pentest operations platform

From scope to retest, without the copy-paste.

Tandera is the operational layer between your tools and your clients. Keep Burp, Nuclei, nmap and your own scripts. Tandera connects scope, evidence, findings, attack paths, QA, reports, delivery, remediation and retest into one record per engagement.

Early access for pentest teams. No spam, no card.

Tandera pentest recon workflow icon CVE-2024-3094 :443 · TLS 1.2 *.api.acme.com
minutes
Lite recon runtime
202
tool importers
1
finding per issue, across tools
PDF·PPTX
client-ready reports
Import from 202 security tools

Generated from our parser registry, not a marketing number. See the full list.

Burp Suite logo Nuclei logo OWASP ZAP logo Nessus logo Acunetix logo Nmap logo Nikto logo Snyk logo Trivy logo TruffleHog logo
the problem

Your process is nine tools and a folder of screenshots.

None of these tools are the problem. The glue between them is, and today that glue is copy-paste: a pentester moving findings between tools by hand.

BurpNucleinmapNotesScreenshotsWordSpreadsheetsPDFEmailJira

The most expensive resource in a pentest is the pentester’s time. Most of it goes to work that is not testing.

one engagement, end to end

Scope to retest, on one record.

Not five products bolted together. Every stage writes to the same engagement record, so the report is a view of your work rather than a document you rebuild by hand.

  1. 01 Scope Typed targets, authorised and locked.
  2. 02 Test Your tools. Imported or pushed via CLI.
  3. 03 Evidence Captured once, attached to the finding.
  4. 04 Findings Correlated across tools, one per issue.
  5. 05 Attack chains How findings chain into real compromise.
  6. 06 QA Senior review before anything ships.
  7. 07 Report Generated from the record, under your brand.
  8. 08 Deliver Your portal, your domain, your client.
  9. 09 Remediate Tracked with the client, not over email.
  10. 10 Retest Validate the fix, close the finding.
The Tandera engagement view for a web app pentest, with the stage bar reading scope, recon, assets, findings, attack chains, review and report.
One engagement, mid-test. The stage bar across the top is the same order as the lifecycle above, because it is the same thing.
work from the terminal

Run the whole pentest from your terminal.

tandera-cli pipes scope out, scans, and imports findings back. No browser required. Recon, import, and report from one command.

tandera-cli — zsh — 96×14
$ tandera scope export --target acme.com \
| httpx -silent \
| nuclei -severity critical,high \
| tandera import --auto-dedupe
✓ 1,284 hosts probed  ·  37 findings imported  ·  12 duplicates merged
$

export scope, probe with httpx, scan with nuclei, import back. One line.

02 · CENTRALIZED FINDINGS

One source of truth for every vulnerability.

Each vulnerability becomes a structured, deduplicated, correlated finding. Severity, CVSS, EPSS, KEV, CWE, CVE, OWASP, MITRE, compliance, evidence, and provenance travel with it.

Severity
Finding
CVSS
Source
CRIT
SQL injection · /api/login
9.8
nuclei
HIGH
Exposed .git directory
8.2
recon
MED
Missing security headers ×3 merged
5.3
burp
LOW
Verbose error message
3.1
zap
EPSSKEVCWEOWASPMITRE ATT&CKcompliance
03 · IMPORTERS

Bring your own tools.

We ingest Burp Suite, Nuclei, OWASP ZAP, Caido, and generic CSV. Everything normalizes into the same table.

Burp Suite✓ .xml
Nuclei✓ .json
OWASP ZAP✓ .json
Caido✓ export
Generic CSV✓ .csv
When three tools report the same issue, you get one finding. Each tool’s evidence is kept and attributed to its source.
attack chains

We chain findings into the path an attacker takes.

A list of vulnerabilities is not a threat model. Tandera correlates related findings into attack paths, so you can show how a leaked credential becomes domain admin. The dashboards still look healthy. The exposure does not.

LOW
Leaked credential
found in git history
MED
Cloud storage access
S3 bucket, internal configs
HIGH
Internal API token
recovered from config
CRIT
Domain admin
full tenant compromise
! Four findings, individually rated low to medium. Chained together, full tenant compromise.
reports White-label

Personalize every report as much as you want.

Sections, branding, tone, layout, and scoring are all yours to shape. We build client-ready PDF and PPTX straight from the canonical findings, then you tailor every detail. AI drafts remediation and ranks by real-world risk.

PDF and PPTX, fully branded and templated.
AI drafts remediation and ranks by exploitability and exposure.
Attack paths flow into the report as exploit chains.
White-label everything. Your logo, your colors, your cover, your domain. The report ships as your firm’s work, not ours.
Tandera pentest reporting platform logoTANDERA
CONFIDENTIAL
Penetration Test Report
acme.com · Q2 2026 · 37 findings
4
CRITICAL
11
HIGH
15
MEDIUM
7
LOW
✦ AIenriched and prioritized
client portal White-label

Hand your client a live portal, not a PDF that goes stale.

When the report ships, the work is not finished. We give every client a secure portal to track each finding from open to verified, request retests, and comment in context. You run the remediation lifecycle end to end, in one place.

Share a secure link. Each client sees only their engagement.
Every finding carries status, owner, evidence, and a remediation thread.
Clients request a retest. You verify and close the loop.
The portal is white-label too. Clients sign in to your brand, on your domain. They never see Tandera.
AC acme.com · client portal
secure
18 of 37 findings verified 49%
✓ Open
✓ Triaged
In progress
Fixed
Verified
SQL injection · /api/login
✓ Verified
Exposed .git directory
Retest requestedIn progress
Missing security headers
Open
the platform

One source of truth, from recon to report.

Three capabilities sit around a single canonical findings database. Everything flows into it. Everything reports out of it.

01 · AUTOMATED RECON

Map the full attack surface.

We enumerate subdomains, DNS, open ports, web tech, TLS, cloud assets, and leaked credentials. When recon matches a known vulnerability, it opens a finding automatically.

Lite
Passive first. Runs in minutes.
Full
Deep and active. Runs in hours.
#subdomains
#DNS records
#open ports
#web tech
#TLS config
#cloud assets
#leaked creds
auto-findings
the economics

Your margin is pentester hours.

A consultancy sells expert time. Every hour spent reformatting a finding, rebuilding a report or chasing a client for a retest is margin you already paid for and cannot bill twice.

  • Testers stay testing Findings arrive from the tools they already run, instead of being retyped into a document.
  • Senior review stops being a rewrite QA happens on the finding record, so your principal reviews content instead of fixing formatting.
  • The report is a view, not a rebuild It is generated from the same record the team worked in all engagement.
  • Retests do not restart the engagement The client requests it, the tester validates it, and the finding closes against the original evidence.
The Tandera assessments list showing ten engagements across several clients, with type, status, progress and finding counts.
Every engagement your team is running, with what is late and what is waiting on someone.
security

You are about to upload your clients’ vulnerabilities.

What’s running today, and what isn’t.

  • Encrypted in transit and at rest TLS in transit; the database has storage encryption enabled and sits in a private VPC with no public endpoint.
  • Secrets sealed with envelope encryption Credential-vault entries, integration tokens and report passwords are encrypted with per-record data keys via AWS KMS.
  • Deletes destroy the key material Deleting a vault credential nulls its encrypted columns in the same statement that writes the tombstone. The ciphertext is gone, not just hidden.
  • Every mutation is audited Actor, action, resource, IP, user agent and before/after state are written in the same transaction as the change.
  • Tenant isolation on every query Your org id comes from the verified token, never from the request. A record from another tenant returns “not found”, never “forbidden”.
  • Your own AWS account, on Enterprise planned A BYOC deployment that keeps findings, evidence and scope in your account: your S3, your database, your KMS key, your region, your CloudTrail. It’s a design document today, not running code. We’ll keep calling it planned until it ships.
  • No SOC 2 or ISO 27001 yet We are not certified and will not imply otherwise. If your procurement requires it today, tell us and we will be straight about the timeline.
Read the security details →
why tandera

Four different products get called “pentest tooling”.

They solve different problems. The useful question isn’t which is best. It’s which lifecycle your team actually runs on.

  • Reporting tools They turn findings into a polished deliverable, and they’re good at it. You still run the engagement around that document somewhere else: scope, QA, delivery, remediation, retest.
  • Automated pentesting Run the tests for you and produce findings. The value is in replacing testing effort, not in operating the engagements a human team delivers.
  • Exposure management Track vulnerabilities continuously across a large estate. Built for an internal programme measuring its own risk, not for a firm delivering engagements to clients.
  • Tandera: pentest operations Organised around how a consultancy actually runs an engagement: scope, testing with your own tools, QA, branded delivery, client remediation and retest, on one record.

If your problem is the document, a reporting tool may genuinely be enough. Tandera is for teams whose problem is everything around it.

questions

Before you join the waitlist

Straight answers about what Tandera is, what your client receives, and where their vulnerability data lives.

What is Tandera?

A pentest operations platform for consultancies and pentest teams. One record per engagement holds scope, evidence, findings, attack chains, QA, the branded report, delivery, remediation and retest, so the deliverable is a view of the work your team already did instead of a document rebuilt by hand.

How is Tandera different from a pentest reporting tool?

A reporting tool turns findings into a polished deliverable, and the good ones do that well. You still run the engagement around that document somewhere else: scope, QA, delivery, remediation and retest. Tandera is organised around the engagement itself. If the document is your only problem, a reporting tool may genuinely be enough.

Do we have to change the tools we test with?

No. Keep Burp, Nuclei, nmap and your own scripts. Tandera imports findings from 202 security tools, and that list is generated from the parser registry in our codebase rather than picked as a marketing number. Everything normalises into the same findings table, and the CLI can push results straight from your pipeline. When three tools report the same issue you get one finding, with each tool’s evidence kept and attributed to its source.

See the full integration list →

What does our client actually receive?

A client-ready report in PDF or PPTX, generated from the same findings record your team worked in all engagement, with attack paths written out as exploit chains. Sections, branding, tone, layout and scoring are yours to shape, and it is white-label: your logo, your colors, your cover, your domain. The report ships as your firm’s work, not ours.

How do clients track remediation and request a retest?

Every client gets a secure portal instead of a PDF that goes stale. They see only their own engagement, follow each finding from open to verified, comment in context, and request a retest there. Your tester validates the fix and closes the finding against the original evidence. The portal is white-label too, on your domain, so clients never see Tandera.

Where does our clients’ vulnerability data live, and who can see it?

In one AWS region, US East in Ohio. The database runs in a private VPC with no public endpoint. Evidence and uploads are encrypted in S3 against a customer-managed KMS key, and credential-vault entries, integration tokens and report passwords use envelope encryption with a per-record data key. The organisation id used to scope every query comes from the verified session token and never from the request, so a record from another tenant returns not found. Every mutation is written to an append-only audit log in the same transaction as the change.

Read the security details →

Do you have SOC 2 or ISO 27001?

Not yet. We are not certified and will not imply otherwise. If procurement requires a certification today, tell us and we will give you a straight answer on the timeline. Running Tandera in your own AWS account, with your S3, your database, your KMS key and your region, is planned for Enterprise and is a design document right now, so we keep calling it planned until it ships.

Read the security details →

Can we use Tandera today?

Not yet. Tandera is pre-launch and access runs through the waitlist below. We are onboarding pentest teams in waves, and teams on the list get priority onboarding and a direct line to the people building it. No spam, no card.

early access

Get Tandera before your next engagement.

Join the waitlist for early access. We are onboarding pentest teams in waves.

Priority onboarding for pentest teams.
A direct line to the people building it.
Early-access pricing, locked in.

No spam, no card. Unsubscribe anytime.

enespt-br