Skip to content

For security teams

One estate, scanned again and again

An internal team does not need a beautiful report. It needs to know what is new since last month, what keeps coming back, what nobody has fixed, and which of those matters — and it needs that without a person maintaining the spreadsheet that answers it.

What an internal programme needs

Six things, and only one of them is a document

The value to a team scanning its own estate is almost never the report. It is knowing what changed, what keeps coming back, and what nobody has fixed.

  • The delta, not the dump

    A scan report is a snapshot; what you act on is the difference. Findings are reconciled against the previous scan and classified as new, persisting, reappeared or fixed, with each classification recorded as an event rather than recomputed for a chart.

  • Recurring findings as one problem

    The same weakness class reappearing across five hosts and three months is one root cause, not fifteen tickets. Detecting that pattern is the thing that changes what a team does next, and it is built on the finding history rather than on a search.

  • Time to remediate, computed or absent

    Mean time to remediate comes from real first-seen and fixed timestamps. Where the data does not support the number, the number is not shown — an invented operational metric is worse than a blank space, because somebody will report it upward.

  • Noise you can suppress and keep suppressed

    A false positive marked once stays marked through the next scan. Accepted risk carries who accepted it and why. The engine stops asking you the same question every month.

  • The register your tracker actually reads

    The XLSX finding register is built to import cleanly into a ticketing system with severity and status mapped, because the value to an internal team is in the tracker rather than in a document nobody opens twice.

  • A report when you are asked for one

    Board summaries and audit evidence are occasional and unavoidable. The same findings assemble into a document written for a non-technical reader, so producing it is not a week of somebody’s time.

Where it is shaped for somebody else

What a consultancy needs that you may not

Said out loud, because the honest version of “it works for both” is a list of the places it does not.

  • Multi-tenancy runs underneath everything

    Organisations, per-client keys and cross-tenant isolation sit in the data layer whether or not you have a second client. For a single internal estate that is machinery you carry for a threat model that is not yours.

  • The deliverable is weighted heavily

    Report depth, export breadth and a review gate are first-class. Your equivalent value is in trend, ticketing and the register, and the document is the occasional output rather than the point.

  • Ingestion is file-first

    Scans arrive as exported files rather than as a live pull from your scanner on a schedule. That is the right shape for a consultancy handed an export, and one integration short of ideal for a continuous internal programme.

If you run an internal programme, saying which of those three actually gets in your way is the most useful thing you can send us — it is the difference between a product that fits your week and one that fits somebody else’s.

What it is not

Not a scanner, not a SOC, not a compliance certificate

This is a system of record and a report engine over findings something else produced. It does not scan your estate, it does not watch your alerts overnight, and it does not tell you that you are certified against a framework. It reads what your tools produced, keeps it honestly, and helps a person turn it into something defensible — and where it cannot evidence a claim, it says so rather than filling the gap.

If you run the programme, say what you would need

The three differences above are the honest ones. If they get in your way — or if they turn out not to matter once you are using it — that is the thing worth telling us.

Get in touch

Talk to the people building it

No chatbot and no ticket queue. Tell us what your security reporting actually looks like — which tools you live in, how long a deliverable takes, what a client has sent back — and someone who works on the software will reply.

info@legosphere.com

Please keep live incident details, credentials and customer data out of this box — it is an ordinary enquiry form, not a secure channel.