SecurityBoat

TriNetra · Offensive Testing

Request a pentest. Watch every state of it happen.

TriNetra PTaaS turns the annual pentest into a service you can see moving — a request form that becomes a trackable engagement, a 12-state lifecycle from Requested to Closed, and findings published to your dashboard the moment they're verified, not held for a final PDF.

TriNetra PTaaS engagement detail — the real 12-state pill-stepper lifecycle header
PT-2026-182 — the real 12-state engagement lifecycle, live. · Illustrative sanitized demo data — not customer results.

The problem

Traditional pentesting means weeks of scheduling emails, tester quality that varies engagement to engagement, and a single static report at the very end — so remediation can't start until testing is over, and you don't learn whether the fix held until next year's engagement.

How PTaaS answers it

You request an engagement in-platform, the SB1 team reviews and scopes it, a matched team forms, and testing runs through a fully visible 12-state lifecycle with findings streaming to your dashboard as they're verified — then an enforced retest loop confirms the fix actually worked, inside the same engagement.

How it actually works

Request the engagement, then watch it move

What should we test?

Asset

Pick the asset to test from your inventory.

Engagement type

Web, API, mobile, cloud, network, or something stranger.

Scope & context

Title

Name the engagement.

Description

A rich-text editor for anything the asset picker can't capture.

  1. 1
    ReviewThe SB1 team reviews scope and feasibility, typically within 1 business day.
  2. 2
    Scoping callA call confirms scope, environment, access, and dates.
  3. 3
    ApprovalThe request becomes a trackable Draft engagement.
  4. 4
    DeliveryLive testing → findings → Pre-Final → Final → Post-Retest report.

Twelve explicit states, start to close

  1. Requested
  2. Draft
  3. Scoping
  4. Open to assign
  5. Team formed
  6. Scheduled
  7. Live
  8. Report drafting
  9. Report review
  10. Delivered
  11. Remediation
  12. Closed

TriNetra's real 12-state engagement lifecycle — recreated for legibility; live product view below.

80
Effort (hrs)
6
Issues Found
3
Team Size
0
Days Remaining
TriNetra PTaaS engagement detail — 12-state lifecycle, KPI strip, and tabs
PT-2026-182, Movies Network Penetration Test — live on the real 12-state lifecycle. · Illustrative sanitized demo data — not customer results.

Nine tabs hold everything about the engagement

BriefAssetsTeamCoverageFindingsAnalyticsReportsChatIntegrations
A PTaaS finding's researcher attribution and engagement link card
Researcher attribution and the engagement it belongs to — real fields on every finding. · Illustrative sanitized demo data — not customer results.

Every engagement, one list

TriNetra Pentest Engagements list — every engagement with lifecycle state, TPM, and findings count
Pentest Engagements — every engagement on the platform, with state, TPM, and findings count. · Illustrative sanitized demo data — not customer results.

Capabilities

What ships in the box

A 12-state lifecycle you can see

Requested to Closed, every transition visible on a pill stepper — no black box between kickoff and report.

A real request-to-approval flow

Asset picker, engagement type, and a rich-text scope editor feed a 4-step "what happens next" that ends in a Live engagement, not a form that vanishes into an inbox.

Nine tabs, one engagement

Brief, Assets, Team, Coverage, Findings, Analytics, Reports, Chat, and Integrations — the full operating surface of an engagement in one object.

Methodology coverage you can measure

Coverage against a named framework, broken into Tested / In progress / Not started / N/A — "we tested it" comes with a number.

Findings with a 7-state stepper and full CVSS

Draft through Resolved, with a decomposed CVSS vector, classification, raw request/response, and numbered PoC on every finding.

Pre-live visibility without spoiling detail

My Requests tracks status and dates before an engagement goes live, without exposing scope, pay, or team assignment ahead of time.

FAQ

Common questions

How fast can an engagement start?

You submit the request form in-platform; the SB1 team reviews within 1 business day, a scoping call confirms details, and approval turns it into a trackable Draft engagement — no email chains.

Do we see findings as they're found?

Every finding is visible on the Findings tab moving through its own 7-state stepper the moment it's verified — pre-verification triage stays internal.

What exactly is in a finding?

A decomposed CVSS score with the full vector string, classification (type, asset type, CWE), affected endpoint, business impact, remediation guidance, raw HTTP request/response, and a numbered proof-of-concept — plus a comments thread for back-and-forth with the researcher.

How do we know testing was thorough?

The Coverage tab tracks methodology coverage against a named framework in real time, and the Analytics tab rolls that up alongside severity breakdown and the lifecycle state funnel at close-out.

Retire the annual PDF.

Tell us what needs testing — web, API, mobile, cloud, network, or something stranger — and we'll walk you through the request form on a call.

Related: Ish · Agentic Pentest · Continuous Testing · Bug Bounty