The operating system
for security work
Run assessments, findings, reports, remediation, compliance, and delivery in one place. Use built-in scanners and AI-powered workflows, or bring in results from the tools you already use. Deploy in our cloud or on your own infrastructure.
Built-in scanning · SaaS or self-hosted · SSO/SAML · Full audit trail · Branded portal
White-labelled to your organisation. Available on your custom domain.
One place to run the full security workflow
From initial assessment through final delivery, SecPortal keeps your team in one platform.
Assess
Run external, authenticated, and code-based assessments in one platform, with built-in scanning and support for results from the tools you already use.
Decide
Triage findings, score risk, map to frameworks, and generate clear remediation guidance with AI-assisted workflows.
Deliver
Publish reports, share branded portals, track remediation, and provide audit-ready outputs for clients or internal stakeholders.
Built-in security scanning
Scan domains, web applications, and source code for vulnerabilities, all from the same platform you use to manage engagements and deliver reports.
External Scanning
16 automated modules scan your external attack surface: SSL, ports, subdomains, cloud exposure, and more.
Authenticated Scanning
17 security tests behind login pages: SQLi, XSS, IDOR, CSRF, broken access control, and more.
Code Scanning
SAST via Semgrep and SCA dependency auditing. Connect GitHub, GitLab, or Bitbucket in one click.
Attack Surface Management
Discover subdomains, detect cloud exposure, check for subdomain takeover, and fingerprint technologies.
Continuous Monitoring
Schedule daily, weekly, or monthly scans. Track trends, catch regressions, and maintain your posture.
Scanner Imports
Import findings from Nessus, Burp Suite, and CSV. Combine external tool results with built-in scans in one view.
AI built into the workflow
Use AI to speed up triage, reporting, summaries, remediation guidance, and engagement admin. Every action stays reviewable and under your control.
Create a client called Xygen Ltd with contact sarah@secportal.io and start a security assessment for them
I'll create the client and set up the engagement. Here's what I'll do:
Applied
Done! Created Xygen Ltd and started a Security Assessment. Want me to add findings?
Yes, add a critical SQL injection on the login page
Logged the finding:
AI proposes. You review and approve. SecPortal is the system of record.
Engagement & Client Setup
Creates clients, scopes engagements, assigns team members, and configures assessment types through natural language.
Finding Triage & Scoring
Logs findings with CVSS scores, triages by severity, flags false positives, and recommends prioritisation. You review before applying.
Report Generation
Generates executive summaries, technical breakdowns, and remediation roadmaps from your engagement data. Every output is editable.
Compliance Mapping
Maps findings to ISO 27001, SOC 2, Cyber Essentials, and other framework controls automatically.
Remediation Guidance
Recommends fixes prioritised by impact, tracks resolution progress, and verifies remediation completeness.
Workspace Administration
Schedules scans, manages team assignments, and handles routine admin tasks so your team focuses on security work.
One platform, many workflows
Whether you manage security across business units or deliver assessments to clients, SecPortal is the single place your team works from.
Internal Security Teams
Run vulnerability scans, manage findings and compliance controls across segregated business units, and produce audit-ready outputs — all in one workspace. Self-host to meet data residency requirements.
- Cross-business-unit security management
- AI-assisted triage, compliance summaries & remediation roadmaps
- ISO 27001, SOC 2, Cyber Essentials & more
- Full audit trail with CSV export for board reporting
Service Providers & Consultancies
Run scans for clients, deliver reports through branded portals, track remediation in real time, and manage invoicing — from solo consultants to multi-team firms and MSSPs.
- Branded client portal on your custom subdomain
- Integrated invoicing with Stripe payment collection
- Client-facing remediation tracking & messaging
- Multi-client engagement management across all assessment types
Pre-built for the assessments you run most
Start with pre-configured engagement types, or create custom ones to match your workflow.
See how SecPortal fits your security workflow
Get started in under 2 minutes, or contact our team for enterprise and self-hosted options.

We built SecPortal because every security team we worked with had the same problem: findings in spreadsheets, reports assembled manually, remediation tracked over email, and no single platform connecting it all. Whether you manage security across business units internally or deliver assessments to clients, the operational overhead is identical. SecPortal is the platform I wished existed.
Built by security professionals, for security professionals.
Simple, transparent pricing
Plans for every team size. Contact us for self-hosted and enterprise options.
- 3 clients or business units
- 1 team member
- 2 engagements per client
- Up to 20 items
- 1 GB storage (+ $1/10 GB extra)
- Report delivery & tracking
- Invoicing & payments
- 3 one-time AI credits
- Two-factor authentication (MFA)
- Custom subdomain
- Branding removal
- Security Scanning
- 1 verified domain
- 2 external scans/month
- 6 core scan modules
- Subdomain scanning
- Authenticated scanning
- Code scanning (SAST + SCA)
- Continuous monitoring
- 100 clients or business units
- 2 team members (+ $29/seat extra)
- Up to 10,000 items
- 25 GB storage (+ $1/10 GB extra)
- Everything in Starter
- 25 AI credits/month
- Two-factor authentication (MFA)
- Custom subdomain
- Branding removal
- Lower transaction fees
- Security Scanning
- 5 verified domains
- 50 external scans/month
- All 33 scan modules
- Subdomain scanning
- Attack surface discovery
- Authenticated scanning
- Code scanning — 20/mo, 5 repos
- Continuous monitoring
- 500 clients or business units
- 5 team members (+ $29/seat extra)
- Up to 50,000 items
- 100 GB storage (+ $1/10 GB extra)
- Everything in Pro
- 75 AI credits/month
- Two-factor authentication (MFA)
- Custom subdomain
- Branding removal
- Lowest transaction fees
- Security Scanning
- 10 verified domains
- 100 external scans/month
- Everything in Pro
- Continuous monitoring
- Flexible scan schedules
- Code scanning — 100/mo, 25 repos
- Everything in Team
- Unlimited team members
- Unlimited storage
- Custom transaction fee rates
- Priority support & SLA
- SSO & SAML authentication
- Custom AI credit allocation
- Dedicated account manager
- Custom integrations
- Security Scanning
- Unlimited domains & scans
- Everything in Team
- Custom scan configurations
Frequently asked questions
Everything you need to know before getting started.
Ready to get started?
Talk to our team about your security workflows and compliance needs, or get started immediately with a free workspace.
Available as SaaS, self-hosted, or on-prem.