Human-reviewed · machine-operable

See every engagement through to verified closure.

VulnQuill turns scanner output and manual testing into reviewed findings, controlled publication, verified remediation, and client-ready reports. Work in the current app or automate the same guarded workflow through REST and MCP.

No card Two active engagements No finding limit
Sanitized current VulnQuill analytics showing findings, remediation status, SLA adherence, CWE, and OWASP coverage
Current product capture · portfolio analyticsRisk · remediation · SLA

Report delivery

Know what reached the client and what happened next.

Follow every report from generation through sending and opening, without rebuilding delivery history from email threads.

  • Sent, opened, unopened, blocked, and revoked delivery states
  • Total and unique views with first and last open times
  • Passphrase-protected links and visit-by-visit access history
Sanitized current VulnQuill report delivery summary showing sent, opened, view, and country totals
Current product capture · report deliverySent · opened · viewed

Controlled automation

Machines can move the work. Humans keep control.

Create findings, submit them for review, publish approved work, record remediation decisions, and complete retests without dropping into a browser-only gap.

  • Explicit review and publish transitions with role and scope gates
  • Passed and failed retest outcomes with a chronological audit
  • Matching REST and MCP capabilities with structured errors
  • Byte-identical retries replay safely; changed requests are rejected
01Draft 02Ready for review 03Published
Sanitized current VulnQuill API reference showing API-key, submit-for-review, and publish operations

Current workflow: create · submit for review · withdraw · publish · request retest · record outcome · decide risk · read the remediation audit.

Current product capture · workflow APIRole-scoped · state-aware

All 21 parser families: Nuclei · Nmap · Nessus · Burp Suite · OWASP ZAP · OpenVAS · Nikto · Acunetix · Qualys · SARIF 2.1.0 · Semgrep · Trivy · CycloneDX · OWASP Dependency-Check · Snyk · Gitleaks · Checkov · Prowler · MobSF · GitLab Security · VulnQuill Generic CSV.

Beyond the report

The operating layer around every engagement.

Every supporting system stays tied to the engagement, so teams can follow risk from discovery through verified closure.

01Finding lifecycle API
Create, review, publish, remediate, retest, and audit findings through documented state-aware operations with consistent structured errors.
02Recon and asset history
Discover and verify live hosts, bring selected targets into scope, and keep finding history attached to the same asset across engagements.
03Methodology and proof of work
Track pass, fail, not-applicable, and not-tested outcomes; keep the raw operator log internally while automatically redacting recognized credential values in client-facing reports.
04Remediation SLAs and retests
Start severity-based deadlines when a finding is published, record passed or failed retests, surface overdue work, and retain the full transition history.
05Controlled web delivery
Share read-only reports through revocable links with optional passphrases and a visit-by-visit access log.
06Portfolio visibility and intake
Measure open risk, time to fix, SLA adherence, recurring weaknesses, and OWASP coverage; turn an approved client request into a planning engagement.

Start free on real work.

The free plan is limited by active engagements, not findings. Paid access is a one-time 30-day or annual purchase; nothing auto-renews.

PlanBest for30-day accessSeats
FreeEvaluate with two active engagements and no finding limit.₹01
SoloIndependent pentesters running unlimited engagements.₹7491
TeamSmall teams that need QA roles, API, MCP, and recon.₹2,9995
ConsultancyGrowing consultancies with a shared delivery workflow.₹7,99950

Prices are in INR. Annual access costs ten 30-day periods. No GST is added.

Run one engagement from scope to closure.

Start with two active engagements for free, or book 20 minutes to see whether VulnQuill fits your current delivery process.