a reminder popup 2 min before automatic sign-out
  • Personal API keys For integrations and automation
  • Brute-force protection Automatic blocking of brute-force attacks
  • Timing-attack protection Following security best practices
  • Strongly hashed passwords With transparent migration of existing accounts
  • Configurable CORS policy Allowed origins defined by the administrator
  • Free-mode restriction Only the admin account signs in without a multi-user licence
24

Licence management

RSA-signed files, editions and feature flags

Controls which features and how many users the platform allows, through RSA-signed licence files verified at startup.

  • RSA signature Verified against a trusted public key
  • Licence fields Edition (free, professional, team), client, expiry date, feature flags
  • Editions Govern multi-user access, groups, custom templates and other features
  • Default free licence App-default.lic, active automatically when no licence is present
  • Hot update Upload a new licence through the UI, with no restart
  • Summary and feature flags Exposed to frontend endpoints for conditional feature display
25

Deployment

A 4-service architecture, installed with one command

Packages the complete platform for one-command deployment on any Docker host, Windows or Linux/macOS.

  • 4-service Docker Compose architecture Db (PostgreSQL 17), backend (FastAPI), frontend (React/Nginx), runner (isolated executor)
  • Runner toolset Nmap, ffuf, sqlmap, curl, openssl, dirb, python3
  • Automatic secret generation Setup.ps1 (Windows) and setup.sh (Linux/macOS) create every secret and start Compose
  • Volumes for operational data Templates, AI uploads, logos, licence: decoupled from the images so updates need no rebuild
  • HTTPS by default Handled by the reverse proxy
  • Cross-platform A single command on Windows and on Linux/macOS
  • Development mode Backend through uvicorn, frontend through the Vite dev server

All of it, on your own infrastructure.

One install command, your infrastructure, your data. Solo Free activates with no licence to configure.