Sectoria Logo
Security Assessment Platform
Product Showcase Guide

Enterprise-grade, self-hosted platform for penetration testing teams to manage the entire security assessment lifecycle.

Version
1.1
Date
March 2026
Classification
Client-Facing
Section 01

Executive Overview

Sectoria is an enterprise-grade, self-hosted platform purpose-built for penetration testing teams to manage the entire security assessment lifecycle — from importing scanner findings to delivering polished, client-ready reports.

60%
Faster Reports
80%
Fewer Errors
100%
Data Control

Who Is Sectoria For?

01

Security Consultancies

Streamline client engagements, manage multiple projects simultaneously, and deliver branded reports.

02

Internal Security Teams

Centralize vulnerability tracking, maintain assessment history, and demonstrate compliance.

03

Enterprise Organizations

Scale security operations across teams and business units with full audit trails and RBAC.

Core Value Propositions

Focus on Testing, Not Documentation

Automate the tedious parts of report writing so your team can focus on finding vulnerabilities.

Professional Client Deliverables

Generate polished, client-branded reports in Word, HTML, or PDF format with a single click.

Complete Data Control

Deploy behind your firewall, in your private cloud, or in air-gapped environments. Your data never leaves your infrastructure.

AI-Powered Intelligence

Leverage local LLM integration to enrich findings with descriptions, remediation guidance, and compliance mappings.

Section 02

The Problem We Solve

Security teams spend up to 40% of their time on documentation instead of actual testing. Sectoria eliminates these pain points:

Pain PointHow Sectoria Solves It
Hours copy-pasting between scanners and WordOne-click scanner import with auto-mapping to your vulnerability database
Inconsistent formatting across team membersTemplate-driven reports ensure every deliverable looks professional
Manual vulnerability tracking in spreadsheetsCentralized vulnerability database with 6000+ pre-built findings
Scattered evidence across folders and emailsIntegrated PoC editor with rich text and image upload per finding
Version control nightmaresImmutable report snapshots with full version history
Client data stored in third-party clouds100% self-hosted — deploy on-prem, private cloud, or air-gapped
No visibility into team workloadReal-time dashboard with capacity tracking and project health metrics
Section 03

Platform Architecture

Technology Stack

LayerTechnologyPurpose
FrontendReact + TypeScript + Material-UIModern, responsive web interface
BackendPython FastAPIHigh-performance REST API (95+ endpoints)
DatabasePostgreSQL 13+Reliable storage with JSONB & full-text search
CacheRedisSession management & real-time features
Real-TimeWebSockets (Socket.IO)Live collaboration & notifications
Reportspython-docx + Jinja2 + WeasyPrintMulti-format report generation
AIOllama / OpenAI (configurable)Local or cloud LLM enrichment
DeploymentDocker + Docker SwarmContainerized, scalable infrastructure

Role-Based Access Control (RBAC)

CapabilityAdministratorTeam LeadTeam Member
System configuration, migration & licensing✓——
User management✓Members only—
Client & template management✓✓View only
Vulnerability database (global feed)✓✓View only
Methodology management✓✓View only
Project creation✓✓—
Access assigned projects✓✓✓
Customize findings & generate reports✓✓✓
Section 04

Getting Started

4.1 First-Time Setup

When Sectoria is deployed for the first time, an Administrator must complete the initial setup wizard.

Walkthrough: Initial Setup
  1. Navigate to your Sectoria instance URL (e.g., https://sectoria.yourcompany.com/setup)
  2. The Setup Wizard appears automatically on first launch
  3. Provide Setup token and Create the initial Administrator account with full name, email, and strong password
  4. The system initializes the database and redirects to the login page
Setup Wizard Step 1 — Verify Token

Step 1 — Verify Setup Token

Setup Wizard Step 2 — Create Administrator

Step 2 — Create Administrator Account

4.2 Login & Authentication

Walkthrough: Standard Login
  1. Enter your email and password
  2. If MFA is enforced by an administrator, the user will be prompted to set up an authenticator app after a successful login. The user must scan the QR code, verify with a 6-digit code from the app, and save the provided backup codes. Once configured, MFA cannot be disabled by the user — only an administrator can remove it.
  3. On subsequent logins, enter the 6-digit code from your authenticator app
  4. Optionally check "Remember Me" for persistent sessions
  5. Click Sign In to access the Dashboard
Login — Credentials

Step 1 — Email & Password

MFA Setup — QR Code

Step 2a — Scan QR Code

MFA Setup — Backup Codes

Step 2b — Save Backup Codes

MFA Login — Authenticator Code

Step 3 — Login with Authenticator

Security Features at Login

Account lockout after 5 failed attempts (30-minute cooldown)

Session timeout (configurable, default 30 minutes)

Multi-Factor Authentication via TOTP apps (Google Authenticator, Authy)

Password complexity enforcement (12+ chars, mixed types)

Section 05

Dashboard & Analytics

The Dashboard is the central command center, providing real-time visibility into your security operations across six analytical sections.

Vulnerability Intelligence

Severity distribution pie chart, vulnerability trends (30-180 days), top finding categories, and knowledge base statistics.

Project Health & Pipeline

Status breakdown across 6 stages, at-risk project detection (overdue/inactive), duration distribution, and team completion rates.

Client Analytics

Contract expiration tracker, industry distribution, client activity grid, and deep-dive analytics dialog with risk exposure metrics.

Team & Capacity

Top performers, workload distribution chart, 7/30-day activity heatmap, and real-time presence indicators.

Dashboard overview with stat cards, charts, and analytics
Dashboard analytics and project health panels
Dashboard additional analytics panels
Dashboard panel 8
Dashboard team and capacity panels
Dashboard storage and system panels
Dashboard panel 6
Dashboard panel 7

Storage Management (Admin)

  • Storage statistics — Used vs. available disk space with visual progress bar
  • Hierarchical tree view — Browse reports by Client → Project → Report
  • Search & filter — Find reports by name, code, or format (DOCX/PDF/HTML)
  • Bulk deletion — Select multiple reports with required audit reason
  • Format icons — Color-coded: PDF, HTML, DOCX
Storage management overview
Storage management tree view
Section 06

Client Management

Manage your client portfolio with comprehensive profiles, scope tracking, and contract management across all industry sectors.

Walkthrough: Creating a New Client
  1. Navigate to Clients from the sidebar
  2. Click + New Client
  3. Fill in: Client Name, Contract reference, Primary Contact (Name & Email), Industry Sector, Contract Dates, and scope of work
  4. Upload the client's logo (used in report generation and branding)
  5. Click Create — auto-generates code (e.g., CLT-20260316-0001)
Client list with industry-colored avatars
Create Client dialog
Client detail page

Scope Management

Each client has a detailed scope allocation panel tracking resource consumption per engagement type:

Scope CategoryDescription
Man-daysTotal allocated testing days per contract
Web Application TargetsNumber of web apps in scope
Mobile Application TargetsiOS/Android apps in scope
WiFi SSIDsWireless networks to assess
IP AddressesNetwork hosts in scope
Thick Client ApplicationsDesktop applications to test
Red Team Objectives/ScenariosRed team engagement scope
Config Review ScopeConfiguration review targets

Per-project utilization shown with color-coded progress bars: red <25%, orange 25-50%, yellow 50-75%, green >75%.

Client detail page with scope allocation progress bars
Section 07

Project Management

Projects are the core organizational unit, representing individual security assessment engagements with a defined lifecycle and 8-tab workspace.

Project Status Workflow

Planning → In Progress → Testing → Reporting → Review → Completed
Walkthrough: Creating a New Project
  1. Navigate to Projects → Click + New Project
  2. Select Client, enter Project Name, choose Type (Pentest / Config Review)
  3. Set Start/End Dates and optional description
  4. Set the scope items (if applicable) to be deducted from overall client scope
  5. Click Create — auto-generates code (e.g., PROJ-20260316-0001)
Projects list with status chips, deadlines, and team counts
Project management detail

Project Workspace (8 Tabs)

◉

Overview

Project summary, dates, team capacity ring visualization

⚙

Engagement Details

Executive Summary, Methodology, Testing approach, environment, and report compliance requirements

⚠

Project Vulnerabilities

Add, customize, and manage findings with PoC evidence

✎

Attack Narrative

Optional narrative with scenarios and images

✓

Re-testing

Remediation verification with pass/fail tracking

☷

Reports

Generated report history with download & versioning

☆

Team

Member assignments with Read-Write / Read-Only / Reviewer permissions

✉

Activity

Real-time presence, comments, notifications, audit feed

Project workspace tabs
Section 08

Vulnerability Management

Sectoria maintains a centralized Vulnerability Feed — a global knowledge base serving as the single source of truth for your organization.

Walkthrough: Browsing the Vulnerability Feed
  1. Navigate to Vulnerabilities from the sidebar
  2. Browse the sortable table: Vulnerability Code, Title with CRITICAL HIGH MEDIUM LOW INFO badges, CVSS Score, Category, Tags
  3. Use filters: search by title, filter by severity, category (20+ OWASP-aligned), or source
  4. Click any row for full vulnerability details with smart color-coded indicators
Vulnerability feed table with severity badges, CVSS scores, and filter toolbar

Smart Color-Coded Indicators

FieldColor Logic (Security-First Perspective)
SeverityCritical High Medium Low Info
Technical ImpactCritical=Red, High=Orange, Medium=Yellow, Low=Green
Ease of IdentificationVery Easy/Easy=Red (dangerous), Moderate=Orange, Difficult/Very Difficult=Green (secure)
Ease of ExploitationVery Easy/Easy=Red (dangerous), Moderate=Orange, Difficult/Very Difficult=Green (secure)

Bulk Import & Export

Import (CSV / JSON)

  • Upload CSV or JSON file with vulnerability data
  • Skip duplicates option (match by title)
  • Field mapping for non-standard columns
  • Import preview with validation results

Export

  • Export all vulnerabilities as JSON
  • Respects current filters (severity, category)
  • Useful for sharing across instances or backup
  • Full field export including tags and CVEs
Vulnerability detail page with color-coded chips
Vulnerability detail page sections
Section 09

Project Vulnerabilities & PoC Evidence

This is where the real work happens — customizing findings for each engagement and documenting exploitation evidence.

Walkthrough: Adding Findings from the Feed
  1. Open a project → Project Vulnerabilities tab
  2. Click + Add from Feed to browse the global vulnerability database
  3. Search, filter by severity/category, and multi-select findings
  4. Click Add Selected — findings are cloned into the project
  5. Re-order vulnerabilities based on tester preference by drag and drop feature
  6. The original feed vulnerability is never modified
Project vulnerabilities list

The below screenshot shows Add From Feed wizard

Add From Feed wizard

Compliance Audit Import

Import compliance audit findings directly from Nessus .nessus files with drag-and-drop upload. Sectoria auto-parses compliance results, skips duplicates, and uses AI-powered severity estimation to assign risk levels based on control criticality and regulatory impact. Max file size: 50MB.

Important: This feature is specifically designed for Configuration Review project types. Compliance audit imports are used when assessing system hardening, baseline configurations, and regulatory compliance — distinct from vulnerability-based penetration testing projects. After import, the user can trigger LLM enrichment on all findings or specific ones using your local LLM (Ollama) to generate severity ratings, enhance descriptions, impact, and remediation guidance — all processed on your infrastructure with zero data leaving your network.

Compliance audit import dialog

Findings Options

Each project vulnerability can be customized, duplicated, compared with source, and promoted to feed if added manually.

Customize Dialog

Edit title, severity, status, impacts, description, technical details, recommendations, CVSS scoring, and risk assessment fields.

Duplicate Finding

Instantly clone a vulnerability within the project — perfect for documenting multiple instances of the same issue across different endpoints or components, each with its own PoC evidence and tester notes.

Promote to Feed

Created a custom project-level finding? Promote it to the global vulnerability feed with one click, making it available for all future projects. Turns field discoveries into reusable organizational knowledge.

Compare with Source

Side-by-side comparison of customized finding vs. original from global feed with highlighted differences.

Proof of Concept Evidence Editor

Professional rich text editor powered by Tiptap, purpose-built for documenting exploitation evidence:

  • Formatting — Bold, italic, code inline, bullet/numbered lists, code blocks, links
  • Image Upload — Drag-and-drop screenshots (JPEG/PNG/GIF/WebP, max 5MB, magic byte validation)
  • Real-time preview — Content renders as formatted HTML in reports
  • Status tracking — Active, Resolved, Verified, False Positive per finding
PoC Rich Text Editor with formatting toolbar

Preview Dialog

Click any vulnerability row for a comprehensive read-only view with all sections: customization alert, basic info, affected components, description, impacts, recommendations, PoC evidence with rendered HTML, and tester notes.

Preview dialog
Section 10

Attack Narrative

The Attack Narrative is an optional project section documenting the testing approach as a story — providing clients with context about how the assessment was conducted best suited for red-teaming and internal penetration testing activities.

Walkthrough: Creating an Attack Narrative
  1. Open a project → Attack Narrative tab
  2. Write the Introduction using the rich text editor (scope, objectives, approach)
  3. Click + Add Scenario for each attack path or testing phase
  4. Give each scenario a title (e.g., "External Reconnaissance", "Web App Testing")
  5. Upload images per scenario (up to 20, screenshots/diagrams/network maps)
  6. Drag and drop scenarios to reorder them
  7. Use Preview to see the formatted output before report generation
Attack Narrative editor with scenario cards

Below showing the Attack Narrative Preview dialog

Attack Narrative preview
FeatureDetails
Rich text editingBold, italic, code blocks, lists, links, embedded images
Scenario managementAdd, edit, delete, drag-and-drop reorder
Image uploadsUp to 10 in introduction, 20 per scenario (5MB each)
CollaborationComments section for team discussion
Version trackingChanges tracked with timestamps
Section 11

Report Generation

Report generation is Sectoria's flagship feature — transforming project data into polished, client-ready deliverables with a 3-step wizard.

☷

DOCX

Microsoft Word with full template formatting, client logo, auto-TOC, and severity-colored tables.

◈

HTML

Web-based with dark/light theme. 3-4x faster generation, 50% smaller files, self-contained.

◼

PDF

Via LibreOffice (from DOCX) or WeasyPrint (from HTML). Print-ready with proper page breaks.

3-Step Report Generation Wizard

Step 1: Configure Report
  1. Enter Report Title (e.g., "Q1 2026 Penetration Testing Report")
  2. Select a Template from client's uploaded Word templates
  3. Choose Format: DOCX / HTML / PDF
  4. Toggle Include Attack Narrative
  5. Set Vulnerability Prefix (e.g., "VULN", "PT", "SEC") for finding codes
Step 2: Select Vulnerabilities
  1. Multi-select findings with severity badges and status chips
  2. Filter by severity, status, or category
  3. Choose ordering: by Severity, CVSS Score, or Custom
Step 3: Review & Generate
  1. Review configuration summary (title, template, format, vulnerability count)
  2. Click Generate Report — progress indicator shows status
  3. Click Download when complete
Report generation wizard
Report generation step 2
Report generation step 3

Immutable Snapshots

Key Feature: Every generated report creates an immutable snapshot of all project data. You can regenerate the exact same report months later, even if underlying data has changed. Critical for audit compliance and client disputes.

Report Content Structure

#SectionDescription
1Cover PageClient logo, project name, date, team lead, version
2Table of ContentsAuto-generated with page numbers
3Executive SummaryHigh-level overview of findings
4Vulnerability Summary TableAll findings with severity, CVSS, status
5Attack Narrative (optional)Introduction and scenarios with embedded images
6Vulnerability DetailsPer-finding: code, description, impact, recommendations, PoC

Template System

Upload client-specific Word templates with placeholders like {{client_name}}, {{vulnerabilities_section}}, {{attack_narrative}}. Sectoria auto-detects and validates all placeholders on upload.

Template system
Section 12

Re-testing & Remediation Tracking

Track vulnerability remediation and verify fixes with a dedicated re-testing workflow consisting of 5 re-test rounds (max) and report generation.

Retest Recording

Record Pass/Fail/Not Tested status per vulnerability with tester comments and timestamps.

Retest Report

Generate dedicated retest reports with severity-based statistics, color-coded results, and trend analysis.

Re-testing tab with Pass/Fail status chips

Notice second vulnerability in above screenshot with 'Failed' status which needs a second round of re-test

Re-testing remediation tracking

Now all vulnerabilities are passed, we can generate re-test report

Re-testing report view
Section 13

Team Assignment & Access Control

Assign team members to projects right after creating new project with granular permission levels, capacity-aware selection, and real-time notifications on every change.

Three Permission Levels

Read/Write — full access to all project content. Read-Only — view only, cannot modify or generate reports. Reviewer — view and comment, approve changes.

Team Lead Designation

Promote any member to Team Lead with a toggle. Team Leads automatically get Read/Write access. Every active project must have at least one Team Lead.

Capacity-Aware Assignment

User selection dropdown sorted by workload utilization. Color-coded capacity bars (green/yellow/red) and active project counts help prevent over-assigning team members.

Real-Time Notifications

Instant WebSocket notifications on assignment, removal, and permission changes. Email notifications sent in parallel. Full audit trail for every team operation.

A user can be READ_WRITE + Team Lead or READ_WRITE + Regular Member, but cannot be READ_ONLY + Team Lead. The Team Lead flag adds organizational authority (can't be removed from active projects, every project must have at least one), while the permission level controls content access. Additionally, user permissions are structured on 2 levels: system level and project level. A team member (not team lead) on system level can be assigned as a Team Lead on a specific project and vice versa.

Team assignment dialog
Team members with permissions
Section 14

Activity Tracking

Complete audit trail with 113 tracked action types across authentication, project management, vulnerabilities, reports, and collaboration — all updated in real-time via WebSocket.

Live Activity Feed

Real-time project activity stream with color-coded action icons, user avatars, and relative timestamps adjusted to each user's timezone. Infinite scroll pagination.

Activity Statistics

Dashboard showing total activities, last 24h/7d counts, trend analysis (increasing/decreasing/stable), most active user, and most common action type.

Advanced Filtering

Filter by action type (project, vulnerability, report, comment), user, status (success/failure/error), and date range. Collapsible filter panel with active filter count.

Rich Action Messages

Intelligent message generation: "Added 'SQL Injection' to project", "Re-tested 'XSS Stored' → PASSED", "Changed status: Planning → In Progress".

Activity tracking feed
Section 15

Team Collaboration

Real-time collaboration features keep your team synchronized via WebSocket-powered communication.

Real-Time Presence

See who's viewing or editing each project section. Auto idle detection after 2 minutes.

Comments & @Mentions

Tabbed discussion (Overview, Vulnerabilities, Narrative). @mentions trigger instant notifications.

Notifications

Team assignments, permission changes, report completions, comment mentions — all in real-time.

Team collaboration with presence indicators and notifications
Team chat and comments
Notification dropdown
Section 16

Scanner Integration

Sectoria features a Universal XML Parser — a configuration-driven engine that can parse any scanner's output without hardcoded logic. Built with enterprise security and extensibility at its core.

Universal Configuration-Driven Parser

No hardcoded parsing logic. Scanner configurations are defined as JSON field mappings — add a new scanner by creating a config file, no code changes required.

Secure XML Processing

Uses defusedxml library to prevent XXE attacks, XML bombs (billion laughs), and DTD retrieval. File size validation (50MB max), extension whitelist, and magic byte validation.

Memory-Efficient Streaming

Generator-based parsing pattern processes findings one at a time — handles large scan files (10,000+ findings) without loading everything into memory.

Admin-Customizable Configurations

Two-tier config registry: built-in defaults (JSON files) overridden by admin database configurations. Customize field mappings per scanner without touching code.

Walkthrough: Importing Nessus Results
  1. Open a project → Project Vulnerabilities → Click Import
  2. Upload your .nessus file
  3. Sectoria auto-detects scanner format, parses vulnerabilities with CVSS & CVEs, normalizes severity, deduplicates
  4. Review import preview with validation results → Click Import
ScannerFormatFeatures
Nessus.nessus (XML)Vulnerability + Compliance audit parsing, CVE extraction, CVSS derivation
Qualys VMXMLVulnerability management scan parsing with QID mapping
Qualys WASXMLWeb application scan parsing
Qualys PCXMLPolicy compliance scan parsing
Burp SuiteXMLPlanned — add via JSON configuration
NmapXMLPlanned — add via JSON configuration
OWASP ZAPXML/JSONPlanned — add via JSON configuration

Architecture

ComponentRole
UniversalParserConfiguration-driven XML parser — extracts raw values using field mappings defined in JSON
ConfigurationRegistryTwo-tier config lookup: admin database overrides → built-in JSON defaults. Auto-detection via XML structure patterns
ImportAdapterTransforms parsed findings into project vulnerabilities with deduplication, severity normalization, and OWASP category mapping
Security Layerdefusedxml for XXE/bomb prevention, input sanitization, field length limits (50K chars), output XSS prevention
BaseParserAbstract interface using Template Method pattern — defines the parsing lifecycle for all scanner implementations

Adding a New Scanner: Create a JSON configuration file defining the XML element paths, field mappings, and transformations. Register it in the config directory or upload via the Admin Settings UI. No Python code changes needed — the Universal Parser handles the rest.

Section 17

AI-Powered Enrichment

Leverage local or cloud-based LLMs to enhance vulnerability descriptions, generate remediation guidance, and map findings to compliance frameworks.

CapabilityDescription
Compliance Severity EstimationAutomatically estimate severity ratings for compliance audit findings based on control criticality, regulatory impact, and organizational risk context
Description EnhancementTransform sparse scanner output into comprehensive, audit-ready findings
Remediation GuidanceGenerate actionable remediation steps tailored to the specific finding
Compliance MappingMap findings to CIS, NIST, PCI-DSS, ISO 27001 frameworks
Impact AnalysisGenerate technical and business impact assessments

Privacy: With Ollama (local LLM), all processing happens on your infrastructure. No data leaves your network. Cloud LLM (OpenAI) is optional and can be toggled off at any time.

Section 18

Custom Methodologies

Design and manage testing methodologies with a visual canvas editor supporting all penetration testing categories. Default methodologies are seeded in Sectoria out of the box, ready to use from day one.

Visual Canvas Editor

Drag-and-drop phase design with arrow connections. Auto-generates SVG diagrams for documentation and reports.

All Categories

Web App, Mobile, Network, API, Cloud, Wireless, Active Directory, Social Engineering, Physical, IoT/ICS, Red Team, Code Review, and more.

Methodology canvas editor with phases connected by arrows

Editing and viewing Configuration Review Methodology

Methodology management
Section 19

Email Notifications

Complete transactional email system with customizable templates across 5 categories: Authentication, Security, Notification, Report, and System.

  • Rich HTML editor for template customization with variable insertion (e.g., {{user_name}})
  • Preview & test send before deploying changes
  • Reset to default if customizations don't work out
  • SMTP configuration with TLS and encrypted credential storage
Email notification templates
Email template editor
Section 20

Administration & Settings

Comprehensive configuration across 8 settings tabs with role-based visibility.

TabAccessKey Settings
GeneralAll usersProfile, theme (Light/Dark/System), personal timezone (55 zones)
PreferencesAdminGlobal timezone, application URL for email links, SMTP configuration, work schedule & weekend days configuration for business day calculations
Report ConfigurationAdminFilename patterns with variables, severity color customization
Storage & BackupAdmin/TLStorage quotas, usage breakdown, cleanup
LLM & AIAdminProvider selection (Ollama/OpenAI), model config, connection test
SecurityAdminSession timeout (15-480min), lockout, MFA enforcement, IP whitelisting
Scanners & ParsersAdminScanner integration configuration, field mapping
System AdministrationAdminLicense management, device migration, system upgrades

System Upgrades (Air-Gap Support)

Upload .sup upgrade packages with RSA-SHA256 digital signature verification, SHA-256 checksums, version compatibility checking, and 7-step tar validation. Rollback option available if issues detected. No internet required.

Section 21

Security & Compliance

Built with security as a first-class concern, designed and continuously tested by cybersecurity professionals.

Authentication & Access

bcrypt password hashing with salt

RFC 7519 JWT with 9-point validation

TOTP MFA (Google Authenticator, Authy)

RBAC with 40+ granular permissions

Redis-backed token revocation blacklist

Data Protection

TLS 1.3 + Fernet (AES-128) encryption

File upload: whitelist + MIME + magic bytes

SQLAlchemy ORM (parameterized queries)

DOMPurify + Jinja2 auto-escaping (XSS)

SSRF prevention (private IP / metadata blocking)

Comprehensive Audit Trail

Every action logged with: User ID, action type (113 types), resource affected, timestamp (UTC), client IP, user agent, status, and JSON details. Supports SOC2, ISO 27001, GDPR compliance requirements.

CVSS Scoring

Full support for CVSS v3.0, v3.1, and v4.0 vector strings with base, temporal, and environmental scores. Built-in CVSS calculator in vulnerability customization for accurate risk assessment.

MITRE ATT&CK Mapping

Map findings to MITRE ATT&CK technique IDs (e.g., T1190, T1059.001) with a dedicated selector component. Available in both global vulnerability feed and per-project vulnerability customization.

OWASP Standards Integration

Findings mapped to: OWASP Web Top 10 (2025), OWASP Web Top 10 (2021), OWASP Mobile Top 10 (2024), and OWASP API Security Top 10 (2023) with links to official documentation.

Section 22

Deployment Options

Sectoria is 100% self-hosted — your data never leaves your infrastructure.

On-Premise

Physical servers in your data center. Maximum control for regulated industries.

Private Cloud

AWS, Azure, GCP private instances. Scalability with cloud infrastructure.

Virtual Machines

VMware, Hyper-V, VirtualBox. Flexible resource allocation.

Air-Gapped

No internet connectivity required. Deploy and upgrade offline for classified environments.

Infrastructure Requirements

ComponentMinimumRecommended
CPU2 cores4+ cores
RAM4 GB8+ GB
Storage50 GB100+ GB
OSUbuntu 22.04+Ubuntu 24.04 LTS
Docker20.10+Latest stable

Container Architecture

ContainerPurpose
sectoria-frontendReact web application (Nginx)
sectoria-backendFastAPI application server
sectoria-postgresPostgreSQL database
sectoria-redisRedis cache and session store

Supports Docker Compose for single-node and Docker Swarm for high-availability clusters.

Appendix A

Screenshot Checklist

Use this checklist to capture all screenshots needed for the final document. 56 screenshots total.

01 Setup wizard — admin account creation
02 Login page with MFA input
03 Dashboard — 4 stat cards
04 Dashboard — vuln intelligence
05 Dashboard — project health
06 Dashboard — client analytics
07 Dashboard — team capacity
08 Storage management dialog
09 Client list with avatars
10 Create Client dialog
11 Client detail — scope bars
12 Client detail — projects
13 Projects list page
14 Create Project dialog
15 Change Status dialog
16 Project Overview — capacity ring
17 Team tab with permissions
18 Add Team Member dialog
19 Engagement Details tab
20 Vulnerability feed table
21 Create Vulnerability dialog
22 Vulnerability detail page
23 Import dialog
24 Add from Feed dialog
25 Create Direct Vuln dialog
26 Customize dialog
27 Customization indicator dot
28 PoC Rich Text Editor
29 Preview dialog
30 Compare dialog (side-by-side)
31 Vuln header stats bar
32 Attack Narrative editor
33 Narrative preview dialog
34 Report gen Step 1
35 Report gen Step 2
36 Report gen Step 3
37 Generated DOCX in Word
38 Generated HTML report
39 Report History tab
40 Template upload + validation
41 Report Color Settings
42 Re-testing tab
43 Retest report
44 Scanner import dialog
45 Compliance import
46 LLM Settings card
47 Methodology canvas
48 Methodology list
49 Presence indicators
50 Comment section
51 Notification dropdown
52 Activity feed
53 Email template editor
54 Settings — General tab
55 Settings — Security tab
56 System Upgrade card
Sectoria Logo
Focus on Testing, Not Documentation

Ready to transform your security assessment workflow?
Schedule a demo to see Sectoria in action.

Get Started
sectoria.io
Website
sectoria.io
LinkedIn
linkedin.com/company/sectoria
Support
sectoria.io/contact