ProvenizeDesign partner brief · For penetration testing teams
Pre-1.0 · v0.9.x
Search your own old reports without handing them to a cloud — and name the report and page behind every finding.
Three problems it solves
The repeat findingYou reported this misconfiguration for another client last year. Nothing in the toolchain remembers.recall across engagements
The confidentiality clampThe material is under NDA. Pasting scope into a hosted tool is the one thing you cannot do.reports stay local
Proof from your reportA client disputes a finding. You need the evidence record, not your memory of it.every finding sourced
It never attacksFindings import reads Burp, Nessus and Nuclei exports. It does not scan or exploit.built that way, not a setting
In an engagement
- Engagement-bound roles — access scoped to one engagement
- Evidence linked in a chain — every tool call becomes a record
- Cited answers — document, page, match score
- Local embeddings — the index stays on the machine
- PII masking — before any external model call
- Legal-hold role — blocks erasure while retention applies
- Cross-provider memory — MCP server in development
- Findings import — planned: Burp, Nessus, Nuclei
What it does not do
- The desktop application does not exist yet — the Python SDK does.
- PII masking is best-effort; its known gaps are documented.
- A standalone auditor tool, so a client verifies without our code, is planned.
What you get- Early access to the SDK
- A direct line to the founder
- Influence on what gets built
- No payment in the partner phase
What we ask- 30–60 minutes of feedback per iteration
- Real engagements to test against
- A tester who tries to break it