Platform capability

A PDF cannot know that it stopped being true.

Your customer asks for proof you were tested. The industry answer is a PDF. It states what was true on the day it was generated, and it keeps stating that forever — through reopened findings, failed retests and regressions it has no way of knowing about.

LiveStatus derived on open
PublicA URL you can share
BandsNever a finding or a target
RevocableAnd it says so

What is actually wrong with the PDF

Nothing, on the day it is issued. A penetration test certificate records that an assessment happened, over an agreed scope, and where remediation stood. All of that is true at the moment of generation, and it converts well — it is the single most requested artefact at the end of an engagement.

The problem starts the next week. A finding gets reopened. A retest fails. A fix regresses during a release. The remediation position described in the document is now wrong, and the document has no way of knowing — so it keeps making the same claim, under your name, to whoever you sent it to. Six months later somebody forwards it to a prospect as current evidence.

So we made the certificate a URL instead of a file. The row in our database records only what was fixed — which assessment, who issued it, over what scope, on what date. Everything it says about remediation is computed at the moment somebody opens the link. The same link that proved a clean result in March shows an honest picture in November.

Coverage

What it does

Designed around one rule: store what was fixed, derive what is current.

Re-derives on every open

Findings resolved, retests verified, anything reopened since — all computed when the page loads. There is no cached verdict to go stale.

Says when it was checked

The page carries the timestamp of the check it just performed, so a reader knows exactly how current the statement is.

Publishes bands, never detail

It states the organisation, the assessment type, the scope you wrote, and where remediation stands as a band. It never publishes a finding title, a target, or a count by severity — that would be a shopping list under your own brand.

Discloses reopened findings

If something was closed and came back, the certificate says so. This is exactly the case a static document cannot represent, and it is the reason the whole thing is a URL.

Withdrawal that still resolves

Revoke it and the link keeps working — it tells the reader it was withdrawn and when. A dead page looks like a mistake; a withdrawal notice is information.

States its own limits

The page says plainly that it is not a certification, that it covers the agreed scope only, and that no absence of vulnerabilities is claimed. A certificate that overstates itself is worth nothing the first time somebody checks it.

A readable verification code

Twenty characters, grouped in fours, with the easily-misread characters left out — because people read these aloud and type them into address bars.

Approach

How you use it

Issued from the assessment, shared as a link.

  1. 01 · Complete an assessment

    Certificates are only issued for assessments that finished. One for a scan that failed or was cancelled would assert that testing happened when it did not.

  2. 02 · Write the scope in your own words

    Shown verbatim on the page. Anything outside it is explicitly stated as not covered.

  3. 03 · Issue and share the link

    Send it to the customer, the insurer, the procurement team. They can re-check it whenever they like.

  4. 04 · Carry on remediating

    As findings close and retests verify them, the page improves by itself. Nothing has to be re-issued.

Deliverables

What you actually receive.

The report is the product. If it cannot be acted on by a developer and understood by a director, we have not finished.

A public verification URL

Shareable, re-checkable, and current every time it is opened.

A view count

How many times it has been opened, and when it was last looked at.

Withdrawal control

Revoke and republish at any time; already-shared links behave correctly either way.

The honest limits, in writing

On the page itself, so nobody has to ask what it does and does not mean.

Is this for you?

Talk to us if any of these are true.

If none of them are, say so on the call and we will tell you honestly whether this is the right piece of work — or point you at the one that is.

Book a scoping call
  • A customer has asked for proof that you were tested.
  • You are sending out a pentest PDF from earlier this year and are not certain it is still accurate.
  • Your procurement questionnaire asks for evidence of recent testing.
  • You want the person receiving your evidence to be able to verify it rather than trust it.

How we work

Six steps, and no surprises.

The same engagement model applies to every piece of work we take on, so you always know what happens next.

01

Scope

A 30-minute call, then a written scope: what is in, what is out, what we need from you and what it costs. Nothing starts before you sign it.

02

Authorise

Rules of engagement, testing windows, escalation contacts and a signed authorisation. Out-of-hours windows where production cannot take the load.

03

Test

Automated coverage first, then manual testing where judgement is required. Critical findings are reported the day we confirm them, not at the end.

04

Report

One report a developer can act on and an executive can read, with evidence, reproduction steps, business impact and a fix for every finding.

05

Remediate

A walkthrough call with your engineers. We answer questions on the fix, not just the finding.

06

Retest

A free retest cycle to confirm the fixes hold, and a clean summary you can hand to a customer, auditor or board.

Questions

Assessment Certificate — answered.

The questions clients actually ask during scoping. If yours is not here, ask it directly.

Is this a certification?

No, and the page says so in as many words. No standards body issues it and it is not equivalent to ISO 27001, SOC 2 or anything else. It records that an assessment was carried out, over a stated scope, and where remediation stands right now. Anybody selling you a "penetration testing certification" is selling something that does not exist.

What if our remediation is not finished — does it make us look bad?

It says what is true, which is the point. The bands run from "no findings identified" through "remediation in progress" to "findings outstanding", and each carries a plain-English explanation. In practice a certificate showing active remediation with a clear position reads considerably better to a security reviewer than a six-month-old PDF they cannot verify. You also control whether it is published at all.

Does it expose anything an attacker could use?

No, and this is designed rather than assumed. The page receives a payload containing the organisation, the assessment type, the scope you wrote, dates and a remediation band — and nothing else. No finding title, no hostname, no count by severity. Our test suite asserts that boundary directly against the payload, not against the rendered page, because the next template is the one that gets it wrong.

Can we take it down?

Yes, at any time. The link keeps resolving and tells the reader the certificate was withdrawn and on what date, which is more useful to them than a dead page. You can republish it later and the original link works again.

Who can see it?

Anybody with the link. The code is twenty random characters from a restricted alphabet — far beyond anything that could be enumerated — and the endpoint is rate-limited. It is unlisted rather than authenticated, because a certificate you have to log in to check is a certificate nobody checks.

Next step

Get a written scope and a fixed price.

A 30-minute call, then a scope document with what is in, what is out and what it costs. No obligation, and no charge for the conversation.