SecurityBoat

TriNetra · Offensive Testing

Request a pentest. Watch every state of it happen.

TriNetra PTaaS turns the annual pentest into a service you can see moving — a request form that becomes a trackable engagement, a 12-state lifecycle from Requested to Closed, and findings published to your dashboard the moment they're verified, not held for a final PDF.

PT-2026-182 · Movies Network Penetration Test

Grey Box● Live
RequestedDraftScopingOpen to assignTeam formedScheduledLiveReport draftingReport reviewDeliveredRemediationClosed

0

Effort (hrs)

0

Issues Found

0

Team Size

0

Days Remaining

BriefAssetsTeamCoverageFindingsAnalyticsReportsChatIntegrations

The problem

Traditional pentesting means weeks of scheduling emails, tester quality that varies engagement to engagement, and a single static report at the very end — so remediation can't start until testing is over, and you don't learn whether the fix held until next year's engagement.

How PTaaS answers it

You request an engagement in-platform, the SB1 team reviews and scopes it, a matched team forms, and testing runs through a fully visible 12-state lifecycle with findings streaming to your dashboard as they're verified — then an enforced retest loop confirms the fix actually worked, inside the same engagement.

How it actually works

Every finding moves on its own rails.

Findings stream to your dashboard the moment they're verified — and the retest loop proves the fix held, inside the same engagement.

SQL injection in legacy reporting export

payments-service · reported by PTaaS engagement PT-2026-182

CRITICAL9.8
DraftTriagingVerifiedAccepted RiskFix in progressRetestResolved

Retest queued the moment the fix landed — the loop that proves the fix held.Retest SLA · 3d

The request flow

Request the engagement, then watch it move.

What should we test?

Asset

Pick the asset to test from your inventory.

Engagement type

Web, API, mobile, cloud, network, or something stranger.

Scope & context

Title

Name the engagement.

Description

A rich-text editor for anything the asset picker can't capture.

  1. 1
    ReviewThe SB1 team reviews scope and feasibility, typically within 1 business day.
  2. 2
    Scoping callA call confirms scope, environment, access, and dates.
  3. 3
    ApprovalThe request becomes a trackable Draft engagement.
  4. 4
    DeliveryLive testing → findings → Pre-Final → Final → Post-Retest report.

Every engagement, one list

Pentest Engagements

Total 20Active 14Completed 6
Movies Network Penetration TestLive6 findings
Mobile Banking API — Grey BoxReport review11 findings
Partner Gateway — Black BoxClosed4 findings

Capabilities

What ships in the box.

A 12-state lifecycle you can see

Requested to Closed, every transition visible on a pill stepper — no black box between kickoff and report.

A real request-to-approval flow

Asset picker, engagement type, and a rich-text scope editor feed a 4-step "what happens next" that ends in a Live engagement, not a form that vanishes into an inbox.

Nine tabs, one engagement

Brief, Assets, Team, Coverage, Findings, Analytics, Reports, Chat, and Integrations — the full operating surface of an engagement in one object.

Methodology coverage you can measure

Coverage against a named framework, broken into Tested / In progress / Not started / N/A — "we tested it" comes with a number.

Findings with a 7-state stepper and full CVSS

Draft through Resolved, with a decomposed CVSS vector, classification, raw request/response, and numbered PoC on every finding.

Pre-live visibility without spoiling detail

My Requests tracks status and dates before an engagement goes live, without exposing scope, pay, or team assignment ahead of time.

FAQ

Common questions.

You submit the request form in-platform; the SB1 team reviews within 1 business day, a scoping call confirms details, and approval turns it into a trackable Draft engagement — no email chains.

Retire the annual PDF.

Tell us what needs testing — web, API, mobile, cloud, network, or something stranger — and we'll walk you through the request form on a call.

Related: Ish · Agentic Pentest · Continuous Testing · Bug Bounty