COMMUNICATION OF RESULTS

Results That Reach the Right People,
at the Right Time, in the Right Place

AttackForge goes beyond static reports. Deliver real-time vulnerability intelligence through a branded portal, seamless enterprise integrations, and intelligent notifications - cutting Mean-Time-to-Remediate by an average of 47%.

A Branded Portal Experience Your Customers Will Love

Give your customers continuous visibility into their security posture - not just a report delivered at the end of an engagement.

Vulnerabilities in Real-Time, Not Weeks Later

Stop waiting for final reports. Customers see vulnerabilities the moment testers mark them as "visible" - complete with evidence, remediation guidance, and affected assets. Critical findings trigger immediate notifications so remediation can begin within hours, not weeks.

Visibility Toggle
Control exactly when customers see vulnerabilities
On-Demand Reports
DOCX, CSV, or JSON anytime
Custom ReportGen Templates
Tailor content, layout, and branding
Evidence Packages
Screenshots, videos, and attack logs
Deep Linking
Share URLs directly to specific vulnerabilities
Real-Time Vulnerability Feed
SQL Injection discovered2 hours ago
CriticalVisible to customer
XSS vulnerability found3 hours ago
HighRemediation started
Security misconfigurationToday
MediumIn review
✓ Immediate visibility • ✓ Same-day remediation • ✓ 95% faster response

Granular Access for Every Stakeholder

Five distinct user roles with configurable project privileges

Admin
Full platform control
Project Coordinator
Project management
Library Moderator
Vulnerability library
Consultant
Testing & reporting
Client
View findings only
SSO Integration
Group-Based Access
Audit Logging

Personalized Dashboards

Every user gets their own source of truth - no confusion, no overload.

Global Dashboard
Analytics Module
Trend Analysis
Custom Actions
Custom Table Views
Dark Mode Support

Your Brand, Your Portal

Complete white-label branding

AttackForge becomes invisible. Your clients see your logo, your colors, and your brand identity throughout the platform.

Custom Logo Upload
Replace branding across all interfaces
Custom Color Schemes
Primary, secondary, and accent colors
Branded Email Templates
Your styling on all notifications
Custom Report Templates
Use your existing report templates and build new templates to match your requirements and style

From Finding to Fix - Complete Visibility

Two-way collaboration replaces email chains

Clients don't just see vulnerabilities - they actively participate in remediation. Track progress against SLAs with complete transparency.

Remediation Plans
Acknowledge and plan timelines directly in portal
Target Remediation Dates
Visual indicators and progress tracking
SLA Tracking
Countdown timers with escalation alerts
Retest Requests
One-click retest when fixes deployed
Remediation Notes
Threaded communication per vulnerability

Connect AttackForge to Your Entire Security Ecosystem

Vulnerability data should flow to where your stakeholders already work. AttackForge integrates with unlimited enterprise platforms through native connectors, Flows automation, and comprehensive APIs.

JIRA

Bi-directional Flows

ServiceNow

Bi-directional Flows

Azure DevOps

Bi-directional Flows

Slack

Flows

Microsoft Teams

Flows

Power BI

Flows

Vulnerabilities Become Tickets - Automatically

Bi-directional sync with JIRA, ServiceNow, Azure DevOps, and more

Security findings shouldn't live in silos. AttackForge exports vulnerabilities directly to your ticketing systems, complete with descriptions, evidence, and custom field mappings. Bi-directional sync means ticket status updates flow back to AttackForge automatically.

One-Click Export
Export vulnerabilities directly from project interface
Custom Issue Type Mapping
Map severity to your priority scheme
Bi-Directional Sync
Ticket resolved → Vulnerability auto-updates
Evidence Attachment
Screenshots and PoC files exported
Vulnerability Created
JIRA Issue Created
Status Synced

Security Alerts Where Your Teams Already Work

When a critical vulnerability is discovered at 2 AM, your security team shouldn't have to check another portal. AttackForge sends real-time notifications directly to Slack, Microsoft Teams, and Discord.

Project-Linked Channels
Dedicated channel for each pentest
Real-Time Alerts
Critical/high vulnerabilities within seconds
Customizable Messages
Rich formatting with severity badges
Daily/Weekly Summaries
Scheduled digests of project status
#security-alerts
AttackForge2:14 AM
CRITICALSQL Injection Discovered

Affected Asset: api.example.com
Project: Q1 2025 Penetration Test

Build Any Integration You Need

150+ REST API endpoints with full OpenAPI v3 documentation

If a native integration doesn't exist, build it yourself. AttackForge provides comprehensive REST APIs, an Event-driven API for real-time notifications, and full OpenAPI v3 documentation. Every feature and data point available in the UI is available via API.

Self-Service RESTful API
150+ endpoints for full CRUD operations
Self-Service Events API
Real-time event notifications
AI Model Context Protocol (MCP)
Connect your AI assistants to AttackForge
Comprehensive API Security
Each user has their own key with scoped permissions
API Example
# Get all vulnerabilities for a project
curl -X GET "https://[tenant].attackforge.com/\
  api/ss/project/{id}/vulnerabilities" \
  -H "X-SSAPI-KEY: your-api-key" \
  -H "Content-Type: application/json"

AI Integration Note: AttackForge's MCP integration allows your AI assistants like Claude to securely query vulnerability data, generate reports, and assist with analysis - while maintaining strict access controls. AI queries are logged, auditable, and respect user permission boundaries.

Intelligent Notifications That Drive Action

Generic email blasts get ignored. AttackForge's rule-based notification engine sends the right information to the right people based on vulnerability attributes, timing, and organizational context.

Keep Teams Informed Throughout the Engagement

From testing kick-off to final retest, project stakeholders receive timely updates tailored to their role. No more "just checking in" emails - everyone knows exactly where things stand.

Daily Start/Stop Testing
Project team members
New Critical Vulnerability
Configurable per project
New High Vulnerability
Configurable per project
Vulnerability Ready for Retest
Pentesters on project
Vulnerability Closed
All stakeholders
Retest Completed
Project team
Project On Hold / Off Hold
Project team

Full Control

Per-User Opt-In
Forced Notifications for Compliance
Custom Email Templates
Batched or Individual Delivery

SLA Reminders and Escalations - On Autopilot

Eliminate manual deadline tracking with intelligent, rules-based alerts

Missed SLAs damage client relationships and create compliance risk. AttackForge eliminates manual deadline tracking with intelligent, rules-based alerts that warn stakeholders before breaches occur and escalate automatically when they don't.

The Problem We Solve

  • • Security teams juggle hundreds of open vulnerabilities across multiple projects
  • • Spreadsheet-based SLA tracking fails silently
  • • By the time someone notices a missed deadline, the damage is done

How It Works

1
Define Rules
Set conditions using 50+ vulnerability attributes
2
Set Timing
Choose when alerts fire: 30, 14, 7, 1 days before SLA breach
3
Assign Recipients
Route to vulnerability owner, project team, security managers
4
Escalate Automatically
If no action taken, escalate to next tier on your schedule

Escalation Ladder Example

SLA - 14 daysWarning emailVulnerability Owner
SLA - 7 daysReminder emailVulnerability Owner + Security Manager
SLA - 1 dayUrgent alertSecurity Manager + Director
SLA breachedEscalationCISO + Compliance + Business Unit Lead
SLA + 7 daysExecutive reportC-Suite weekly digest
No Manual Intervention
Once rules are set, they run forever
Digest vs. Real-Time
Choose one email per vulnerability or daily/weekly summaries
Access-Controlled
Recipients only see vulnerabilities they're authorized to view
Filter Operators
Tools to query for the exact data you need in every email, every time

Reach the Right People - Automatically

Email recipients aren't always on the project team. AttackForge supports dynamic distribution lists based on custom fields, groups, and organizational hierarchy.

Project Team by Role
Project Group Members
Vulnerability Creator
Individual Users
Individual Groups
Custom Field - User Select
Custom Field - Group Select

Emails That Look Like They Came From You

Full HTML control over email templates. Add your logo, custom CSS, and dynamic content for professional communications.

Full HTML and CSS Custom Email Templates
Consistent branding across all emails
Code Editor with Preview
Real-time feedback on template changes
Dynamic Metatags
Insert project, vulnerability, user data
Conditional Formatting
Show/hide sections based on attributes

Your Vulnerability Data Deserves Maximum Level Protection

You're trusting AttackForge with the most sensitive data in your organization - a roadmap of every exploitable weakness. We treat that responsibility with the security rigor it demands.

Security Architecture

Data at Rest
AES-256 encryption, customer-managed keys available
Data in Transit
TLS 1.2+, no legacy protocol support
Authentication
OAuth2 OIDC, mandatory MFA option, SSO enforcement
Authorization
Role-based access, project-level permissions, API scope controls
Network
DDoS mitigation, IP allowlisting, Network flow enforcement
Availability
Highly-available infrastructure, Redundancy across availability zones
Data Sovereignty
Choose your Azure region to ensure data sovereignty
Certifications
AttackForge is SOC 2 Type II certified in Security, Confidentiality and Availability Trust Principles

Access Controls

Enforced MFA
Every local user has MFA enforced by default
Five Distinct Roles
Admin, Project Coordinator, Library Moderator, Consultant, Client
Project-Level Granularity
View, Upload, or Edit permissions per user per project
API Key Scoping
Restrict API access to specific endpoints and HTTP methods
Session Management
Configurable timeout, concurrent session limits, forced re-authentication

Audit & Monitoring

Comprehensive Audit Logs
Every login, data access, configuration change, and export logged
Immutable Log Storage
Audit logs cannot be modified or deleted, even by admins
SIEM Integration
Export logs to Splunk, Sentinel, or any SIEM
Real-Time Alerts
Anomaly detection for suspicious access patterns
Retention
Configurable retention: 3 years standard, custom policy available for compliance

Deployment Options

Single-Tenant Cloud
Dedicated instance in AttackForge-managed cloud
Best for: Hassle-free infrastructure
On-Premises
Full installation in your data center
Best for: Isolated environments

AI Integration Security

When using MCP integration with AI assistants (Claude, ChatGPT, Copilot):

  • ✓Use your own AI - assistants and models - for peace of mind
  • ✓AI queries execute with the user's permission scope - no privilege escalation
  • ✓Zero data retention: train your own models - not ours
  • ✓Organization-wide kill switch to disable AI integration entirely

Feature-level Permission Controls

Give every project team member access to the right features and workflows for their role

Secure by default

Bulk Export

Download entire vulnerability evidence as ZIP for offline handoff or archival.

Compliance ready

Events API

Automations trigger on upload, edit, or delete. Integrate with Slack, Teams, Jira.

Real-time sync

Pentest-as-a-Service (PTaaS) Example

A security team uses workspaces to receive mobile app binaries, API documentation, and test credentials from customers - all in one auditable location with timestamped uploads. Testers document findings in test case workspaces that remain tester-visible only until findings are ready for customer review. When a customer uploads a new version of their app, the Flows workflow automation engine triggers a Slack notification to the team channel instantly.

Ready to Transform How You Communicate Security Findings?

Start your free trial today. Deploy in minutes. See results immediately.

SOC 2 Type II CertifiedInstant DeploymentNo credit card required