Documentation

White-Label Reports

Put your agency name, logo, colors, and support line on scan, pentest, and compliance reports, then send a time-limited client view.

Who This Topic Is For

Agencies and consultancies on Team or Enterprise who deliver scan, pentest, or compliance reports to clients under their own brand.

Prerequisites

Before You Start

Use this checklist to make sure the workflow guidance applies cleanly to your current task.

  • The organization is on Team or Enterprise. Free and Pro keep Vulnify branding on exports.
  • You belong to an organization workspace. Org owner or admin can save branding; members can usually view it.
  • You have a logo file ready: PNG or JPEG for PDF and HTML, or SVG for HTML. Maximum size is 1 MB.
Expectations

What To Expect

Use this section to set the right outcome before you start the workflow.

One organization brand, not per-client packs

Company name, colors, logo, cover subtitle, footer, disclaimer, and support line apply to the organization. Per-client brand packs and reseller splits are not part of this product. Use the optional Prepared for overlay when a specific client name should appear on one report.

No logged-in client portal

Clients do not create Vulnify accounts. Delivery is a branded HTML or PDF report, a time-limited /r/ share link, and optional email. The old public /report/domain/date page is not the agency client path.

Logo format matters for PDF

PNG and JPEG embed in both HTML and PDF. SVG is suitable for HTML preview and HTML reports. If the sample PDF is missing the logo, upload a PNG or JPEG instead of SVG.

Share links expire

Copy client link creates a branded view at /r/{token}. The in-app action uses a 14-day lifetime. Links can last from 1 to 90 days. If a link expires or is revoked, create a new one from Scan History, Dashboard, or the pentest workspace.

Playbook

Step-By-Step Guidance

Follow these steps in order for a reliable and repeatable outcome.

  1. Confirm Team or Enterprise and open Settings.

    Sign in, open Settings, and find the White-Label Reports card under the organization. If you see an upgrade warning, the current plan does not include white_label.

    Hide Powered by Vulnify stays off until that feature is available.

  2. Fill the brand fields and upload a logo.

    Set Company Name, Report Title, primary and secondary colors, Website URL, Support Email, Cover subtitle, Footer text, and Report Disclaimer.

    Upload PNG, SVG, or JPEG up to 1 MB. A Logo URL override is optional for HTML only.

    Hosted uploads are the path that embeds in PDF.

  3. Save, then preview before a client send.

    Click Save Report Branding.

    Use Preview report for an HTML iframe of the branded cover. Use Download sample PDF to confirm the logo, colors, footer, and hide-Vulnify setting look correct on paper.

    Reset to Defaults restores the built-in Vulnify cover if you need a clean start.

  4. Run or open a real report, then copy a client link.

    Complete a dashboard scan, pentest, or compliance report as usual.

    From Scan History, Dashboard, or the pentest workspace, choose Copy client link. Optional prompts ask for Prepared for (client company) and Engagement title.

    The clipboard receives a URL such as https://vulnify. app/r/{token}.

  5. Email the client when they should not chase a link.

    Use Email to client, enter the recipient, and optionally the Prepared for name. The client receives the branded deliverable and can open the time-limited view.

    This is not a mailbox inside Vulnify and it is not a logged-in client portal.

  6. Tell the client what they will see.

    They open the share link in a browser, view branded HTML, and can download PDF when that artifact exists. They should not expect a Vulnify login, a score explanation unique to pentest PDFs, or a permanent public archive.

    If the link is dead, ask you for a new one rather than using /report/{domain}/{date}.

Examples

Worked Examples

These scenarios show how the workflow looks in practice, including the result you should see.

Agency cover on a weekly scan PDF

Harbor Labs on Team uploads harbor-labs.png, sets Company Name to Harbor Labs, Report Title to Security Assessment, cover subtitle to Confidential client deliverable, and enables Hide Powered by Vulnify. They save, preview HTML, then download the sample PDF.

Client PDFs show the Harbor Labs logo, colors, and footer. Vulnify is not printed on the cover.

Prepared for overlay for one retailer

From Scan History they click Copy client link, enter Acme Retail in Prepared for, and Q3 checkout review as the engagement title. The share page and PDF cover read Prepared for Acme Retail without changing the organization-wide brand pack.

The client sees their company on this report only. Next month a different client can use the same agency brand with a new overlay.

SVG logo missing from PDF

The HTML preview shows a sharp SVG mark. The sample PDF does not. They re-upload a PNG of the same logo and download the sample again.

HTML still looks correct. PDF now draws the PNG. SVG remains HTML-only.

Expired share link after two weeks

The client bookmarks /r/{token} and opens it on day 16. The view is no longer active because the in-app copy used 14 days. The agency creates a new client link from Scan History.

A new token is copied. The old URL stays dead. There is no self-serve client login to recover it.
Validation

Validation Checklist

Use this checklist to confirm the workflow was completed correctly.

  • The organization plan is Team or Enterprise.
  • Sample PDF shows the hosted logo, colors, footer, and hide-Vulnify setting you expect.
  • A real scan or pentest can generate a /r/ client link.
  • Prepared for and engagement title appear when you entered them.
  • The client can open the link without a Vulnify account.
Troubleshooting

Common Problems And Fixes

If something does not match expectation, check these common failure modes first.

White-label controls are locked on Free or Pro

White-label is included on Team and Enterprise only. Upgrade the organization, then return to Settings to upload a logo and hide Vulnify branding.

Common failure mode

Member can view branding but cannot save

Only organization owner or admin can update branding. Ask an admin to save, or use an admin account for logo upload and hide-Vulnify.

Common failure mode

Client opened /report/domain/date instead of the share link

That older public-safe page is not the branded agency deliverable. Send the /r/{token} link created from Copy client link or Email to client.

Common failure mode

Expecting a unique brand pack per client workspace

This product uses one organization brand. Put the client name in Prepared for on each send. Per-client brand packs are not included.

Common failure mode
FAQ

White-Label Reports FAQs

Common questions for this topic.

White-label is included on Team and Enterprise. Pro and Free accounts keep Vulnify branding on exported reports.

Next Recommended Action

Continue to the best next page based on where you are in your workflow.