Vulnerability management software
that tracks every finding
Vulnerability management tool with auto-calculated CVSS 3.1 scores, Nessus and Burp Suite imports, 300+ pre-built templates, and real-time remediation tracking. Log, prioritise, and close vulnerabilities from one platform.
No credit card required. Free plan available forever.
Centralise every vulnerability in a single finding register
Vulnerability management is at the heart of every security engagement. Whether your team uncovers issues through manual security assessments, automated scanning, or compliance audits, each finding needs to be documented with enough detail for clients to understand the risk, prioritise remediation, and verify the fix. SecPortal's findings management module provides a structured, searchable register that captures the full lifecycle of every vulnerability from discovery to closure.
Instead of copying findings between Word documents, spreadsheets, and ticketing systems, security teams log everything directly in SecPortal. Each finding records the title, description, severity, CVSS vector, affected assets, evidence, remediation guidance, and current status. The result is a consistent, professional output that saves hours of formatting and reduces the risk of errors in client deliverables.
Five-tier severity classification
Critical
Immediate exploitation risk requiring urgent remediation
High
Significant security impact with clear attack vectors
Medium
Moderate risk requiring planned remediation efforts
Low
Minor issues or hardening recommendations
Info
Informational observations and best-practice notes
Import findings from your favourite scanners
Manual data entry is a bottleneck that slows delivery and introduces mistakes. SecPortal supports direct import from industry-standard vulnerability scanners so you can populate your finding register in seconds, not hours. Imported findings are automatically mapped to the correct severity level and linked to the active engagement.
- Nessus (.nessus) scanner import with automatic severity mapping
- Burp Suite (.xml) import preserving request/response evidence
- CSV import with custom column mapping for any scanner output
- Automatic deduplication across multiple scan imports
Built for security teams, not generic project managers
Every feature in the findings module has been designed around the workflows that security teams actually use. From CVSS 3.1 vector string parsing to pre-built templates drawn from real-world assessments, SecPortal eliminates the boilerplate so your team can focus on analysis and client impact.
- CVSS 3.1 auto-calculation from vector string input
- 300+ pre-built finding templates covering OWASP Top 10, network, cloud, and more
- Remediation tracking with client-facing status updates in real time
- Map findings to compliance controls for ISO 27001, SOC 2, and Cyber Essentials
- Rich-text descriptions with evidence attachments and screenshots
- Bulk actions for tagging, severity updates, and status changes
- Full audit trail on every finding for compliance evidence
Related use cases
Stop losing findings in spreadsheets
Centralise every vulnerability in one searchable, trackable database.
No credit card required. Free plan available forever.