Pentr packages technical-vulnerability and security-testing evidence the way surveillance auditors expect to receive it. Annex A controls A.8.8 and A.8.29 map to phases in the agent, and the locker hands your auditor a signed, control-mapped deliverable.
Each row is a 2022 Annex A control, the phase in the agent that satisfies it, and the deliverables the locker holds for your auditor.
Locks the scope and seals a signed consent attestation.
Identifies in-scope operational surfaces and log sources.
Enumerates installed software and environment boundaries.
The A.8.8 core — matched against KEV + NIST NVD.
Re-viewable chain proving the vulnerability is live.
Verifies separation between prod and out-of-scope nets.
sha-256 chain signed at seal time. Surveillance-ready.
Plug in a scope. The agent works the Annex A technological controls, and the locker hands your auditor a signed, control-mapped deliverable before the surveillance visit.