Now live · 7-day free trial

Pre-engagement workflow from scope to approval.

Loalyx manages the full pre-engagement phase — client intake, readiness checks, approved scope and the final PDF bundle. Without spreadsheets or endless email threads.

7-day free trial · no card required
app.loalyx.com
LLoalyx
Engagements

Active book — Q2 2026

FilterNew engagement
IDEngagementStageStatusOwner / Note
ENG-2026-0184External pentestClient reviewPendingv1.4 · 2h
ENG-2026-0181Web app pentestExecutingOn track3/5 milestones
ENG-2026-0179Cloud config reviewAwaiting kickoffDraftdraft v0.3
ENG-2026-0177Internal red teamSigned · in flightOn track14 days remaining
ENG-2026-0173Pentest retestAwaiting reviewerPendingv2.0 · 3d
ENG-2026-0170API surface auditReport draftingDraftv1.1
How it works

From intake to a signed scope,
one auditable workflow.

Every engagement passes through four stages. Each transition is recorded, time-stamped, and visible to both sides.

STEP 01

Client intake

Client fills an intake form — targets, contacts and test windows. You review and convert it to a version.

STEP 02

Fill the scope form

In-scope, out-of-scope, testing conditions and legal terms in one place.

STEP 03

Readiness check & approval

Loalyx validates nothing critical is missing. Client approves the scope online via a secured link.

STEP 04

PDF bundle in one click

Scope/SOW + LOA + checklist, versioned. Audit trail and ZIP bundle included automatically.

Engagement scoping

Scope documents that read like SOWs but behave like software.

Templated, versioned, and diffable. Structured fields for targets, exclusions, and rules of engagement — exportable and reusable across clients.

  • Reusable scope templates by engagement type
  • Inline diff between scope versions
  • Structured fields → bundle export
See scoping in action
app.loalyx.com/projects/eng-2026-0184/scope
Statement of work · v1.4

External pentest — production perimeter

Internal review
§ 3.1 — IN-SCOPE TARGETS
customer.example.com · identity.example.com
api.example.com/v3 + added in v1.4

§ 3.2 — OUT-OF-SCOPE
Stripe (3rd party) · Auth0 SSO · Internal HR portal
Approval portal

A client portal that respects your client's time.

Branded magic-link with OTP — no password, no account. Client signs, requests changes, or declines. Every action is signed and time-stamped.

  • Approve / Request changes / Decline — one click
  • OTP via email — no password sprawl
  • Single-use link — revoked on signature
See the reviewer view
approve.loalyx.com/eng-2026-0184
NPre-engagement scope · previewAwaiting your sign-off

External pentest — Q2 2026
requires your approval

Sign & approveRequest changes
Action will be signed and recorded.
Document custody

Reports never leave the portal unless you say so.

PDFs, evidence packs, and remediation guidance live behind authenticated, watermarked links. Downloads are logged. Revocation is one click.

  • Time-limited signed URLs for PDFs
  • Audit log with IP, actor and timestamp
  • Granular revocation without re-issuing
See document controls
app.loalyx.com/projects/eng-2026-0184/documents
Documents · ENG-2026-0184
Final report v1.2
PDF · 4.2 MB
expires 30dActive
Evidence pack
ZIP · 38 MB
expires 7dHeld
Remediation guide
PDF · 1.1 MB
no expiryActive
Security posture

We build for security teams.

We don't claim certifications we don't have. Below is what's true today.

Encryption

TLS 1.3 in transit. Encryption at rest at both DB and object storage layers.

Access

Workspace + project RBAC. Token-based client access with OTP. Magic-link reviewers.

Audit

Audit log for every action. Hashed IP / UA metadata. Exportable.

Compliance

SOC 2 / ISO 27001 planned — not yet certified. Security posture documented transparently at /security.

Run your first engagement the right way.

No spreadsheets, no email threads, no grey zones in the scope. From intake to approval.

Start free trialTalk to us