Deliverables and Controlled Release

A penetration test report is one of the most sensitive documents a client will ever receive. It’s a map of how to break into their organization.
And yet the final step of most engagements is an email attachment. Once it’s sent, you lose track of it. You can’t say who opened it, whether the right person received it, or how many copies are now sitting in inboxes you’ve never heard of. When a corrected version goes out, the old one doesn’t go away.
Deliverables give that final step the same care as the rest of the engagement.
A Proper Home for Final Files
Every engagement has a Deliverables section for the files you hand to the client: reports, attestation letters, scoping documents, memos and presentations. Upload a file, or publish straight from a report you generated in Neuron.
Deliverables start as drafts and are published to the Delivery Portal when they’re ready. Clients see them in a Deliverables list alongside the findings and briefs for their engagement, and the client accounts entitled to a deliverable get an email when it’s published.
Every view and download is recorded in an access log, so “did they get it?” has a definite answer.
One Current Version
Reports change. A client asks for a correction, or a retest changes the picture.
Upload a new version of a deliverable and it supersedes the old one. The previous version is withdrawn from the portal, so clients only ever see the current file, and the version history shows which revision is live and which were withdrawn. Withdrawn deliverables can be restored if you need them back.
Controlled Release
Some documents need more than a download link.
Publish a deliverable under Controlled Release and the recipient has to sign for it before it will download. They read your release statement, confirm they agree to it, and type their name. Only then does the file arrive.
Controlled Release deliverables are limited to named portal accounts, so they never appear on anonymous share links. Before publishing, Neuron shows exactly who will gain access, which share links will lose it, and whether anyone downloaded an earlier copy without signing.

Every signature produces a receipt. It records who signed, the statement they agreed to word for word, a hash of the exact document, their IP address and the time. Open any receipt and Neuron re-verifies its integrity on the spot. Print it, or export it as JSON for your own records.
You set default release terms for your whole organization, override them per client, and adjust the statement on an individual deliverable when a document needs different wording.
Every Copy Traces Back

When a client downloads a PDF deliverable from the portal, Neuron stamps that copy with the recipient’s identity, IP address and download time. If a report ever turns up somewhere it shouldn’t, you know whose copy it was.
You choose the diagonal watermark word, which corner the identity stamp goes in (so it never prints over your own footer), whether to include the IP address, and a closing sentence. A live preview shows exactly what will be printed. The stored file is never modified: each recipient’s copy is stamped at download time.
A Conversation Next to the File
Clients have questions about reports. Each deliverable has its own threaded comment thread, reachable from the engagement, the portal and share links, with comment counts on every list. The discussion stays with the document it’s about, instead of scattering across email.
A Portal Worth Logging Into
The Delivery Portal itself is built to be the place clients go for engagement information. The overview shows a severity breakdown, findings discovered over time, remediation progress and retest verification. A schedule view lays out the engagement, its assessments and retest phases. The portal follows light and dark themes.
What This Means for Your Team
Report delivery stops being the one step of the engagement you can’t account for. You know who received each document, which version they have, that they agreed to your handling terms, and that every copy can be traced. For clients with strict handling requirements, that’s often the difference between “we’ll take your word for it” and “show us.”
Deliverables are part of the Delivery Portal, a licensed Neuron module. If you’d like to see it in action, visit https://neuron.ws/demo (opens in a new tab)
Thanks for reading,
The PenTest.WS Development Team
See Neuron on your terms.
Tell us about your team and environment. We will show you Neuron running the way you would run it: on your infrastructure, under your control.