New · Release 2026.04, Multi-tenant audit exports & SLA dashboards now liveSee changelog →
Remediation
Remediation support and retests that prove fixes held
Hands-on guidance to fix findings, verify patches, and produce delta reports for auditors and clients.
Product illustration · sample data
Security & VAPT
A+ score
EngagementHTTP LabReport PDF
A+
Last scan · 2 hours ago
Critical vulnerabilities0
High severity2
Manual + imported4
Engagement reportReady
Platform
Included in the Infronest workspace
These capabilities ship in the product today—consulting adds human validation and attestation where required.
Automated web scanning
Scoped engagements
HTTP Lab
Manual & imported findings
Analyst workbench
Audit-ready reports
CVSS 3.1 scoring & CVE enrichment
OWASP & MITRE ATT&CK mapping
Compliance control mapping
Mobile app VAPT
CI & integrations
Role-based access
Tenant isolation
Capabilities
What you get
Delivered with AI-assisted engineering and human review on architecture, security, and production readiness.
In-platform FP workflow with required reasons
Workbench delta and re-scan after deploy
Consulting retest and attestation (L4)
Compliance mapping updates
Executive readouts
Workflow
What teams can do here
Step 1
Triage findings
Step 2
Assign owners
Step 3
Verify fixes
Step 4
Issue final report
How it works
How it works
01
Triage and assign
Findings from automated, manual and imported sources are prioritised on the analyst workbench and given owners, so each issue has a clear route to a fix.
02
Fix with guidance
Each finding carries remediation guidance and CVSS context. Anything believed to be a false positive is closed through a workflow that requires a documented reason, keeping the record honest.
03
Verify the fixes
After remediation, the same scan profile is re-run and the verification engine re-checks previously reported issues, so a closure is evidence-backed rather than assumed.
04
Issue a delta report
A delta report shows exactly what was closed versus what remains open since the last assessment — the artefact auditors and clients ask for. An optional consulting attestation letter follows a human re-test.
Example
A worked example
Imagine a web engagement closing with one critical SQL injection, two highs and four mediums. On the workbench the critical goes to a backend engineer and the highs to the frontend lead, each carrying its CVSS vector and remediation notes. One medium turns out to be a WAF artefact and is closed as a false positive with the reason logged. When the parameterised-query fix deploys, the verification engine re-checks the injection and confirms it no longer reproduces. The delta report shows three findings moved to closed and one documented dismissal — and the client-facing attestation letter follows the certified human re-test.
FAQ
Frequently asked questions
What exactly does a re-test verify?
A re-test re-checks the specific findings from the original assessment to confirm each one is actually fixed — not that the whole application is newly perfect. The output is a clear open-versus-closed picture for those issues.
Is the re-test included in the original engagement price?
The productised one-time assessment includes a re-test, and re-running automated scan profiles against an engagement is part of the platform. A certified human re-test with attestation is the L4 consulting add-on — see the VAPT hub for how the layers fit.
How much should we budget for the full find-fix-verify cycle?
Plan around the initial assessment, since verification re-runs are part of the platform. In the Indian market a focused web application penetration test typically costs ₹1.5–4 lakh (USD 2,000–5,000) and combined network + web VAPT for a mid-size environment ₹5–15 lakh (USD 6,000–18,000); Infronest engagements start at ₹36,750 per application with the re-test included.
How soon after fixing can we re-test, and how long does it take?
As soon as the fixes deploy — you trigger the re-run yourself. Because a re-test only re-checks previously reported findings, it completes in days rather than the one-to-three weeks typical of an initial scoped web assessment; a certified human re-validation is scheduled with the consulting team.
How are fixes confirmed — automated re-scan or manual?
Both paths exist. Automated re-scans and the verification engine re-check reported issues for fast confirmation, and a human re-tester manually re-validates critical and high findings when an audit needs that assurance.
What is a delta report and who is it for?
A delta report compares the current state to the previous assessment and lists what closed and what is still open, with evidence. It is built for auditors and clients who need proof that remediation actually happened.
Do you issue a certificate or attestation after the re-test?
We can provide an executive attestation letter after a human re-test, describing what was validated. It is professional attestation of the testing performed — not an ISO, PCI or other compliance certification, which only an accredited body can grant.
What happens to findings we believe are false positives?
They are not silently dropped. Closing a finding as a false positive requires a documented reason in the workflow, so the audit trail explains why every dismissed issue was dismissed.