Skip to main content
GullySystem
Computers and IT · Software for cybersecurity companies

Track scoped engagements, findings and retests, and renewals of resold security licences, in one register.

A cybersecurity firm earns from assessments, managed monitoring and resold security licences, and the work runs across scoping emails, tester notes and report drafts. The software we would build keeps each engagement, its scope, testers, findings and retest status on one record. It also holds retainer hours and licence renewals by client, so reports go out on time and nothing resold lapses unnoticed.

At a glance

Security work is sold as a scope: a set of applications, networks or cloud accounts, tested by named people for a fixed period. The record that matters is what was in scope, what was found and what has been fixed.

Most firms keep that across email, a ticket board and a folder of report drafts. A custom register brings the commercial side and the technical side together without storing any client’s sensitive data more widely than it needs to be.

How the work runs today

A prospect asks for a test of a web application and a mobile app. The firm sends a scoping questionnaire, agrees the targets and dates in writing, and assigns testers from the available bench.

During the engagement, testers log findings with a severity, evidence and a fix suggestion. A reviewer checks each one, and the report is assembled from those notes and sent to the client as a protected file.

After the fixes, the client asks for a retest. Alongside this, the firm resells endpoint, firewall and email security licences and runs monitoring retainers with a set number of hours each month.

Where it breaks

What goes wrong for cybersecurity companies without a proper system.

Scope lives in an email thread

Which hosts were in scope, and which were excluded, is argued after the report is sent. The thread has the answer somewhere.

Findings sit in tester notes

Each tester keeps findings in a personal file and the report is stitched together at the end. Duplicates and gaps get through.

Retests are forgotten

The client fixes issues and nobody tells the firm. A retest is offered months later, or not at all.

Retainer hours are not counted

A monitoring client uses far more hours than the contract covers, and no report shows it. The pricing stays the same.

Licence renewals lapse

A resold firewall subscription runs out on a Friday. The client’s protection ends before anyone has quoted the renewal.

What the software does

What we would build for cybersecurity companies.

Named the way your team already talks about the work. We start with whichever part the audit shows is costing you most.

Engagement register

Record each engagement with client, scope, targets, test window, assigned testers and stage, from proposal through report delivery and retest.

Scope and authorisation record

Store the signed scope, the permitted dates and the contacts at the client, so testers work against a written record and the rules of engagement are one click away.

Findings tracker

Log each finding once, with severity, affected asset, evidence and fix advice, then follow it from open to fixed to retested and closed.

Report assembly and review

Pull reviewed findings into the report template, record who reviewed and approved it, and keep each issued version with its date.

Retainers and hours

Set hours per month for managed and advisory clients, log work against the retainer, and show used and remaining hours before the invoice.

Licence and renewal tracker

List resold licences and subscriptions by client and due date, with the quote prepared well before the vendor’s date.

Access and audit trail

Open client records only to the people on that engagement, and log who viewed or downloaded each report.

Solutions inside

The business modules cybersecurity companies use most.

Each one is also available on its own, or inside a system built for you.

How it works

How the work runs from Bengaluru for your city.

  1. 1

    The audit, by call

    A screen-share and a look at the sheets, Tally reports and WhatsApp groups your team uses. No travel needed.

  2. 2

    A written proposal

    Scope, what we build first and the cost, agreed in writing before anything starts.

  3. 3

    Build in short rounds

    Working screens shared every few weeks. Your team tests them from your own office.

  4. 4

    Go-live, in person when it helps

    For data migration and training we can come to your city. Travel is agreed in advance.

  5. 5

    Support online

    Fixes, changes and hosting handled remotely by the same team that built it.

Common questions

Questions cybersecurity companies ask before they call.

Does it run scans or tests?

No. Your tools do the testing. The system we build records the scope, the findings your testers log, the review and the retest, and keeps them together by client.

Can it import findings from our scanner?

Often, yes. A scanner that exports a file or has an interface can feed findings in. Each tool is scoped separately, and a tester still reviews what arrives.

Will it make our firm certified or compliant?

No. It keeps the records your auditor or a client may ask for. Certification stays between your firm and the body that grants it.

How is client data kept apart?

Each engagement has its own access list, and every view or download is logged. Where a client needs reports kept on their side, that is agreed during scoping.

What happens in the free technology audit?

We look at the software, spreadsheets and WhatsApp groups your business runs on today and write down what works, what slows your team down and what is missing. A demo login, a screen-share or a few screenshots are enough to start. You get a report ordered by priority, and there is no obligation to hire us afterwards.

How much will the software cost?

We don’t publish a price, because it depends on what the system has to do. The audit settles the scope, and the cost goes into a written proposal before any work starts.

Category

Part of a wider group.

Talk to us

Tell us how your business runs today.

A few lines on your spreadsheets, software and WhatsApp groups is enough. We reply the same working day.

  • No obligation
  • A reply within one business day
  • Your details stay private

All fields are required. A short description is enough.

Your details stay private. Privacy policyProtected by reCAPTCHA.