02 — BluVault
Run security assessments end to end. Report them without the busywork.
BluVault is a multi-tenant VAPT engagement-management platform — the system of record a pen-testing firm uses to run assessments for its clients, and the portal those clients and channel partners use to consume results.
What it does
Every stage of an engagement, in one platform
Intake to engagement
Prospects fill a requirement questionnaire; the firm runs a clarification loop, generates a proposal, and on acceptance it converts straight into an active client, engagement, and assessments.
Structured findings & evidence
Testers capture findings with CVSS severity, PoC evidence, impact and remediation, and import scanner exports, firewall rulesets, and CIS results through deterministic analyzers plus threat intel.
Maker-checker review
A per-finding review lifecycle with segregation of duties, return-for-changes, and a single sign-off gate before anything reaches a client.
Branded reporting
Generate PDF/DOCX/XLSX from a canonical report-template engine, then password-protect, watermark, and PAdES-seal it, and share it via an expiring tokenized link.
Trust certificates
Issue completion certificates clients and third parties can verify on a public, data-minimized page.
How it works
From intake to a signed, shareable report
01
Onboard & scope
Bring in a client org, its assets, and request assessments across web, mobile, API, network, cloud, red team, and more.
02
Assign & test
A security manager assigns testers via a per-assessment capability model; testers log findings and structured evidence as they go.
03
Review, publish, report
Findings pass maker-checker review, the assessment is published to the client, and a branded, sealed report goes out.
Built for
- Penetration-testing / security-consulting firms
- Their enterprise clients (CISO, InfoSec, asset teams)
- Channel partners reselling or referring engagements
Questions
Good to know
Who is BluVault for?
It's the system of record a pen-testing firm uses to run assessments for its clients, and the portal those clients and channel partners use to consume results — one multi-tenant platform covering every stage of an engagement.
How are reports delivered securely?
Reports are generated from a canonical template engine (PDF/DOCX/XLSX), then password-protected, watermarked, and PAdES-sealed before being shared through an expiring tokenized link. Completion certificates are verifiable by third parties on a public, data-minimized page.
What assessment types does it support?
Web, mobile, API, network, cloud, red team, and more — with testers assigned per assessment through a capability model, and scanner exports, firewall rulesets, and CIS results imported through deterministic analyzers enriched with threat intel.