The Platform

The Whole Engagement, from First Scope to Final Retest.

The engagement is the product: scoping, phases, findings, evidence, QA, the report, the retest. Every field, section and prompt is yours to define, and the document round-trips back into the assessment when you edit it in Word.

ReportsEditable built-in PDFs alongside fully custom Word templates, with any edits you make reflected back in the portal.
Your fieldsRename any finding field or add your own, each with its own AI prompt in your voice.
Your sectionsDecide what the report contains, section by section, and the prompt behind each one.
Your databaseEvidence, files and reports stored without a limit, because the database is yours.
Setting It Up

Scoping the Client Fills In, Phases the Team Can See.

Scope requests go to the client through their portal, so the answers arrive structured instead of scattered across an email thread. From there the engagement is phased, scheduled and assigned in one view.

  • Structured scopingAsk for targets, credentials, environments and constraints once, in a form the client completes in their own portal. It lands attached to the engagement, not in a mailbox.
  • Phased engagementsExternal, internal, retest, or whatever shape the work takes. Each phase carries its own dates, testers and checklist, under one engagement and one report.
  • Assignment and statusTesters are assigned per phase, and assessments can start and complete themselves on their scheduled dates rather than waiting for someone to remember to move them.
  • Client credentials, collected safelyAsk the client to submit access credentials before the start date and they arrive encrypted, one-time view, attached to the engagement rather than sitting in an email thread.
  • Your testing source addressesKeep your public testing IPs on file and they appear on your reports automatically, so the client has what they need for whitelisting without a separate email.
  • Access scoped to the workPeople see the engagements they are on. Roles by seniority decide the rest, enforced in the database rather than by hiding buttons.
The Work Itself

Paste the Evidence. Get the Finding.

Writing up a finding is the part of the job that is unavoidable, repetitive, and the same twelve vulnerabilities every quarter in slightly different words. Drop your evidence in and one button drafts the rest of it.

Generate All from Evidence

Not a field at a time. One action reads the evidence you captured and fills in everything the finding needs, in order, skipping anything you have already written.

  1. 01The title, derived from the evidence if you have not written one, so everything downstream has something to anchor to.
  2. 02A library match, if your firm has written this weakness up before. Your house wording arrives first, and the model works around it rather than over it.
  3. 03Description and remediation, in your voice, from the evidence rather than from a generic template.
  4. 04CVSS, with the vector worked out from what the evidence actually shows rather than typed from memory.
  5. 05CWE and category, classified from the finding as written.
  6. 06Affected assets, pulled from what the evidence names.
  7. 07Your custom fields, each one using the prompt you wrote for it.
  8. 08References last, because they draw on the title, category, CWE and description that now exist.
Why the Order Matters

Each step is written to use what the previous ones produced, which is why the output hangs together rather than reading as eight unrelated paragraphs. Anything already filled in is left alone, so running it on a half-written finding completes it instead of overwriting your work.

Everything Is Still Yours to Change

Writing
Per Field
Every field has its own generate button as well, so you can redo one thing without touching the rest.
Editors
Rich text with evidence blocks, images, tables and code, and clean paste from Word that keeps your formatting instead of shredding it.
Your Prompts
Each generated field uses a prompt you can read and rewrite in settings, with a reset to the shipped default. Nothing is hidden.
Your Key
All of it runs on your own provider key or a model on your own hardware. Nothing is proxied through Pental.
Scoring and Structure
CVSS
The vector is worked out as you toggle metrics, so the score and the string can never disagree with each other.
Severity
Your own labels and colours, carried from the editor to the client portal to the rendered document.
Custom Fields
Add the fields your methodology carries, likelihood, business risk, whatever it is, each with its own control type and its own prompt.
Phases
A finding belongs to the phase it came from, so the same weakness found externally and internally stays two findings with different exposure.
Downstream
Release
Findings reach the client when you release them, not when you save them.
Retests
A retest carries the original findings and tracks what is fixed, what is still open and what is new, so it is a delta rather than a rewrite.
History
Every change is on the engagement timeline: who wrote, who edited, who reviewed, who released.
A findings table with the severity scale repainted in the firm’s own colours.
Thornbury CyberTheir teamDemonstration portals. The four firms are invented; every screen is the real software.
Compounding

A Library That Stops You Writing SQL Injection for the Hundredth Time.

The best description of a vulnerability your firm will ever write should be written once. Save any finding to the library, insert it into the next engagement with its scoring and remediation intact, and adjust the specifics. Your house wording stays your house wording, and it gets better every time someone improves it.

Where It Lives

The library is a set of tables in your own database, like everything else. It is your firm's accumulated judgement, so it sits on your side of the trust boundary, exportable whenever you like.

Before It Ships

QA as a Workflow, Not a Favour.

Work moves through review states with comments attached to the thing being reviewed. Nothing reaches a client because someone forgot it had not been checked.

  • Review statesDraft, in review, approved. Who reviewed what is on the record, and release waits for approval.
  • Comments in placeFeedback lands on the finding or the section it concerns, not in a side channel that evaporates.
Coverage You Can Show

Checklists and Runbooks, Attached to the Phase They Belong To.

Methodology usually lives in a document nobody opens and in the heads of whoever has been there longest. Here it is a set of templates you write once and attach to the phases you run, so what was covered is a record rather than a recollection.

Two Kinds
Checklist
The things that must be covered. Items are ticked off as the work happens, and the phase shows how much of it is done.
Runbook
The steps for doing something the way your firm does it. Same structure, ordered as a procedure, so the how travels with the what.
How They Attach
Per Phase
Attached to the phase, not the engagement, so an internal phase and a web phase each carry their own.
Suggested
Give a template a phase hint and it is offered first whenever you add a phase of that type.
Reusable
Written once in settings and reused across every engagement, so improving one improves all of them.
  • Progress is visibleEach attached template shows what has been ticked and what is left, on the phase, while the work is happening rather than in a retrospective.
  • Share it, or do notMark a template client-visible and it appears in their portal, so a client who wants to see your methodology can. Everything else stays internal.
  • Your standards, not a presetEvery template is yours to write, name and order. Nothing is imported from a framework you do not follow.
  • The question it answersWhen a client or their auditor asks what was actually tested, the answer is attached to the engagement rather than reconstructed from memory.
The Deliverable

Two Ways to Produce a Document. Both of Them Yours.

Start with the built-in PDF, generated from your branding with no Word skills needed. Move to a fully custom Word template whenever you want, and the platform fills it in. Mix them freely: a custom report template and the built-in attestation letter is a perfectly normal setup.

Rendering
Deterministic
The same engagement produces the same file, byte for byte. When a client puts this quarter next to last quarter, the only differences are the findings.
Custom Word
Your own DOCX with your cover page, headers, fonts, tables and appendices exactly as you built them. The platform fills your document, it does not impose one.
Built-In PDF
Editable from your branding: fonts, logo variant, colours and layout options, with nothing to upload and no Word skills needed.
Filenames
Generated files follow your own naming convention, so what lands in the client's inbox already matches their filing and your archive.
Summaries
Executive and retest summaries are drafted from the findings actually in the assessment, then edited by a human before anything ships.
Types
Report
The full assessment deliverable, findings, evidence and summaries in your format.
Attestation
The letter your client's auditor asks for, without a morning lost to it.

Edit It in Word, and the Portal Follows

Everyone generates a document. The problem starts afterwards: the report gets edited in Word, delivered, and the platform is out of step with what the client actually received. Pental reads the edited document back in.

  1. 01Generate from your template. Every value the generator writes is marked in place as it goes, invisibly, so the document knows what it is made of.
  2. 02Edit it in Word like any other document: rewrite prose, restyle it, move screenshots, add or drop findings.
  3. 03Upload it back. The platform shows you, item by item, exactly what differs between the document and the assessment.
  4. 04Tick what you want applied. Nothing is written that was not shown to you first, and nothing is deleted unless you ask for it.
  • The whole findingTitle, severity, CVSS and vector, affected hosts, references, description, remediation, evidence with its screenshots, and every custom field you have defined, each matched by its own marker rather than by guessing at titles.
  • Formatting countsHeadings, bold, lists, code blocks, links, alignment, table shading and captions come back as they are in the document, including formatting Word holds on a style rather than on the text itself.
  • Phases preservedA multi-phase report puts each finding back under the phase it belongs to, resolved against the phases your assessment actually has.
  • It creates what is missingA finding in the document that is not yet in the assessment can be created from it, with its fields and screenshots. An existing one is updated, never duplicated.
  • Deleting is deliberateEmpty an area in Word and it offers to clear it. A finding the document no longer carries gets an explicit keep-or-delete choice, never a checkbox that could be misread.
  • The delivered file, keptUpload the final signed-off PDF against the assessment so the artefact the client received and the working copy behind it live in the same place.

How templates are mapped, and how the AI drafts within them, is covered on the AI page

Your Methodology, Not Ours

The Report's Shape Is a Setting, Not a Constraint.

Two firms testing the same application produce different documents, because they work differently. The parts of the platform that decide what a report contains are yours to configure.

  • Custom assessment sectionsDefine the sections your report carries, reorder them, switch off the ones you do not use, and add your own, each with its own AI prompt so it is written the way your firm writes it.
  • Custom finding fieldsAdd your own fields to a finding, choose the control each one uses, and give every field its own AI prompt. Likelihood, business risk, whatever your methodology carries.
  • A prompt for everythingEvery generated field and every section has its own editable prompt, used verbatim, with a reset to the shipped default. There is no hidden prompt anywhere in the product.
  • Severity, your paletteYour own labels and colours for critical through informational, applied consistently from the editor to the client portal to the rendered document.
  • Assessment typesSet the engagement types your firm actually sells, so a phase is labelled the way your own reports describe it.

Everything above is on every plan, including the one with the free trial on it.

The Client Side

A Portal Your Clients Sign into, Wearing Your Brand.

Clients get standing accounts on your domain, locked to their own organisation. Between engagements it is where their whole history with you lives: every report you have ever released, the findings and their current state, the attestation letters their auditors ask for. During an engagement it is where they scope, follow progress and receive findings. All of it under your brand.

  • A standing record, not a one-offEvery engagement you have run for that client stays available to them: reports, findings, retest outcomes and attestation letters, in one place they can return to a year later without emailing you for a copy.
  • Their view, your controlA client sees its own record, its own assessments and only the findings you have released. That boundary is enforced in the database, not by hiding buttons.
  • The reason they come backWhen their auditor asks for last year's report, or a customer asks for evidence of testing, it is already there under your name. That is a renewal conversation you did not have to start.
  • Comments in contextQuestions about a finding are raised against that finding, so the context comes attached rather than arriving as a separate email thread.
  • Retest requestsThe client can ask for the retest from the report they are reading, which becomes a scoped phase on your side.
  • Feedback that compoundsStructured feedback at the end of an engagement, with a nudge towards a Google review when it is glowing.
Day to Day

The Parts You Feel Every Day.

  • One timelineEvery engagement keeps a full activity trail: scope answered, phase started, finding written, review signed off, report released, retest requested. When a client asks what happened and when, the answer is on screen.
  • Dashboards and notificationsWhat is in flight, what is blocked, what is due. Notifications go where your team lives, including Slack and Teams.
  • Modules you can switch offNot using the library, the testing calendar, feedback or the dashboards? Turn the module off and it leaves the interface entirely, for your team and your clients.
  • Sign-in your policy will likeEmail and password by default with a mandatory second factor, passkeys and authenticator apps, Google and Microsoft SSO, or emailed one-time codes if you prefer passwordless. The detail lives on the security page.
  • Storage without a meterEvidence, files and reports live inside your own database, with no storage tier to outgrow. Unlimited on every plan, because it is your database.
  • Full backup and restoreExport the whole portal as one archive: clients, assessments, findings, the library, users, settings and branding, plus every uploaded file. Restore it into a fresh project if you ever need to.
  • Notifications you chooseEach event has its own switch, from a critical finding raised to a report released to a new device signing in, so the platform is as loud or as quiet as your team wants.

Run One Engagement Through It.

The trial is the full platform, on whichever plan fits. The setup guide records every step, ten of them creating the database. Seven days, no card, and whatever you decide, the database stays yours.