Features
Everything Dossier does, in plain terms.
Dossier turns raw security-scan exports into a client-ready penetration test report, parsed, correlated, scored, mapped to controls and written in your voice. Everything below is deterministic where it must be (parsing, deduplication, scoring, control mapping) and AI-assisted only for the prose, so no finding is ever invented.
Multi-tool import
Native parsers for Nmap XML, Nessus, Trivy, Nuclei, Burp Suite and OWASP ZAP, with Metasploit, BloodHound, Nikto, SQLMap and ffuf on the way. Drop in the exports you already have; no re-scanning, no reformatting.
Try itCorrelation & deduplication
The same vulnerability seen by three tools becomes one finding with three proofs. Cross-tool deduplication strips the noise that makes raw scan output unreadable, so your client sees the real issue count, not the tool count.
Try itCVSS 3.1 scoring
Every finding carries its CVSS 3.1 score, vector and CWE, decoded into attack vector, complexity and impact. Nothing is invented, each number is traceable to the source scan.
Try itRisk prioritisation
Findings are ranked by severity and exploitability, the top risks surfaced in the executive summary, and remediation grouped into an immediate / short-term / medium-term roadmap a client can act on.
Try itHonest compliance mapping
Findings are mapped to the relevant ISO 27001 Annex A and NIS2 technical measures as evidence for the auditor, never a fabricated compliance percentage. The conformity decision stays where it belongs, with the assessor.
Try itWhite-label reports
Your logo, accent colour and footer on every page. Reports ship as your firm's deliverable, not ours.
Try itDOCX, PDF & HTML export
One report, three formats: editable DOCX, print-ready PDF and a self-contained HTML page. Hand over whichever the client asked for.
Try itFrench & English output
Full French and English reports, written, not machine-translated, so the prose reads the way a consultant would write it.
Try itPrivacy by default
Scan files are deleted after processing and reports are purged on a retention schedule. Anonymised input is honoured exactly as supplied.
Try itA pentest report generator built around the tools you already use
Dossier is a penetration test and vulnerability report generator for security consultants, MSPs and audit firms. It reads the native output of Nmap, Nessus, Trivy, Nuclei, Burp Suite and OWASP ZAP, correlates findings across tools, removes duplicates, and assigns a verifiable CVSS 3.1 score to every one.
Where most tools stop at a list, Dossier produces the deliverable: an executive summary in business terms, a prioritised remediation roadmap, an evidence-based ISO 27001 and NIS2 control mapping, and a full technical annex, in French or English, exported as DOCX, PDF or HTML under your own brand.
The design principle is honesty. Parsing, deduplication, scoring and control mapping are deterministic code; the model only writes prose from already-structured data. No magic risk score, no invented compliance percentage, every figure traces back to the scan you uploaded.