Skip to content
Vulnotes LogoVulnotes
Companies

Companies

Companies (called "Clients" in the sidebar) represent the organizations you perform assessments for. Each company can have multiple contacts and be linked to multiple reports.

Clients list

Create a client

Open Clients and click New Client. Enter the company name and optionally upload a logo, then click Next to add contacts. Click Create Client when finished. You can also continue without contacts and add them later.

Expand a company in the list to see its contacts and portal access. Use its edit action to update the company name, logo, or contacts.

Contacts

Each company can have multiple contacts. Contacts are the people at the client organization who receive the report, approve the scope, or serve as your points of contact during the assessment. Each contact can have:

  • First name and last name (required)
  • Email address (required)
  • Phone number
  • Role or job title (e.g. CISO, Security Consultant, CTO)

Contacts in reports

When creating a report, select a company and its relevant contacts. The report template can use:

  • client.primaryContact - the first selected contact, with the company's first contact used as a fallback
  • client.contacts - all contacts on the linked company

Use the primary contact for a cover page or recipient. Check any distribution list that loops over client.contacts, as it includes the company's full contact list.

Client Portal access

Contacts do not receive a portal account automatically. Once the Client Portal is configured, use Invite beside a contact to send an invitation. Choose a Portal Role and, if needed, an Access duration (months). Leave the duration empty for no expiry; a limited period starts when the invitation is accepted.

Choose a contact's portal role and optional access duration

The expanded company shows active accounts and pending invitations. You can change a role, deactivate or reactivate access, resend or cancel a pending invitation, and set a new access term. A new term starts when applied; leaving it empty makes access permanent.

See Team access for the portal roles and the controls available to client administrators.

Team access and visibility

If your organization uses teams, a company's visibility can be restricted to specific teams. Team members only see the companies (and by extension, the reports) that their team has access to. This is configured by administrators through the team exclusion list settings.

See Teams for more details on team-based access control.