Your last five engagements, searchable.
Recognise what you saw before. Keep client data separate. Name the source of every finding.
In plain words
For security testers: at a new client you find something you have seen somewhere before — but in which report was it?
Provenize searches your own old reports, on your own laptop, and names the report and the page. Data from different clients stays separated, so your confidentiality agreements stay intact.
Three pains from practice
- The repeat findingYou reported this misconfiguration for a different client last year. Nothing in your toolchain remembers that.search across engagements, with the source named
- The NDA clampYou want AI help, and the material is under NDA. Pasting the scope into a hosted tool is the one thing you cannot do.your files never leave your computer
- Report proofA client disputes a finding. You need the evidence record, not your memory of it.every claim points at the record that produced it
In an engagement
What it does while you work.
- Access limited to one engagementBuiltroles scoped to one engagement
- Import findingsBuiltreads scanner exports — never runs them
- Answers with their sourceBuiltdocument, page, match score
- Recognise it across engagementsBuiltrecognise what you already reported
- Evidence linked in a chainBuiltevery step becomes a line in the log
- The search index stays on your computerBuiltthe index stays on your computer
- Retention-hold roleBuiltblocks erasure while retention applies
- Separate checking app for othersPlanneda client can check without our software
Agreements with the client
Provenize reads findings and documents. It does not scan, exploit, or execute anything — by design, not by configuration.
Break it before we ship it.
Become a design partner