Your Security.
Complete Visibility.
Every Nanorisk engagement is managed through the Security Portal — the central hub for engagement management, communication, and reporting. From scoping through to delivery and beyond, everything is accessible, documented, and auditable in one secure platform, eliminating the need for sensitive information to be exchanged over email. The portal is included with every engagement at no additional cost.
Your Security Posture at a Glance
When you log in, the Overview Dashboard provides an immediate, consolidated view of your organisation's security position across all active Nanorisk services — including your security score, module status, risk heatmap, threat intelligence, and activity timeline.
Know What You Have. Know What's at Risk.
The Asset Management module maintains a full inventory of your digital assets — the servers, applications, APIs, cloud services, and infrastructure that form the scope of your assessments. Every vulnerability and finding is linked directly to the affected asset.
End-to-End Engagement Management
Every penetration testing engagement is managed through the portal from initial scoping through to final delivery. Track progress, review documents, access findings, and communicate securely — all from a single project view.
We provide a step-by-step roadmap for each penetration testing project so you can see at any time what stage you're at and what's coming next. The portal tracks progress through each phase — from scoping and authorisation through to delivery and retesting.
Digital Signing. Secure Documents.
The authorisation form and quote are provided both on the portal and as a downloadable document. All signing is completed digitally via the portal unless otherwise requested — no printing, scanning, or emailing sensitive contracts.
Track Every Finding. Manage Every Fix.
All findings are viewable in real time on the portal. Each finding includes severity classification, CVSS scoring, affected assets, evidence, remediation guidance, and effort estimation.
How severity is decided
Every finding is rated on three factors together, rather than an automated score alone: technical impact, likelihood of exploitation in your environment, and the CVSS v4.0 Base Score. Impact and likelihood are each rated High, Medium or Low.
CVSS v4.0 bands
Critical 9.0–10.0, High 7.0–8.9, Medium 4.0–6.9, Low 0.1–3.9, Informational 0.0. Threat and environmental metrics tailor the score to your infrastructure rather than leaving it generic.
Mapped and consistent
Every finding is mapped to the Common Weakness Enumeration (CWE). Ratings are applied consistently across consultants and engagements, supported by our maintained findings library.
Reports & Attestation
All reporting is viewable directly within the portal, with the option to download as PDF or Word, and every assessment comes with more than just the report.
Assessment Reports
Executive summary, technical findings with evidence, CVSS scores, remediation guidance and threat intelligence, accessible in the portal or downloadable as PDF or Word.
Retesting Reports
Following remediation, retesting validates that fixes are effective. Outcomes are delivered as a separate report through the portal.
Attestation Letters
Formal letters of attestation for every assessment, as PDF or Word, supporting your compliance and governance requirements.
Free OSINT Report
An Open-Source Intelligence Gathering report on your organisation’s public exposure, included at no additional cost, alongside a threat intelligence report.
Spreadsheet Export
Generate a spreadsheet of your current findings at any point, during the assessment as well as after it, so remediation teams can start without waiting for the final report.
Post-Assessment Clean-Up
Every report confirms what was removed and reverted after testing, so nothing is left behind in your environment.
Five Retests, Included
Retesting of up to five findings of your choosing is included free of charge for up to 60 days after the assessment, along with a wash-up call. Where a finding is fixed while testing is still under way, you can mark it as client closed in the portal and we will retest it during the assessment. Retesting beyond the included five is chargeable, priced on the time required, and quoted before any work is booked.
Built for Security Professionals
The portal is designed with the same rigour applied to the assessments delivered through it.
Two-Factor Authentication
All accounts support TOTP-based 2FA with backup codes. Session management lets you view active sessions and terminate access from any device.
Role-Based Access
Granular access controls ensure each user sees only what they are authorised to see. Per-project permissions control access to sensitive documents.
Audit Trail
Comprehensive activity logging of all portal interactions supporting accountability, oversight, and compliance requirements.
Encrypted Communication
All sensitive information exchange happens through encrypted channels within the portal — never over email.
Controlled Documents
Secure storage and lifecycle management of all engagement documentation, NDAs, and artefacts with retention policy enforcement.
Session Security
View login history, active sessions with IP and device information, and terminate sessions remotely. Password strength enforcement and change tracking.
Get in Touch
If you would like to discuss an assessment or see how the Security Portal supports your organisation's security programme, please get in touch.