Re-derives on every open
Findings resolved, retests verified, anything reopened since — all computed when the page loads. There is no cached verdict to go stale.
Platform capability
Your customer asks for proof you were tested. The industry answer is a PDF. It states what was true on the day it was generated, and it keeps stating that forever — through reopened findings, failed retests and regressions it has no way of knowing about.
Nothing, on the day it is issued. A penetration test certificate records that an assessment happened, over an agreed scope, and where remediation stood. All of that is true at the moment of generation, and it converts well — it is the single most requested artefact at the end of an engagement.
The problem starts the next week. A finding gets reopened. A retest fails. A fix regresses during a release. The remediation position described in the document is now wrong, and the document has no way of knowing — so it keeps making the same claim, under your name, to whoever you sent it to. Six months later somebody forwards it to a prospect as current evidence.
So we made the certificate a URL instead of a file. The row in our database records only what was fixed — which assessment, who issued it, over what scope, on what date. Everything it says about remediation is computed at the moment somebody opens the link. The same link that proved a clean result in March shows an honest picture in November.
Coverage
Designed around one rule: store what was fixed, derive what is current.
Findings resolved, retests verified, anything reopened since — all computed when the page loads. There is no cached verdict to go stale.
The page carries the timestamp of the check it just performed, so a reader knows exactly how current the statement is.
It states the organisation, the assessment type, the scope you wrote, and where remediation stands as a band. It never publishes a finding title, a target, or a count by severity — that would be a shopping list under your own brand.
If something was closed and came back, the certificate says so. This is exactly the case a static document cannot represent, and it is the reason the whole thing is a URL.
Revoke it and the link keeps working — it tells the reader it was withdrawn and when. A dead page looks like a mistake; a withdrawal notice is information.
The page says plainly that it is not a certification, that it covers the agreed scope only, and that no absence of vulnerabilities is claimed. A certificate that overstates itself is worth nothing the first time somebody checks it.
Twenty characters, grouped in fours, with the easily-misread characters left out — because people read these aloud and type them into address bars.
Approach
Issued from the assessment, shared as a link.
Certificates are only issued for assessments that finished. One for a scan that failed or was cancelled would assert that testing happened when it did not.
Shown verbatim on the page. Anything outside it is explicitly stated as not covered.
Send it to the customer, the insurer, the procurement team. They can re-check it whenever they like.
As findings close and retests verify them, the page improves by itself. Nothing has to be re-issued.
Deliverables
The report is the product. If it cannot be acted on by a developer and understood by a director, we have not finished.
Shareable, re-checkable, and current every time it is opened.
How many times it has been opened, and when it was last looked at.
Revoke and republish at any time; already-shared links behave correctly either way.
On the page itself, so nobody has to ask what it does and does not mean.
Is this for you?
If none of them are, say so on the call and we will tell you honestly whether this is the right piece of work — or point you at the one that is.
Book a scoping callHow we work
The same engagement model applies to every piece of work we take on, so you always know what happens next.
A 30-minute call, then a written scope: what is in, what is out, what we need from you and what it costs. Nothing starts before you sign it.
Rules of engagement, testing windows, escalation contacts and a signed authorisation. Out-of-hours windows where production cannot take the load.
Automated coverage first, then manual testing where judgement is required. Critical findings are reported the day we confirm them, not at the end.
One report a developer can act on and an executive can read, with evidence, reproduction steps, business impact and a fix for every finding.
A walkthrough call with your engineers. We answer questions on the fix, not just the finding.
A free retest cycle to confirm the fixes hold, and a clean summary you can hand to a customer, auditor or board.
Questions
The questions clients actually ask during scoping. If yours is not here, ask it directly.
No, and the page says so in as many words. No standards body issues it and it is not equivalent to ISO 27001, SOC 2 or anything else. It records that an assessment was carried out, over a stated scope, and where remediation stands right now. Anybody selling you a "penetration testing certification" is selling something that does not exist.
It says what is true, which is the point. The bands run from "no findings identified" through "remediation in progress" to "findings outstanding", and each carries a plain-English explanation. In practice a certificate showing active remediation with a clear position reads considerably better to a security reviewer than a six-month-old PDF they cannot verify. You also control whether it is published at all.
No, and this is designed rather than assumed. The page receives a payload containing the organisation, the assessment type, the scope you wrote, dates and a remediation band — and nothing else. No finding title, no hostname, no count by severity. Our test suite asserts that boundary directly against the payload, not against the rendered page, because the next template is the one that gets it wrong.
Yes, at any time. The link keeps resolving and tells the reader the certificate was withdrawn and on what date, which is more useful to them than a dead page. You can republish it later and the original link works again.
Anybody with the link. The code is twenty random characters from a restricted alphabet — far beyond anything that could be enumerated — and the endpoint is rate-limited. It is unlisted rather than authenticated, because a certificate you have to log in to check is a certificate nobody checks.
Next step
A 30-minute call, then a scope document with what is in, what is out and what it costs. No obligation, and no charge for the conversation.