Now in private beta

Security reviews,
finally under
control.

VulnLedger is the workspace for security professionals — track findings, manage sessions, collaborate with clients, and deliver reports without losing your mind.

VulnLedger mascot

Invite-only. No spam — just a heads-up when your spot is ready.

EU-hosted option PDF & CSV export SSO / OIDC

What you get

Session-driven reviews

Plan, scope, and execute security review sessions with a clear asset-to-finding chain. Every engagement lives in one place.

Structured finding capture

Record vulnerabilities with severity, status, evidence attachments, and taxonomy tags — fast enough to keep pace with testing.

Polished PDF reports

Generate client-ready PDF reports in seconds — with CSV and JSON exports on the side for spreadsheets and downstream tooling.

Multi-client workspaces

Manage dozens of clients without context bleed. Role-based access keeps each client's data exactly where it belongs.

Self-hosted, data stays put

Runs on your own infrastructure with Docker — no third-party SaaS and no client data crossing your perimeter. Built for EU and regulated environments.

Full audit trail

Every login, finding edit, and session change is timestamped and recorded. Forensic-grade history without anyone having to remember to log it.