Your Security.
Complete Visibility.

Every Nanorisk engagement is managed through the Security Portal — the central hub for engagement management, communication, and reporting. From scoping through to delivery and beyond, everything is accessible, documented, and auditable in one secure platform, eliminating the need for sensitive information to be exchanged over email. The portal is included with every engagement at no additional cost.

Included
With Every Engagement
Real-Time
Findings & Reports
Secure
Encrypted Communication
2FA
Authentication
Nanorisk Security Portal

Your Security Posture at a Glance

When you log in, the Overview Dashboard provides an immediate, consolidated view of your organisation's security position across all active Nanorisk services — including your security score, module status, risk heatmap, threat intelligence, and activity timeline.

portal.nanorisk.co.uk
Nanorisk Security Portal - Client Overview Dashboard

Know What You Have. Know What's at Risk.

The Asset Management module maintains a full inventory of your digital assets — the servers, applications, APIs, cloud services, and infrastructure that form the scope of your assessments. Every vulnerability and finding is linked directly to the affected asset.

portal.nanorisk.co.uk/assets
Asset Map Asset List Asset Detail Asset Vulnerabilities

End-to-End Engagement Management

Every penetration testing engagement is managed through the portal from initial scoping through to final delivery. Track progress, review documents, access findings, and communicate securely — all from a single project view.

portal.nanorisk.co.uk/pentesting
Project Overview Vulnerability Scores Project Metrics Project Roadmap

We provide a step-by-step roadmap for each penetration testing project so you can see at any time what stage you're at and what's coming next. The portal tracks progress through each phase — from scoping and authorisation through to delivery and retesting.

Digital Signing. Secure Documents.

The authorisation form and quote are provided both on the portal and as a downloadable document. All signing is completed digitally via the portal unless otherwise requested — no printing, scanning, or emailing sensitive contracts.

portal.nanorisk.co.uk/pentesting/authorisation
Digital Authorisation Form and Quote

Track Every Finding. Manage Every Fix.

All findings are viewable in real time on the portal. Each finding includes severity classification, CVSS scoring, affected assets, evidence, remediation guidance, and effort estimation.

How severity is decided

Every finding is rated on three factors together, rather than an automated score alone: technical impact, likelihood of exploitation in your environment, and the CVSS v4.0 Base Score. Impact and likelihood are each rated High, Medium or Low.

CVSS v4.0 bands

Critical 9.0–10.0, High 7.0–8.9, Medium 4.0–6.9, Low 0.1–3.9, Informational 0.0. Threat and environmental metrics tailor the score to your infrastructure rather than leaving it generic.

Mapped and consistent

Every finding is mapped to the Common Weakness Enumeration (CWE). Ratings are applied consistently across consultants and engagements, supported by our maintained findings library.

portal.nanorisk.co.uk/pentesting/findings
Live Findings View Vulnerability Detail

Reports & Attestation

All reporting is viewable directly within the portal, with the option to download as PDF or Word, and every assessment comes with more than just the report.

portal.nanorisk.co.uk/pentesting/delivery
Report Delivery

Assessment Reports

Executive summary, technical findings with evidence, CVSS scores, remediation guidance and threat intelligence, accessible in the portal or downloadable as PDF or Word.

Retesting Reports

Following remediation, retesting validates that fixes are effective. Outcomes are delivered as a separate report through the portal.

Attestation Letters

Formal letters of attestation for every assessment, as PDF or Word, supporting your compliance and governance requirements.

Free OSINT Report

An Open-Source Intelligence Gathering report on your organisation’s public exposure, included at no additional cost, alongside a threat intelligence report.

Spreadsheet Export

Generate a spreadsheet of your current findings at any point, during the assessment as well as after it, so remediation teams can start without waiting for the final report.

Post-Assessment Clean-Up

Every report confirms what was removed and reverted after testing, so nothing is left behind in your environment.

Five Retests, Included

Retesting of up to five findings of your choosing is included free of charge for up to 60 days after the assessment, along with a wash-up call. Where a finding is fixed while testing is still under way, you can mark it as client closed in the portal and we will retest it during the assessment. Retesting beyond the included five is chargeable, priced on the time required, and quoted before any work is booked.

Built for Security Professionals

The portal is designed with the same rigour applied to the assessments delivered through it.

Two-Factor Authentication

All accounts support TOTP-based 2FA with backup codes. Session management lets you view active sessions and terminate access from any device.

Role-Based Access

Granular access controls ensure each user sees only what they are authorised to see. Per-project permissions control access to sensitive documents.

Audit Trail

Comprehensive activity logging of all portal interactions supporting accountability, oversight, and compliance requirements.

Encrypted Communication

All sensitive information exchange happens through encrypted channels within the portal — never over email.

Controlled Documents

Secure storage and lifecycle management of all engagement documentation, NDAs, and artefacts with retention policy enforcement.

Session Security

View login history, active sessions with IP and device information, and terminate sessions remotely. Password strength enforcement and change tracking.

Get in Touch

If you would like to discuss an assessment or see how the Security Portal supports your organisation's security programme, please get in touch.