SCHEDULING & LOGISTICS

From Request to Delivery:
Orchestrate Your Entire Pentest Lifecycle

Intake requests, schedule resources, coordinate testers, deliver results and track remediation - all from one purpose-built platform.

Self-Service Project Requests That Actually Work

Eliminate email chaos with structured intake that captures everything upfront - scope, timelines, access requirements, and stakeholder details.

❌

Before AttackForge

  • •Intake requests arrive via email, Slack, tickets, and hallway conversations
  • •Scope details are incomplete and require endless back-and-forth
  • •Coordinators spend hours chasing information before testing can begin
  • •No audit trail or standardization across engagements

After AttackForge

  • Stakeholders submit structured requests through a customer portal
  • Required fields ensure complete information upfront - no chasing
  • Approvals happen in clicks, not email threads
  • Full audit trail retained for every engagement from day one

Self-Service Request Portal

Customers submit requests via customizable scoping forms. File uploads during request automatically transfer to project workspace upon approval.

Tailored, professional intake experience

Service Catalogue Integration

Present test suites as selectable services - Web App Pentest, API Security, PCI Compliance, Mobile Testing, and more. Relevant test cases auto-load when projects are created.

Methodology-aware intake, not generic dropdowns

Approval Workflow

Three-state workflow: Pending → Approved / Rejected. Request more information for incomplete submissions. Clone from previous projects to carry forward scope and assets.

Ideal for annual retests and continuous testing

Granular Access Controls

Permissions at View / Edit / Action levels. Assign access to individual users or groups. Auto-add to group feature for streamlined permissions.

Perfect for consultancies with client-facing staff

Notifications & Audit Trail

Email notifications at every workflow stage. Full history retained in "Actioned Requests" archive. Event-driven API integration with ServiceNow, Jira, and more.

Timestamped, auditable record of every request

Clone Previous Projects

When approving requests, clone from previous engagements to carry forward scope, assets, workspace files, and vulnerabilities for retest scenarios.

Save hours on recurring assessments

Pentest-as-a-Service (PTaaS) Tip

Security teams use project requests to standardize customer intake, eliminate scoping ambiguity, and create auditable records of every engagement from day one. The branded portal creates a professional first impression while the structured workflow ensures nothing falls through the cracks.

Scheduling & Resource Visibility Beyond the Spreadsheet

See who's working on what, when. Make informed decisions without the spreadsheet shuffle.

⚠️ Important: This is about visibility and coordination, not workforce management software. We give you clarity - you make the decisions.

Before: Spreadsheet Chaos

  • • Resource allocation lives in a shared spreadsheet that's perpetually outdated
  • • Double-bookings happen regularly
  • • Coordinators ping testers individually to check availability
  • • No visibility into who's actually working on what

After: Clear Visibility

  • One calendar view shows every engagement, every tester, every deadline
  • Check availability in seconds
  • Make informed decisions without the spreadsheet

Project Calendar

Filter by:
Mon
Tue
Wed
Thu
Fri
Sat
Sun
1
Web App
API Test
2
3
4
5
Web App
6
API Test
7
8
9
Web App
10
11
API Test
12
13
Web App
14
15
16
API Test
17
Web App
18
19
20
21
Web App
API Test
22
23
24
25
Web App
26
API Test
27
28

Multi-User View

See all projects, all users, all dates in one place.

No more email chains

Timeline Filtering

Filter by day, week, month. Zoom in or out as needed.

Instant clarity

Smart Search

Find projects by name, tester, client, or date range.

Navigate all your projects

Collaboration Workspaces: Your Single Source of Truth

Credentials, documentation, evidence, notes - all in one place with full traceability.

The Documentation Nightmare

  • • Credentials scattered across emails and Slack DMs
  • • Screenshots buried in local folders
  • • Notes trapped in personal OneNote/Notion pages
  • • No audit trail when something goes wrong
  • • Customer uploads vanish into ticket systems
  • • Handoff between testers = knowledge loss
  • • Compliance auditor asks "where's the proof?" and you panic
  • • Report writing becomes archaeology

Project Workspace

Acme Corp Web App Pentest

vpn-credentials.txt
Uploaded by Sarah • 2 hours ago
api-documentation.pdf
Uploaded by Marcus • 1 day ago
scan-results.xml
Uploaded by Priya • 3 days ago
Upload File

Test Case Workspace

SQL Injection Testing

Procedure
Test all input fields for SQL injection vulnerabilities using standard payloads...
Execution Notes

Testing login form - found potential injection point in username field...

Evidence
sql_injection_proof.png
Screenshot • 2.4 MB

Feature-level Permission Controls

Give every project team member access to the right features and workflows for their role

Secure by default

Bulk Export

Download entire workspace as ZIP for offline handoff or archival.

Compliance ready

Events API

Automations trigger on upload, edit, or delete. Integrate with Slack, Teams, Jira.

Real-time sync

Pentest-as-a-Service (PTaaS) Example

A security team uses workspaces to receive mobile app binaries, API documentation, and test credentials from customers - all in one auditable location with timestamped uploads. Testers document findings in test case workspaces that remain tester-visible only until findings are ready for customer review. When a customer uploads a new version of their app, the Flows workflow automation engine triggers a Slack notification to the team channel instantly.

Command Your Offensive Security Program.

Stop firefighting logistics. Start delivering security impact. Try AttackForge on-demand.

SOC 2 Type II CertifiedInstant DeploymentNo credit card required