From Request to Delivery:
Orchestrate Your Entire Pentest Lifecycle
Intake requests, schedule resources, coordinate testers, deliver results and track remediation - all from one purpose-built platform.
Self-Service Project Requests That Actually Work
Eliminate email chaos with structured intake that captures everything upfront - scope, timelines, access requirements, and stakeholder details.
Before AttackForge
- •Intake requests arrive via email, Slack, tickets, and hallway conversations
- •Scope details are incomplete and require endless back-and-forth
- •Coordinators spend hours chasing information before testing can begin
- •No audit trail or standardization across engagements
After AttackForge
- Stakeholders submit structured requests through a customer portal
- Required fields ensure complete information upfront - no chasing
- Approvals happen in clicks, not email threads
- Full audit trail retained for every engagement from day one
Request-to-Project Workflow
Customer Submits Request
Coordinator Reviews
Approved / Request Info / Rejected
Project Created
Team Notified
Customer Submits Request
Coordinator Reviews
Approved / Request Info / Rejected
Project Created
Team Notified
Self-Service Request Portal
Customers submit requests via customizable scoping forms. File uploads during request automatically transfer to project workspace upon approval.
Service Catalogue Integration
Present test suites as selectable services - Web App Pentest, API Security, PCI Compliance, Mobile Testing, and more. Relevant test cases auto-load when projects are created.
Approval Workflow
Three-state workflow: Pending → Approved / Rejected. Request more information for incomplete submissions. Clone from previous projects to carry forward scope and assets.
Granular Access Controls
Permissions at View / Edit / Action levels. Assign access to individual users or groups. Auto-add to group feature for streamlined permissions.
Notifications & Audit Trail
Email notifications at every workflow stage. Full history retained in "Actioned Requests" archive. Event-driven API integration with ServiceNow, Jira, and more.
Clone Previous Projects
When approving requests, clone from previous engagements to carry forward scope, assets, workspace files, and vulnerabilities for retest scenarios.
Pentest-as-a-Service (PTaaS) Tip
Security teams use project requests to standardize customer intake, eliminate scoping ambiguity, and create auditable records of every engagement from day one. The branded portal creates a professional first impression while the structured workflow ensures nothing falls through the cracks.
Scheduling & Resource Visibility Beyond the Spreadsheet
See who's working on what, when. Make informed decisions without the spreadsheet shuffle.
⚠️ Important: This is about visibility and coordination, not workforce management software. We give you clarity - you make the decisions.
Before: Spreadsheet Chaos
- • Resource allocation lives in a shared spreadsheet that's perpetually outdated
- • Double-bookings happen regularly
- • Coordinators ping testers individually to check availability
- • No visibility into who's actually working on what
After: Clear Visibility
- One calendar view shows every engagement, every tester, every deadline
- Check availability in seconds
- Make informed decisions without the spreadsheet
Project Calendar
Acme Corp Web App Pentest
Lead: Sarah Chen • Jan 15 - Jan 22
Beta Inc API Security Review
Lead: Marcus Torres • Jan 18 - Jan 25
Gamma Ltd Mobile Pentest
Lead: Priya Sharma • Jan 20 - Jan 27
Multi-User View
See all projects, all users, all dates in one place.
Timeline Filtering
Filter by day, week, month. Zoom in or out as needed.
Smart Search
Find projects by name, tester, client, or date range.
Collaboration Workspaces: Your Single Source of Truth
Credentials, documentation, evidence, notes - all in one place with full traceability.
The Documentation Nightmare
- • Credentials scattered across emails and Slack DMs
- • Screenshots buried in local folders
- • Notes trapped in personal OneNote/Notion pages
- • No audit trail when something goes wrong
- • Customer uploads vanish into ticket systems
- • Handoff between testers = knowledge loss
- • Compliance auditor asks "where's the proof?" and you panic
- • Report writing becomes archaeology
Project Workspace
Acme Corp Web App Pentest
Test Case Workspace
SQL Injection Testing
Testing login form - found potential injection point in username field...
Feature-level Permission Controls
Give every project team member access to the right features and workflows for their role
Bulk Export
Download entire workspace as ZIP for offline handoff or archival.
Events API
Automations trigger on upload, edit, or delete. Integrate with Slack, Teams, Jira.
Pentest-as-a-Service (PTaaS) Example
A security team uses workspaces to receive mobile app binaries, API documentation, and test credentials from customers - all in one auditable location with timestamped uploads. Testers document findings in test case workspaces that remain tester-visible only until findings are ready for customer review. When a customer uploads a new version of their app, the Flows workflow automation engine triggers a Slack notification to the team channel instantly.
Command Your Offensive Security Program.
Stop firefighting logistics. Start delivering security impact. Try AttackForge on-demand.