Help

White-Label Reports Help

Fix locked branding, missing logos on PDF, expired client links, and Team-only white-label access.

Who This Topic Is For

Agency users delivering reports to clients who hit a branding lock, a missing logo, or a dead share link.

Prerequisites

Before You Start

Use this checklist to make sure the workflow guidance applies cleanly to your current task.

  • You can open Settings and see the White-Label Reports card, or you can see the upgrade warning.
  • You know whether the client opened a /r/ link, a PDF attachment, or an older /report/ URL.
  • You know who is org owner or admin if save is disabled.
Expectations

What To Expect

Use this section to set the right outcome before you start the workflow.

Upgrade wall on Free and Pro

Those plans keep Vulnify branding. Logo upload, hide-Vulnify, client share, and email-to-client require Team or Enterprise.

Fourteen-day client links from the in-app buttons

Copy client link and Email to client use 14 days. After that the token fails and you create a new link. There is no client login to recover an expired URL.

One brand for the organization

Colors and logo are organization-wide. Put the client name in Prepared for when copying a link. That overlay does not replace the agency cover.

Playbook

Step-By-Step Guidance

Follow these steps in order for a reliable and repeatable outcome.

  1. Read the White-Label card state.

    If it asks you to upgrade, stop and move to Team or Enterprise. If it says only owner or admin can update, switch accounts.

    If save is enabled, continue to the logo and preview steps.

  2. Prove branding with sample PDF, not only HTML.

    Save Report Branding, click Preview report, then Download sample PDF. If HTML has the logo and PDF does not, replace SVG with PNG or JPEG under 1 MB and save again.

  3. Regenerate or resend after branding changes.

    Files created before the save still look old. Run a new export, or copy a new client link, after the logo and hide-Vulnify change.

  4. Confirm the client URL shape.

    A working agency view looks like /r/{token}. If the client used /report/{domain}/{date}, send the branded share link instead.

    If /r/ returns unavailable, the token expired or was revoked; copy a new client link from Scan History or the pentest workspace.

  5. Use overlay fields for the client name.

    Prepared for and engagement title are optional prompts on Copy client link and Email to client. They label that deliverable.

    They are not a second logo pack and not a client account.

Examples

Worked Examples

These scenarios show how the workflow looks in practice, including the result you should see.

Pro agency cannot hide Vulnify

The checkbox is disabled and an upgrade warning is visible. They upload a logo anyway and the export still says Powered by Vulnify.

Expected on Pro. Upgrade to Team, save branding again, then download a new sample PDF.

Client bookmarked an expired /r/ link

The send was 16 days ago. The page is unavailable. Scan History still has the scan. Copy client link creates a fresh token and optional Prepared for name.

The new URL works for 14 days. The old bookmark stays dead.

PDF missing logo after SVG upload

Preview report shows the mark. Sample PDF does not. File type is SVG. They upload logo.png and download the sample again.

PDF draws the PNG. HTML continues to work.
Operations

Operational Playbook

Use this long-form guidance to execute the workflow consistently across planning, implementation, and validation.

Confirm Plan And Role Before Debugging The Cover Page

White-label is a Team and Enterprise feature. Free and Pro users will see an upgrade warning and cannot hide Powered by Vulnify. Inside a Team organization, owner and admin can save branding; members can usually view the card but cannot upload a logo or change hide-Vulnify. If a designer cannot save, that is authorization, not a broken form. Upgrade or switch to an admin account first. Do not treat the lock as a file-type problem.

Separate HTML Preview Success From PDF Logo Success

Preview report renders HTML and can show SVG. Download sample PDF draws raster logos. PNG and JPEG embed in both. SVG is HTML-first and can be absent on PDF. When a client says the PDF has colors but no mark, re-upload PNG or JPEG rather than chasing a share-link bug. Hosted upload is the primary path. Logo URL override is optional and intended for HTML. After changing the file, save branding, then download a new sample PDF before sending a client link.

Client Delivery Is A Link, Not A Portal

Copy client link and Email to client create a time-limited view at /r/{token}. The in-app actions use 14 days. Clients should not create Vulnify accounts. The older /report/{domain}/{date} public-safe page is not the branded agency path; if a client landed there, resend the /r/ URL. Expired or revoked tokens stay dead. Create a new link from Scan History, Dashboard, or the pentest workspace. Optional Prepared for and engagement title apply to that report overlay only. They do not create a second brand pack.

Hide Vulnify Only When The Feature Is On

The Hide Powered by Vulnify checkbox is forced off unless the organization has white_label. Saving other fields on a lower plan will not remove Vulnify from exports. After upgrade, save branding again, preview, and download sample PDF. Scan, pentest, and compliance generators all read the same organization branding. If one export looks branded and another does not, confirm you regenerated after save rather than opening a file created before the logo existed.

Escalate With Plan, File Type, And The Exact URL The Client Opened

Include whether the account is Team or Enterprise, who tried to save, the logo file type and size, whether HTML preview showed the mark, whether sample PDF showed the mark, and the exact URL the client opened. That distinguishes a plan gate, an SVG-on-PDF issue, an expired share token, and a user who forwarded the wrong report route. Do not paste client secrets into the ticket. Do not promise a logged-in client portal; that product is not included.

Validation

Validation Checklist

Use this checklist to confirm the workflow was completed correctly.

  • Plan is Team or Enterprise, or the upgrade wall is understood.
  • Sample PDF matches the intended logo, colors, footer, and hide-Vulnify setting.
  • The URL sent to the client starts with /r/.
  • Prepared for text is present when you entered a client company.
  • A member who cannot save has been routed to an org admin.
Troubleshooting

Common Problems And Fixes

If something does not match expectation, check these common failure modes first.

Logo upload rejected

Use PNG, SVG, or JPEG at 1 MB or smaller. Other types and larger files fail. For PDF, prefer PNG or JPEG.

Common failure mode

Hide Vulnify does not stick on a lower plan

The control is forced off without white_label. Upgrade, then save again.

Common failure mode

Client cannot log in to see the report

They should not log in. Send the /r/ share link or email. There is no client portal in this product.

Common failure mode

Share link opened the wrong kind of public report

Do not send /report/{domain}/{date} for agency delivery. Use Copy client link so the client gets branded HTML and PDF download on /r/{token}.

Common failure mode

Wanted a different logo per client

Organization branding is shared. Use Prepared for for the client name. Per-client brand packs are not included.

Common failure mode
FAQ

White-Label Reports Help FAQs

Common questions for this topic.

It is included on Team and Enterprise. Free and Pro keep Vulnify branding. Org members may also be unable to save when they are not owner or admin.

Next Recommended Action

Continue to the best next page based on where you are in your workflow.