Gammor
    Pentest Reporting Platform

    Gammor

    Pentest reports, done in a fraction of the time, from the first finding to the delivered report, without the copy and paste.

    A BreachArc product.

    Invite-based · 7-day trial · no credit card, we set up your workspace.

    What it is

    Reporting is where testing time quietly disappears. Gammor is a multi-tenant platform that lets security teams write, brand and deliver penetration-test reports in a fraction of the time, AI drafts each finding from your notes, you stay in control of every word, and the finished document exports client-ready with your branding on every page.

    It is built and run by BreachArc, and it carries the one thing most reporting tools do not: a CERT-In report layout alongside the Standard layout, for teams delivering India compliance work.

    Everything a reporting workflow needs

    AI-assisted findings

    Turn rough notes into a complete finding, title, description, business impact and remediation, then edit freely. Paste a CVSS vector and the score and severity are calculated for you.

    Reusable templates

    Define the exact fields each engagement type should capture and reuse them across projects, with a shared catalog so you never start from a blank page.

    Branded, client-ready reports

    Generate professional Word and PDF reports with your logo and colours on every page, in the Standard layout, or the CERT-In layout for India compliance.

    Projects & evidence in one place

    Organise each engagement, attach screenshots and evidence directly to findings, and track every finding from draft to delivered.

    Roles for the whole team

    Admins, project leads, testers, reviewers and view-only clients each get exactly the access they need. Confidential findings stay visible only to the right people.

    Secure client portal

    Share a delivered report through a secure, revocable link, no account required on the client's side, and access can be withdrawn at any time.

    Complete audit trail

    Every create, edit and status change is recorded, so you always have an accountable history of who did what and when.

    Isolated workspaces

    Each customer workspace is fully separated from every other, enforced at the data layer and not just in the interface.

    How it works

    1

    Create a project

    Start an engagement with its client, scope and dates. Bind a finding template so every finding captures the right fields, and add your team with the right role for each person.

    2

    Add findings

    Write each finding with AI assistance, then refine it your way. Paste a CVSS vector to auto-calculate score and severity, and attach screenshots and evidence inline.

    3

    Generate the report

    Produce a polished document in your chosen layout, Standard or CERT-In, with your branding on every page, and export to Word or PDF in a single click.

    4

    Deliver securely

    Share the report through a secure, revocable portal link with no account needed on the client's side, or hand over the exported file directly.

    Built for security teams

    • Pentest firms & MSSPs: standardise reporting across testers and run many isolated client workspaces from one platform.
    • In-house security teams: keep findings, evidence and reports in one accountable place.

    Security is the default

    • Strict per-workspace data isolation, enforced at the data layer.
    • Role-based access control down to per-project roles.
    • A full audit trail of every change.
    • Read-only client access through revocable portal links.
    • Built with GDPR readiness in mind.

    Ready to cut your reporting time?

    Gammor is invite-based. Tell us about your team and we will set up a workspace and walk you through it. Every plan includes the full platform, starting with a 7-day trial.

    Explore Gammor